[GH-ISSUE #7050] Google OIDC, users can create new accounts with the "signups_allowed": false, #19371

Closed
opened 2026-04-25 21:54:52 -05:00 by GiteaMirror · 6 comments
Owner

Originally created by @capsel22 on GitHub (Apr 2, 2026).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7050

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.35.4
  • Web-vault version: v2026.1.1
  • OS/Arch: linux/x86_64
  • Running within a container: true (Base: Debian)
  • Database type: SQLite
  • Database version: 3.50.2
  • Uses config.json: true
  • Uses a reverse proxy: true
  • IP Header check: true (X-Real-IP)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • TZ environment: Europe/London
  • Browser/Server Time Check: false
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: true

Config & Details (Generated via diagnostics page)

Show Config & Details

Environment settings which are overridden: DOMAIN, ADMIN_TOKEN

Config:

{
  "_duo_akey": null,
  "_enable_duo": false,
  "_enable_email_2fa": false,
  "_enable_smtp": true,
  "_enable_yubico": false,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_idle_timeout": 600,
  "database_max_conns": 10,
  "database_min_conns": 2,
  "database_timeout": 30,
  "database_url": "***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "dns_prefer_ipv6": false,
  "domain": "*****://*******************",
  "domain_origin": "*****://*******************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": false,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": false,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": false,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": null,
  "log_level": "info",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": false,
  "password_iterations": 600000,
  "purge_incomplete_sso_auth": "0 20 0 * * *",
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://push.bitwarden.com",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": false,
  "signups_domains_whitelist": "",
  "signups_verify": true,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": "starttls",
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "************************",
  "smtp_from_name": "***********",
  "smtp_host": "**************",
  "smtp_password": "***",
  "smtp_port": 587,
  "smtp_security": "starttls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "******************",
  "sso_allow_unknown_email_verification": false,
  "sso_audience_trusted": null,
  "sso_auth_only_not_session": false,
  "sso_authority": "*****://*******************",
  "sso_authorize_extra_params": "access_type=offline&prompt=consent",
  "sso_callback_path": "*****://************************************************",
  "sso_client_cache_expiration": 0,
  "sso_client_id": "*************************************************************************",
  "sso_client_secret": "***",
  "sso_debug_tokens": false,
  "sso_enabled": true,
  "sso_master_password_policy": null,
  "sso_only": true,
  "sso_pkce": true,
  "sso_scopes": "email profile openid",
  "sso_signups_match_email": true,
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

1.35.4

Deployment method

Official Container Image

Custom deployment method

No response

Reverse Proxy

Nginx Proxy Manager v2.13.6

Host/Server Operating System

Linux

Operating System Version

No response

Clients

Web Vault

Client Version

No response

Steps To Reproduce

  1. Go to vaultwarden web portal
  2. Provide an email address
  3. Click Use single sign-on
  4. You will be redirected to Google Authentication
  5. Login to your google account
  6. You will be pass back to vaultwarden
  7. Provide master password
  8. Login to portal with no issues

Expected Result

with the "signups_allowed": false AND user not created/invited I was expecting an error and inability to sign up/create user

Actual Result

User can sign up and create an account.
Tested on 3 different users which weren't invited nor previously had an account

Logs


Screenshots or Videos

Image Image Image Image Image Image

Additional Context

No response

Originally created by @capsel22 on GitHub (Apr 2, 2026). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7050 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Your environment (Generated via diagnostics page) * Vaultwarden version: v1.35.4 * Web-vault version: v2026.1.1 * OS/Arch: linux/x86_64 * Running within a container: true (Base: Debian) * Database type: SQLite * Database version: 3.50.2 * Uses config.json: true * Uses a reverse proxy: true * IP Header check: true (X-Real-IP) * Internet access: true * Internet access via a proxy: false * DNS Check: true * TZ environment: Europe/London * Browser/Server Time Check: false * Server/NTP Time Check: true * Domain Configuration Check: true * HTTPS Check: true * Websocket Check: true * HTTP Response Checks: true ### Config & Details (Generated via diagnostics page) <details><summary>Show Config & Details</summary> **Environment settings which are overridden:** DOMAIN, ADMIN_TOKEN **Config:** ```json { "_duo_akey": null, "_enable_duo": false, "_enable_email_2fa": false, "_enable_smtp": true, "_enable_yubico": false, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_idle_timeout": 600, "database_max_conns": 10, "database_min_conns": 2, "database_timeout": 30, "database_url": "***************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "dns_prefer_ipv6": false, "domain": "*****://*******************", "domain_origin": "*****://*******************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": null, "duo_ikey": null, "duo_skey": null, "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": false, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": false, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": false, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": null, "log_level": "info", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": false, "org_groups_enabled": false, "password_hints_allowed": false, "password_iterations": 600000, "purge_incomplete_sso_auth": "0 20 0 * * *", "push_enabled": false, "push_identity_uri": "https://identity.bitwarden.com", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://push.bitwarden.com", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": false, "signups_domains_whitelist": "", "signups_verify": true, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": "starttls", "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "************************", "smtp_from_name": "***********", "smtp_host": "**************", "smtp_password": "***", "smtp_port": 587, "smtp_security": "starttls", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": "******************", "sso_allow_unknown_email_verification": false, "sso_audience_trusted": null, "sso_auth_only_not_session": false, "sso_authority": "*****://*******************", "sso_authorize_extra_params": "access_type=offline&prompt=consent", "sso_callback_path": "*****://************************************************", "sso_client_cache_expiration": 0, "sso_client_id": "*************************************************************************", "sso_client_secret": "***", "sso_debug_tokens": false, "sso_enabled": true, "sso_master_password_policy": null, "sso_only": true, "sso_pkce": true, "sso_scopes": "email profile openid", "sso_signups_match_email": true, "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": null, "yubico_secret_key": null, "yubico_server": null } ``` </details> ### Vaultwarden Build Version 1.35.4 ### Deployment method Official Container Image ### Custom deployment method _No response_ ### Reverse Proxy Nginx Proxy Manager v2.13.6 ### Host/Server Operating System Linux ### Operating System Version _No response_ ### Clients Web Vault ### Client Version _No response_ ### Steps To Reproduce 1. Go to vaultwarden web portal 2. Provide an email address 3. Click Use single sign-on 4. You will be redirected to Google Authentication 5. Login to your google account 6. You will be pass back to vaultwarden 7. Provide master password 8. Login to portal with no issues ### Expected Result with the "signups_allowed": false AND user not created/invited I was expecting an error and inability to sign up/create user ### Actual Result User can sign up and create an account. Tested on 3 different users which weren't invited nor previously had an account ### Logs ```text ``` ### Screenshots or Videos <img width="574" height="264" alt="Image" src="https://github.com/user-attachments/assets/de1f3815-e71f-47c4-b4da-1e181769f4b3" /> <img width="1380" height="577" alt="Image" src="https://github.com/user-attachments/assets/6e98bad2-3918-411c-b691-d92cf07a7b12" /> <img width="672" height="495" alt="Image" src="https://github.com/user-attachments/assets/35965766-3974-426e-ba92-e9e639eb29bd" /> <img width="772" height="683" alt="Image" src="https://github.com/user-attachments/assets/7b948bfd-da73-44bf-af9e-f29c585175a1" /> <img width="1646" height="587" alt="Image" src="https://github.com/user-attachments/assets/5576ab52-b769-4d81-843d-e73bd7b352c7" /> <img width="1411" height="339" alt="Image" src="https://github.com/user-attachments/assets/1582a6c5-b80b-491c-8602-2f3276d36292" /> ### Additional Context _No response_
GiteaMirror added the bug label 2026-04-25 21:54:52 -05:00
Author
Owner

@BlackDex commented on GitHub (Apr 2, 2026):

If I'm correct SSO bypasses that check. But not sure from the top of my head. @Timshel maybe knows this better?

<!-- gh-comment-id:4178312873 --> @BlackDex commented on GitHub (Apr 2, 2026): If I'm correct SSO bypasses that check. But not sure from the top of my head. @Timshel maybe knows this better?
Author
Owner

@Timshel commented on GitHub (Apr 2, 2026):

Yes the idea is to remove the need to invite users one by one for the configured provider.
The signups_domains_whitelist is still applied but signups_allowed is ignored.

It's not really intended to use with providers where you do not control the user list, it becomes kind of useless since the main feature are to remove the need for invitation and allow access revocation at the provider level if sso_only is used.

<!-- gh-comment-id:4178445098 --> @Timshel commented on GitHub (Apr 2, 2026): Yes the idea is to remove the need to invite users one by one for the configured provider. The `signups_domains_whitelist` is still applied but `signups_allowed` is ignored. It's not really intended to use with providers where you do not control the user list, it becomes kind of useless since the main feature are to remove the need for invitation and allow access revocation at the provider level if `sso_only` is used.
Author
Owner

@capsel22 commented on GitHub (Apr 2, 2026):

Alright I see.
Not ideal, I hoped to use the Google OAuth same as I use for other self-hosted apps but they do allow control of limiting user creation to only invited or created only.

I think in this scenario I will disable it. Maybe it will be considered as a feature in the future.

<!-- gh-comment-id:4178490404 --> @capsel22 commented on GitHub (Apr 2, 2026): Alright I see. Not ideal, I hoped to use the Google OAuth same as I use for other self-hosted apps but they do allow control of limiting user creation to only invited or created only. I think in this scenario I will disable it. Maybe it will be considered as a feature in the future.
Author
Owner

@capsel22 commented on GitHub (Apr 2, 2026):

Thanks both for your quick replies. All the best

<!-- gh-comment-id:4178574284 --> @capsel22 commented on GitHub (Apr 2, 2026): Thanks both for your quick replies. All the best
Author
Owner

@Timshel commented on GitHub (Apr 2, 2026):

Maybe I'm missing something but if you still want to invite users I don't understand what OAuth is bringing you ?

It does open the possibility of not sending/storing the master password to/in the server but at the moment this is not supported.
It might become possible some day since Bitwarden is adding features removing the need for master password (Ex: trusted devices) but I don't know how it interacts with the part of the application/server which used to require it (Ex: adding a 2FA device).

<!-- gh-comment-id:4178740513 --> @Timshel commented on GitHub (Apr 2, 2026): Maybe I'm missing something but if you still want to invite users I don't understand what OAuth is bringing you ? It does open the possibility of not sending/storing the master password to/in the server but at the moment this is not supported. It might become possible some day since Bitwarden is adding features removing the need for master password (Ex: [trusted devices](https://bitwarden.com/help/about-trusted-devices/#impact-on-master-passwords)) but I don't know how it interacts with the part of the application/server which used to require it (Ex: adding a 2FA device).
Author
Owner

@capsel22 commented on GitHub (Apr 2, 2026):

Maybe I'm missing something but if you still want to invite users I don't understand what OAuth is bringing you ?

It does open the possibility of not sending/storing the master password to/in the server but at the moment this is not supported. It might become possible some day since Bitwarden is adding features removing the need for master password (Ex: trusted devices) but I don't know how it interacts with the part of the application/server which used to require it (Ex: adding a 2FA device).

Ohhh yeah, I didn't realise you can't hide the master password requirement when using sso.
You are right at this point in time there is no benefit.

<!-- gh-comment-id:4178768966 --> @capsel22 commented on GitHub (Apr 2, 2026): > Maybe I'm missing something but if you still want to invite users I don't understand what OAuth is bringing you ? > > It does open the possibility of not sending/storing the master password to/in the server but at the moment this is not supported. It might become possible some day since Bitwarden is adding features removing the need for master password (Ex: [trusted devices](https://bitwarden.com/help/about-trusted-devices/#impact-on-master-passwords)) but I don't know how it interacts with the part of the application/server which used to require it (Ex: adding a 2FA device). Ohhh yeah, I didn't realise you can't hide the master password requirement when using sso. You are right at this point in time there is no benefit.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#19371