Fill in "API access token", "Alias domain" and "Server URL"
Click "Regenerate username"
Expected Result
The alias should be generated
Actual Result
Fails with
Content-Security-Policy: The page’s settings blocked the loading of a resource (connect-src) at https://your.instance.com/api/v1/aliases because it violates the following directive: “connect-src 'self' https://api.pwnedpasswords.com https://api.2fa.directory https://app.simplelogin.io/api/ https://app.addy.io/api/ https://api.fastmail.com/ https://api.forwardemail.net”
Logs
No response
Screenshots or Videos
No response
Additional Context
No response
Originally created by @ligix on GitHub (Dec 13, 2024).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/5290
### Vaultwarden Support String
### Your environment (Generated via diagnostics page)
* Vaultwarden version: v1.32.6
* Web-vault version: v2024.6.2c
* OS/Arch: linux/x86_64
* Running within a container: true (Base: Debian)
* Database type: SQLite
* Database version: 3.46.0
* Environment settings overridden!: true
* Uses a reverse proxy: true
* IP Header check: true (X-Real-IP)
* Internet access: true
* Internet access via a proxy: false
* DNS Check: true
* Browser/Server Time Check: true
* Server/NTP Time Check: true
* Domain Configuration Check: true
* HTTPS Check: true
* Websocket Check: false
* HTTP Response Checks: true
### Config & Details (Generated via diagnostics page)
<details><summary>Show Config & Details</summary>
**Environment settings which are overridden:** ADMIN_TOKEN
**Config:**
```json
{
"_duo_akey": null,
"_enable_duo": false,
"_enable_email_2fa": true,
"_enable_smtp": true,
"_enable_yubico": true,
"_icon_service_csp": "",
"_icon_service_url": "",
"_ip_header_enabled": true,
"_max_note_size": 10000,
"_smtp_img_src": "cid:",
"admin_ratelimit_max_burst": 3,
"admin_ratelimit_seconds": 300,
"admin_session_lifetime": 20,
"admin_token": "***",
"allowed_iframe_ancestors": "",
"attachments_folder": "data/attachments",
"auth_request_purge_schedule": "30 * * * * *",
"authenticator_disable_time_drift": false,
"data_folder": "data",
"database_conn_init": "",
"database_max_conns": 10,
"database_timeout": 30,
"database_url": "***************",
"db_connection_retries": 15,
"disable_2fa_remember": false,
"disable_admin_token": false,
"disable_icon_download": false,
"domain": "*****://***************",
"domain_origin": "*****://***************",
"domain_path": "",
"domain_set": true,
"duo_context_purge_schedule": "30 * * * * *",
"duo_host": null,
"duo_ikey": null,
"duo_skey": null,
"duo_use_iframe": false,
"email_2fa_auto_fallback": false,
"email_2fa_enforce_on_verified_invite": false,
"email_attempts_limit": 3,
"email_change_allowed": true,
"email_expiration_time": 300,
"email_token_size": 12,
"emergency_access_allowed": true,
"emergency_notification_reminder_schedule": "0 3 * * * *",
"emergency_request_timeout_schedule": "0 7 * * * *",
"enable_db_wal": true,
"enable_websocket": true,
"enforce_single_org_with_reset_pw_policy": false,
"event_cleanup_schedule": "0 10 0 * * *",
"events_days_retain": null,
"experimental_client_feature_flags": "fido2-vault-credentials",
"extended_logging": true,
"helo_name": "***************",
"hibp_api_key": null,
"http_request_block_non_global_ips": true,
"http_request_block_regex": null,
"icon_blacklist_non_global_ips": true,
"icon_blacklist_regex": null,
"icon_cache_folder": "data/icon_cache",
"icon_cache_negttl": 259200,
"icon_cache_ttl": 2592000,
"icon_download_timeout": 10,
"icon_redirect_code": 302,
"icon_service": "internal",
"incomplete_2fa_schedule": "30 * * * * *",
"incomplete_2fa_time_limit": 3,
"increase_note_size_limit": false,
"invitation_expiration_hours": 120,
"invitation_org_name": "Vaultwarden",
"invitations_allowed": true,
"ip_header": "X-Real-IP",
"job_poll_interval_ms": 30000,
"log_file": null,
"log_level": "info",
"log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
"login_ratelimit_max_burst": 10,
"login_ratelimit_seconds": 60,
"org_attachment_limit": null,
"org_creation_users": "",
"org_events_enabled": false,
"org_groups_enabled": false,
"password_hints_allowed": true,
"password_iterations": 100000,
"push_enabled": false,
"push_identity_uri": "https://identity.bitwarden.com",
"push_installation_id": "***",
"push_installation_key": "***",
"push_relay_uri": "https://push.bitwarden.com",
"reload_templates": false,
"require_device_email": false,
"rsa_key_filename": "data/rsa_key",
"send_purge_schedule": "0 5 * * * *",
"sendmail_command": null,
"sends_allowed": true,
"sends_folder": "data/sends",
"show_password_hint": false,
"signups_allowed": false,
"signups_domains_whitelist": "",
"signups_verify": false,
"signups_verify_resend_limit": 6,
"signups_verify_resend_time": 3600,
"smtp_accept_invalid_certs": false,
"smtp_accept_invalid_hostnames": false,
"smtp_auth_mechanism": "Plain",
"smtp_debug": false,
"smtp_embed_images": true,
"smtp_explicit_tls": null,
"smtp_from": "************************",
"smtp_from_name": "Vaultwarden",
"smtp_host": "************",
"smtp_password": "***",
"smtp_port": 587,
"smtp_security": "starttls",
"smtp_ssl": null,
"smtp_timeout": 15,
"smtp_username": "************************",
"templates_folder": "data/templates",
"tmp_folder": "data/tmp",
"trash_auto_delete_days": null,
"trash_purge_schedule": "0 5 0 * * *",
"use_sendmail": false,
"use_syslog": false,
"user_attachment_limit": null,
"user_send_limit": null,
"web_vault_enabled": true,
"web_vault_folder": "web-vault/",
"yubico_client_id": null,
"yubico_secret_key": null,
"yubico_server": null
}
```
</details>
### Vaultwarden Build Version
1.32.6
### Deployment method
Official Container Image
### Custom deployment method
_No response_
### Reverse Proxy
nginx/1.26.2
### Host/Server Operating System
Linux
### Operating System Version
_No response_
### Clients
Web Vault
### Client Version
Firefox 131.0.2-1
### Steps To Reproduce
1. Go to Tools
2. Select username generation
3. Pick "Forwarded email alias"
4. Select addy.io as the service
5. Fill in "API access token", "Alias domain" and "Server URL"
6. Click "Regenerate username"
### Expected Result
The alias should be generated
### Actual Result
Fails with
```
Content-Security-Policy: The page’s settings blocked the loading of a resource (connect-src) at https://your.instance.com/api/v1/aliases because it violates the following directive: “connect-src 'self' https://api.pwnedpasswords.com https://api.2fa.directory https://app.simplelogin.io/api/ https://app.addy.io/api/ https://api.fastmail.com/ https://api.forwardemail.net”
```
### Logs
_No response_
### Screenshots or Videos
_No response_
### Additional Context
_No response_
Do you provide a custom Server URL?
If so, then this is probably the reason.
We do not have something to configure this currently and that should be added then.
<!-- gh-comment-id:2541271152 -->
@BlackDex commented on GitHub (Dec 13, 2024):
Do you provide a custom **Server URL**?
If so, then this is probably the reason.
We do not have something to configure this currently and that should be added then.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @ligix on GitHub (Dec 13, 2024).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/5290
Vaultwarden Support String
Your environment (Generated via diagnostics page)
Config & Details (Generated via diagnostics page)
Show Config & Details
Environment settings which are overridden: ADMIN_TOKEN
Config:
Vaultwarden Build Version
1.32.6
Deployment method
Official Container Image
Custom deployment method
No response
Reverse Proxy
nginx/1.26.2
Host/Server Operating System
Linux
Operating System Version
No response
Clients
Web Vault
Client Version
Firefox 131.0.2-1
Steps To Reproduce
Expected Result
The alias should be generated
Actual Result
Fails with
Logs
No response
Screenshots or Videos
No response
Additional Context
No response
@BlackDex commented on GitHub (Dec 13, 2024):
Do you provide a custom Server URL?
If so, then this is probably the reason.
We do not have something to configure this currently and that should be added then.
@BlackDex commented on GitHub (Dec 14, 2024):
@ligix I have a fix pending for approval.