[GH-ISSUE #6270] Cannot delete item collection folder #39634

Closed
opened 2026-07-17 17:16:30 -05:00 by GiteaMirror · 4 comments
Owner

Originally created by @extramatrix on GitHub (Sep 4, 2025).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6270

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.34.3
  • Web-vault version: v2025.7.0
  • OS/Arch: linux/x86_64
  • Running within a container: true (Base: Debian)
  • Database type: SQLite
  • Database version: 3.50.2
  • Uses config.json: true
  • Uses a reverse proxy: true
  • IP Header check: true (X-Real-IP)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • Browser/Server Time Check: true
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: true

Config & Details (Generated via diagnostics page)

Show Config & Details

Environment settings which are overridden: ADMIN_TOKEN

Config:

{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": false,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_max_conns": 10,
  "database_timeout": 30,
  "database_url": "***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "domain": "*****://***************************",
  "domain_origin": "*****://***************************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": false,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": true,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": null,
  "log_level": "info",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": true,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://push.bitwarden.com",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": true,
  "signups_domains_whitelist": "******",
  "signups_verify": false,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": null,
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "***************************",
  "smtp_from_name": "Vaultwarden",
  "smtp_host": "***********",
  "smtp_password": null,
  "smtp_port": 25,
  "smtp_security": "off",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": null,
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

1.34.3

Deployment method

Official Container Image

Custom deployment method

No response

Reverse Proxy

haproxy

Host/Server Operating System

Linux

Operating System Version

Oracle Linux 9

Clients

Web Vault

Client Version

No response

Steps To Reproduce

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. Click on '...'
  5. Etc '...'

Expected Result

I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.

Actual Result

I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior.
I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.
Actually, only I can do it as an admin. Why?
Thank you in advance.
Best regards.

Max
Image

Logs


Screenshots or Videos

Image

Additional Context

No response

Originally created by @extramatrix on GitHub (Sep 4, 2025). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6270 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Your environment (Generated via diagnostics page) * Vaultwarden version: v1.34.3 * Web-vault version: v2025.7.0 * OS/Arch: linux/x86_64 * Running within a container: true (Base: Debian) * Database type: SQLite * Database version: 3.50.2 * Uses config.json: true * Uses a reverse proxy: true * IP Header check: true (X-Real-IP) * Internet access: true * Internet access via a proxy: false * DNS Check: true * Browser/Server Time Check: true * Server/NTP Time Check: true * Domain Configuration Check: true * HTTPS Check: true * Websocket Check: true * HTTP Response Checks: true ### Config & Details (Generated via diagnostics page) <details><summary>Show Config & Details</summary> **Environment settings which are overridden:** ADMIN_TOKEN **Config:** ```json { "_duo_akey": null, "_enable_duo": true, "_enable_email_2fa": false, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_max_conns": 10, "database_timeout": 30, "database_url": "***************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "domain": "*****://***************************", "domain_origin": "*****://***************************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": null, "duo_ikey": null, "duo_skey": null, "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": false, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": true, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": true, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": null, "log_level": "info", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": false, "org_groups_enabled": true, "password_hints_allowed": true, "password_iterations": 600000, "push_enabled": false, "push_identity_uri": "https://identity.bitwarden.com", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://push.bitwarden.com", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": true, "signups_domains_whitelist": "******", "signups_verify": false, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": null, "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "***************************", "smtp_from_name": "Vaultwarden", "smtp_host": "***********", "smtp_password": null, "smtp_port": 25, "smtp_security": "off", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": null, "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": null, "yubico_secret_key": null, "yubico_server": null } ``` </details> ### Vaultwarden Build Version 1.34.3 ### Deployment method Official Container Image ### Custom deployment method _No response_ ### Reverse Proxy haproxy ### Host/Server Operating System Linux ### Operating System Version Oracle Linux 9 ### Clients Web Vault ### Client Version _No response_ ### Steps To Reproduce 1. Go to '...' 2. Click on '....' 3. Scroll down to '....' 4. Click on '...' 5. Etc '...' ### Expected Result I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior. I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions. ### Actual Result I’ve been using Vaultwarden self hosted 1.34.3 (2005-07) , and I’ve noticed some strange behavior. I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions. Actually, only I can do it as an admin. Why? Thank you in advance. Best regards. Max <img width="1226" height="722" alt="Image" src="https://github.com/user-attachments/assets/38fb6250-828b-4678-8be5-54813329e015" /> ### Logs ```text ``` ### Screenshots or Videos <img width="1226" height="722" alt="Image" src="https://github.com/user-attachments/assets/1af0ecf0-628a-43f1-9af1-77807ba772c2" /> ### Additional Context _No response_
GiteaMirror added the bug label 2026-07-17 17:16:31 -05:00
Author
Owner

@stefan0xC commented on GitHub (Sep 9, 2025):

In Bitwarden there's a difference between folders and collections so I'm assuming you meant the latter. Because you don't need any special permissions to create folders (because folders pertain only to your personal account and are not shared).

I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions.

I tried to reproduce the issue but I have not managed to create the error message. Could you please describe in more detail how to reproduce the issue? What role and permissions exactly did you give the user? What steps exactly produce the error? Because (since v1.34.2 or more specifically https://github.com/dani-garcia/vaultwarden/commit/25865efd799d0321428e1dff1489b834e1206021) a User role should not be able to manage a collection at all anymore (even with the Manage collection permission), and a Custom user cannot delete collections either (unless they also have been given the permission to manage all collections).

<!-- gh-comment-id:3272491836 --> @stefan0xC commented on GitHub (Sep 9, 2025): In Bitwarden there's a difference between [folders](https://bitwarden.com/help/folders/) and [collections](https://bitwarden.com/help/about-collections/) so I'm assuming you meant the latter. Because you don't need any special permissions to create folders (because folders pertain only to your personal account and are not shared). > I set a user’s permissions so they can create both items and folders in the organization, and they can. But when they try to delete a folder, they get an error saying they don’t have permissions. I tried to reproduce the issue but I have not managed to create the error message. Could you please describe in more detail how to reproduce the issue? What role and permissions exactly did you give the user? What steps exactly produce the error? Because (since [v1.34.2](https://github.com/dani-garcia/vaultwarden/releases/tag/1.34.2) or more specifically https://github.com/dani-garcia/vaultwarden/commit/25865efd799d0321428e1dff1489b834e1206021) a `User` role should not be able to manage a collection at all anymore (even with the `Manage collection` permission), and a `Custom` user cannot delete collections either (unless they also have been given the permission to manage all collections).
Author
Owner

@extramatrix commented on GitHub (Sep 10, 2025):

The role is personalized, and you guessed right, they are collections. If I assign role User there's not menù on the left side of a collection. I also using Groups, and this user has Manage collection on the Collection.
By the way, with the personalized role, I see the three dots but no delete option. If I select the collection, and click on the three dots above the line i see Delete option, but clicking on it shows the message "You do not have the necessary permissions to perform this operation".
Thank you.

Image Image Image
<!-- gh-comment-id:3274516098 --> @extramatrix commented on GitHub (Sep 10, 2025): The role is personalized, and you guessed right, they are collections. If I assign role User there's not menù on the left side of a collection. I also using Groups, and this user has Manage collection on the Collection. By the way, with the personalized role, I see the three dots but no delete option. If I select the collection, and click on the three dots above the line i see Delete option, but clicking on it shows the message "You do not have the necessary permissions to perform this operation". Thank you. <img width="1218" height="236" alt="Image" src="https://github.com/user-attachments/assets/d1919f00-5552-44e9-9800-ba679a38a202" /> <img width="290" height="95" alt="Image" src="https://github.com/user-attachments/assets/20c55136-4a88-4d9b-be25-e65daf74fec2" /> <img width="616" height="69" alt="Image" src="https://github.com/user-attachments/assets/f75fd98d-c22a-4f51-a69e-883c9685432e" />
Author
Owner

@extramatrix commented on GitHub (Sep 26, 2025):

I noticed another strange behavior.
In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost!
Is this intended behavior or a bug?

<!-- gh-comment-id:3337188629 --> @extramatrix commented on GitHub (Sep 26, 2025): I noticed another strange behavior. In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost! Is this intended behavior or a bug?
Author
Owner

@stefan0xC commented on GitHub (Oct 8, 2025):

I noticed another strange behavior. In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost! Is this intended behavior or a bug?

That's because if you delete a collect the contained items are not deleted but only not in a collection anymore. They should still show up in the Admin Console via the special Unassigned collection.

Image
<!-- gh-comment-id:3381224969 --> @stefan0xC commented on GitHub (Oct 8, 2025): > I noticed another strange behavior. In the case described above, if an admin user deletes a collection containing credentials, the credentials themselves aren't sent to the Recycle Bin—everything is lost! Is this intended behavior or a bug? That's because if you delete a collect the contained items are not deleted but only not in a collection anymore. They should still show up in the Admin Console via the special `Unassigned` collection. <img width="1147" height="92" alt="Image" src="https://github.com/user-attachments/assets/ebbaa0aa-0223-452a-8e55-1793b82a81fd" />
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#39634