I think I found a small bug in the web UI while backing up my vaults. I have my own vault and an organization for my home. First, I exported normally my own vault. When I selected encrypted json as type, I got asked for a password as usual:
When I then changed the vault to my home's, json encrypted remained selected, but I did not get a field asking for a password. Just for funsies, I clicked confirm to generate an export, and sure enough, the resulting backup was not encrypted.
This is obviously not a big issue, just the UI being misleading. As soon as you change the export type to something else and back to encrypted json, it works just fine and asks for the password again.
Reverse Proxy
traefik 3.5.2
Host/Server Operating System
Linux
Operating System Version
Ubuntu 24.04 LTS
Clients
Web Vault
Client Version
Firefox 143 - v2025.7.0
Steps To Reproduce
Backup a vault using json encrypted protected with password (not account locked)
Change vault to be backed up
The backup type is still "json encrypted", but you are not prompted for a password, and the resulting backup is not encrypted
Expected Result
Either the type field goes back to "json" (unencrypted), or it remains as "json encrypted", but it prompts for a password as usual.
Actual Result
The UI misleads you into thinking you're creating an encrypted vault backup, when it's actually not encrypted.
Logs
Screenshots or Videos
No response
Additional Context
No response
Originally created by @manugutito on GitHub (Oct 5, 2025).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6342
### Prerequisites
- [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=)
- [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/)
### Vaultwarden Support String
### Your environment (Generated via diagnostics page)
* Vaultwarden version: v1.34.3
* Web-vault version: v2025.7.0
* OS/Arch: linux/x86_64
* Running within a container: true (Base: Debian)
* Database type: SQLite
* Database version: 3.50.2
* Uses config.json: true
* Uses a reverse proxy: true
* IP Header check: true (X-Real-IP)
* Internet access: true
* Internet access via a proxy: false
* DNS Check: true
* Browser/Server Time Check: false
* Server/NTP Time Check: true
* Domain Configuration Check: true
* HTTPS Check: true
* Websocket Check: true
* HTTP Response Checks: true
### Config & Details (Generated via diagnostics page)
<details><summary>Show Config & Details</summary>
**Environment settings which are overridden:** DOMAIN, SIGNUPS_ALLOWED, ADMIN_TOKEN
**Config:**
```json
{
"_duo_akey": null,
"_enable_duo": true,
"_enable_email_2fa": false,
"_enable_smtp": true,
"_enable_yubico": true,
"_icon_service_csp": "",
"_icon_service_url": "",
"_ip_header_enabled": true,
"_max_note_size": 10000,
"_smtp_img_src": "***:",
"admin_ratelimit_max_burst": 3,
"admin_ratelimit_seconds": 300,
"admin_session_lifetime": 20,
"admin_token": "***",
"allowed_connect_src": "",
"allowed_iframe_ancestors": "",
"attachments_folder": "data/attachments",
"auth_request_purge_schedule": "30 * * * * *",
"authenticator_disable_time_drift": false,
"data_folder": "data",
"database_conn_init": "",
"database_max_conns": 10,
"database_timeout": 30,
"database_url": "***************",
"db_connection_retries": 15,
"disable_2fa_remember": false,
"disable_admin_token": false,
"disable_icon_download": false,
"domain": "*****://**************",
"domain_origin": "*****://**************",
"domain_path": "",
"domain_set": true,
"duo_context_purge_schedule": "30 * * * * *",
"duo_host": null,
"duo_ikey": null,
"duo_skey": null,
"duo_use_iframe": false,
"email_2fa_auto_fallback": false,
"email_2fa_enforce_on_verified_invite": false,
"email_attempts_limit": 3,
"email_change_allowed": true,
"email_expiration_time": 600,
"email_token_size": 6,
"emergency_access_allowed": true,
"emergency_notification_reminder_schedule": "0 3 * * * *",
"emergency_request_timeout_schedule": "0 7 * * * *",
"enable_db_wal": true,
"enable_websocket": true,
"enforce_single_org_with_reset_pw_policy": false,
"event_cleanup_schedule": "0 10 0 * * *",
"events_days_retain": null,
"experimental_client_feature_flags": "",
"extended_logging": true,
"helo_name": null,
"hibp_api_key": null,
"http_request_block_non_global_ips": true,
"http_request_block_regex": null,
"icon_blacklist_non_global_ips": true,
"icon_blacklist_regex": null,
"icon_cache_folder": "data/icon_cache",
"icon_cache_negttl": 259200,
"icon_cache_ttl": 2592000,
"icon_download_timeout": 10,
"icon_redirect_code": 302,
"icon_service": "internal",
"incomplete_2fa_schedule": "30 * * * * *",
"incomplete_2fa_time_limit": 3,
"increase_note_size_limit": false,
"invitation_expiration_hours": 120,
"invitation_org_name": "Vaultwarden",
"invitations_allowed": true,
"ip_header": "X-Real-IP",
"job_poll_interval_ms": 30000,
"log_file": null,
"log_level": "info",
"log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
"login_ratelimit_max_burst": 10,
"login_ratelimit_seconds": 60,
"org_attachment_limit": null,
"org_creation_users": "",
"org_events_enabled": false,
"org_groups_enabled": false,
"password_hints_allowed": true,
"password_iterations": xxxxxxx,
"push_enabled": false,
"push_identity_uri": "https://identity.bitwarden.com",
"push_installation_id": "***",
"push_installation_key": "***",
"push_relay_uri": "https://push.bitwarden.com",
"reload_templates": false,
"require_device_email": false,
"rsa_key_filename": "data/rsa_key",
"send_purge_schedule": "0 5 * * * *",
"sendmail_command": null,
"sends_allowed": true,
"sends_folder": "data/sends",
"show_password_hint": false,
"signups_allowed": false,
"signups_domains_whitelist": "",
"signups_verify": false,
"signups_verify_resend_limit": 6,
"signups_verify_resend_time": 3600,
"smtp_accept_invalid_certs": false,
"smtp_accept_invalid_hostnames": false,
"smtp_auth_mechanism": null,
"smtp_debug": false,
"smtp_embed_images": true,
"smtp_explicit_tls": null,
"smtp_from": "************************",
"smtp_from_name": "Vaultwarden",
"smtp_host": "**************",
"smtp_password": "***",
"smtp_port": 465,
"smtp_security": "force_tls",
"smtp_ssl": null,
"smtp_timeout": 15,
"smtp_username": "************************",
"templates_folder": "data/templates",
"tmp_folder": "data/tmp",
"trash_auto_delete_days": null,
"trash_purge_schedule": "0 5 0 * * *",
"use_sendmail": false,
"use_syslog": false,
"user_attachment_limit": null,
"user_send_limit": null,
"web_vault_enabled": true,
"web_vault_folder": "web-vault/",
"yubico_client_id": null,
"yubico_secret_key": null,
"yubico_server": null
}
```
</details>
### Vaultwarden Build Version
v1.34.3
### Deployment method
Official Container Image
### Custom deployment method
Hi all,
I think I found a small bug in the web UI while backing up my vaults. I have my own vault and an organization for my home. First, I exported normally my own vault. When I selected encrypted json as type, I got asked for a password as usual:
<img width="1164" height="737" alt="Image" src="https://github.com/user-attachments/assets/f8919fed-8a97-40eb-80f4-073361c44f80" />
When I then changed the vault to my home's, json encrypted remained selected, but I did not get a field asking for a password. Just for funsies, I clicked confirm to generate an export, and sure enough, the resulting backup was not encrypted.
<img width="1179" height="698" alt="Image" src="https://github.com/user-attachments/assets/5204ff5d-915b-4df6-87fe-ff5068fc51f4" />
This is obviously not a big issue, just the UI being misleading. As soon as you change the export type to something else and back to encrypted json, it works just fine and asks for the password again.
### Reverse Proxy
traefik 3.5.2
### Host/Server Operating System
Linux
### Operating System Version
Ubuntu 24.04 LTS
### Clients
Web Vault
### Client Version
Firefox 143 - v2025.7.0
### Steps To Reproduce
1. Backup a vault using json encrypted protected with password (not account locked)
2. Change vault to be backed up
3. The backup type is still "json encrypted", but you are not prompted for a password, and the resulting backup is not encrypted
### Expected Result
Either the type field goes back to "json" (unencrypted), or it remains as "json encrypted", but it prompts for a password as usual.
### Actual Result
The UI misleads you into thinking you're creating an encrypted vault backup, when it's actually not encrypted.
### Logs
```text
```
### Screenshots or Videos
_No response_
### Additional Context
_No response_
GiteaMirror
added the bug label 2026-07-17 17:32:11 -05:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @manugutito on GitHub (Oct 5, 2025).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/6342
Prerequisites
Vaultwarden Support String
Your environment (Generated via diagnostics page)
Config & Details (Generated via diagnostics page)
Show Config & Details
Environment settings which are overridden: DOMAIN, SIGNUPS_ALLOWED, ADMIN_TOKEN
Config:
Vaultwarden Build Version
v1.34.3
Deployment method
Official Container Image
Custom deployment method
Hi all,
I think I found a small bug in the web UI while backing up my vaults. I have my own vault and an organization for my home. First, I exported normally my own vault. When I selected encrypted json as type, I got asked for a password as usual:
When I then changed the vault to my home's, json encrypted remained selected, but I did not get a field asking for a password. Just for funsies, I clicked confirm to generate an export, and sure enough, the resulting backup was not encrypted.
This is obviously not a big issue, just the UI being misleading. As soon as you change the export type to something else and back to encrypted json, it works just fine and asks for the password again.
Reverse Proxy
traefik 3.5.2
Host/Server Operating System
Linux
Operating System Version
Ubuntu 24.04 LTS
Clients
Web Vault
Client Version
Firefox 143 - v2025.7.0
Steps To Reproduce
Expected Result
Either the type field goes back to "json" (unencrypted), or it remains as "json encrypted", but it prompts for a password as usual.
Actual Result
The UI misleads you into thinking you're creating an encrypted vault backup, when it's actually not encrypted.
Logs
Screenshots or Videos
No response
Additional Context
No response