Originally created by @jducaud on GitHub (Mar 19, 2022).
Subject of the issue
My Vaultwarden account email address is said by the Web Vault to be linked to a breach but it does not seem to be.
Deployment environment
Machine: Synology DS218+ (OS: DSM 6.2.4-25556 Update 5)
Docker image: vaultwarden/server 1.24.0 (latest: 6 weeks ago / 187MB) (Web Vault 2.25.1)
Client: Firefox 98.0.1 (64-bit) (connection to the Web Vault) on Microsoft Windows 10 21H2
Reverse proxy and version (on DSM): nginx 1.16.1
Steps to reproduce
1 - Log in to my Vaultwarden account on the Web Vault
2 - Go to "Tools > Reports > Data breach report"
3 - Press the "Check breaches" button
4 - The message "BREACHED ACCOUNTS FOUND" (uppercased and red) is displayed, asking for a manual check on HIBP website
5 - Go to HIBP website (just click on the provided hyperlink by the Web Vault)
6 - See that my email address has not been pwned
Expected behaviour
I have no subscription running at HIBP, so I do not have an API key. I would expect the Web Vault to remind me that I have not an HIBP API key, but without warning me that I have been pwned (this supposed breach has even a date: August 18th 2019).
Actual behaviour
See above.
Troubleshooting data
Here are 2 relevant screenshots
Steps 1 to 4
Steps 5 to 6
Originally created by @jducaud on GitHub (Mar 19, 2022).
### Subject of the issue
My Vaultwarden account email address is said by the Web Vault to be linked to a breach but it does not seem to be.
### Deployment environment
Machine: Synology DS218+ (OS: DSM 6.2.4-25556 Update 5)
Docker image: vaultwarden/server 1.24.0 (latest: 6 weeks ago / 187MB) (Web Vault 2.25.1)
Client: Firefox 98.0.1 (64-bit) (connection to the Web Vault) on Microsoft Windows 10 21H2
Reverse proxy and version (on DSM): nginx 1.16.1
### Steps to reproduce
1 - Log in to my Vaultwarden account on the Web Vault
2 - Go to "Tools > Reports > Data breach report"
3 - Press the "Check breaches" button
4 - The message "BREACHED ACCOUNTS FOUND" (uppercased and red) is displayed, asking for a manual check on HIBP website
5 - Go to HIBP website (just click on the provided hyperlink by the Web Vault)
6 - See that my email address has not been pwned
### Expected behaviour
I have no subscription running at HIBP, so I do not have an API key. I would expect the Web Vault to remind me that I have not an HIBP API key, but without warning me that I have been pwned (this supposed breach has even a date: August 18th 2019).
### Actual behaviour
See above.
### Troubleshooting data
Here are 2 relevant screenshots
Steps 1 to 4

Steps 5 to 6

This is a feature.
Since you do not have a HIBP API-Key you normally would get an error message.
To make it a bit easier for people to check the mail address we added a custom error message noting that the API-Key is not set and we have added a link to HIBP with the mail addresses provided.
Just read the message carefully, and you would see that it states Manual HIBP Check and that the Key is not set.
@BlackDex commented on GitHub (Mar 19, 2022):
This is a feature.
Since you do not have a HIBP API-Key you normally would get an error message.
To make it a bit easier for people to check the mail address we added a custom error message noting that the API-Key is not set and we have added a link to HIBP with the mail addresses provided.
Just read the message carefully, and you would see that it states **Manual HIBP Check** and that the Key is not set.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @jducaud on GitHub (Mar 19, 2022).
Subject of the issue
My Vaultwarden account email address is said by the Web Vault to be linked to a breach but it does not seem to be.
Deployment environment
Machine: Synology DS218+ (OS: DSM 6.2.4-25556 Update 5)
Docker image: vaultwarden/server 1.24.0 (latest: 6 weeks ago / 187MB) (Web Vault 2.25.1)
Client: Firefox 98.0.1 (64-bit) (connection to the Web Vault) on Microsoft Windows 10 21H2
Reverse proxy and version (on DSM): nginx 1.16.1
Steps to reproduce
1 - Log in to my Vaultwarden account on the Web Vault
2 - Go to "Tools > Reports > Data breach report"
3 - Press the "Check breaches" button
4 - The message "BREACHED ACCOUNTS FOUND" (uppercased and red) is displayed, asking for a manual check on HIBP website
5 - Go to HIBP website (just click on the provided hyperlink by the Web Vault)
6 - See that my email address has not been pwned
Expected behaviour
I have no subscription running at HIBP, so I do not have an API key. I would expect the Web Vault to remind me that I have not an HIBP API key, but without warning me that I have been pwned (this supposed breach has even a date: August 18th 2019).
Actual behaviour
See above.
Troubleshooting data
Here are 2 relevant screenshots
Steps 1 to 4

Steps 5 to 6

@BlackDex commented on GitHub (Mar 19, 2022):
This is a feature.
Since you do not have a HIBP API-Key you normally would get an error message.
To make it a bit easier for people to check the mail address we added a custom error message noting that the API-Key is not set and we have added a link to HIBP with the mail addresses provided.
Just read the message carefully, and you would see that it states Manual HIBP Check and that the Key is not set.