Repository navigation
bitwarden userscript does not work on macos #6144
Description
Activity
@JonnyHaystack @typerslow Is anyone of you interested in working on that by any chance? Maybe the Python keyring library would be a better fit?
there is a bitwarden backend for keyring -- that might even provide another way for qutebrowser to interact with bitwarden?
https://pypi.org/project/bitwarden-keyring/
As far as I can tell that keyring package doesn't provide a way for us to support the --auto-lock flag. Which means that in order to not introduce any breaking changes we'd probably have to do something along the lines of checking if keyctl is available, and if it isn't, we'd use the python package without support for --auto-lock.
I've created a script that handles bitwarden cli for MacOS. https://github.com/KaloyanYosifov/qutebrowser-bitwarden-macos
I am using subprocess directly on the security command for MacOS, but it still should be enough. I am using it while I browse with qutebrowser, so it seems to be ok for now.
I would love if there is any feedback to improve the package and if there are any security issues with it. Currently, you just install it for yourself, so I see no issue on using it on your laptop or computer(It is using macOS keychain).
And I've also added an expiration feature, so after 15 minutes you have to reenter your password.
if there are any security issues with it
hi i have not tried it but looking at the warning above i'm afraid to try it. as far as i am concerned, my bitwarden password should not ever appear in cleartext anywhere?
FWIW you can set logging.level.ram to disable debug logging to RAM. At some point there should be a proper password-fill API as part of #30 which can take care of not logging the password, but as long as passwords are handled as generic commands sent from userscripts, that's not possible.
@The-Compiler thanks for the info -- to me such a non-logging input seems very desirable
The userscript I added in the PR #8904 I opened seems to work well so far for me. CI Is failing, but looks unrelated to my changes.
Version info:
qutebrowser v2.0.2
Git commit: f11cdd0 on HEAD (2021-02-04 10:19:33 +0100)
Backend: QtWebEngine (Chromium 83.0.4103.122)
Qt: 5.15.2
Does the bug happen if you start with
--temp-basedir?:yes
Description
after installing pyperclip and tldextract on my macos python installation, i
:spawn --userscript qute-bitwarden. this fails with the error message:FileNotFoundError: [Errno 2] No such file or directory: 'keyctl'this is expected as
keyctldoes not exist on macos, nor is it installable via homebrew. on macos, credentials are managed via the keychain app which also has a cli interface, afaik.unfortunately i'm not knowledgeable how to make this work, but it seems clear that the current bitwarden userscript cannot work on macos.