Autofill should only use the unlock-PIN also when "Require master password on app restart" is turned on

I don’t know if this is a bug or a missing feature or a “current intended design”,
But I noticed that if you select Unlock vault via PIN code in the app settings and say No to "Do you want to require unlocking with your master password when the application is restarted? "

Now when you try to autofill, you’ll be able to use your PIN code to unlcok vault and gather the item to autofill on that site.

However, now you can also open the app itself, unlcok it and gather access to everything in the vault/settings as well as all security aspects whch isn’t ideal for security.

If you say yes to "Do you want to require unlocking with your master password when the application is restarted? "

You now won’t be able to use PIN code to unlock the vault on the app, but that means you also won’t be able to use the PIN code for Autofill for some reason.

The ideal approach would be to have it so that you must use Master password for the app itself to unlock the vault and access everything, but have the option to use PIN code for unlocking the vault when using the Autofill feature.

Currently this isn’t possible as far as I know. It’s either PIN only within current session after using master password or use PIN everywhere to unlock, including after restart of the Bitwarden app.

Now like I said earlier, I don’t know if this is a bug or a missing feature, but this is something I would like to see implemented.

Thank you for considering this request.

This is related to the following topics:

Hm. I think this bug could also be connected with your issue:

If I understand (and remember) this bug report correctly, then even with both biometric unlock and PIN unlock deactivated – and an unlocked vault – the iOS app still requires the master password for autofill actions (unless the session timeout is set to “never”).

PS: I was the one that changed your title to better reflect your request.