Duo 2FA stuck to login through the bitwarden extension!

Anyone else have Bitwarden waiting for DUO?
After logging into bitwarden a popup appears to launch my duo two-steps.
However after clicking on launch Duo, bitwarden keeps loading without going through to Duo to verify my login.
Bit1

Same here… Maybe someone will fix it cuz our company is stuck :smiley: We write to support but still no answer…

In the meantime I discovered that the problem must be with the Edge extension version 2024.9.1.
Because it works if I go directly to bitwarden vault.

It dont work on google chrome, opera, firefox too so its problem with extension I think…

@Doohie Hi! I changed the tag of this thread from “Authenticator” (which would be the 2FA-authenticator app of Bitwarden) to “Password Manager” since you are talking about the browser extension for Edge. I also set it to “cloud-default” for now - or are you self-hosting?

1 Like

I dont use self-hosting…

1 Like

To be honest, I have no clue about DUO. But if it worked yesterday and not today (and the browser extension didn’t get an update since yesterday), it could be connected to the Bitwarden server update (to 2024.9.2) a few hours ago, I would think.

(first, I thought of a browser update being the culprit too, but if several browsers are affected, I don’t think that that’s the deciding factor)

Would be interesting to know, whether the mobile apps are also affected.

Also think this is going to be the reason,
Hope this gets fixed soon.
Everything works until the extension redirects you and hangs on …vault.bitwarden.com/duo-redirect-connector…

… yeah… though, it could also be, that there is a new “incompatibility” between server and the extensions, and the fix will come with the new upcoming extensions versions (just speculation) :thinking:

PS: I don’t see a matching issue on GitHub - maybe contact support (again?) and/or open an issue on GitHub (Issues · bitwarden/clients · GitHub) so that the team get’s (more) aware of the problem.

Can or would you do this for me please ?

I don’t experience this problem - you would have to describe the circumstances etc.

So the extension works for you?

I don’t use Duo. :sweat_smile:

1 Like

I am having the same issue as laid out by @Doohie.

When trying to log into my vault using the Bitwarden extension in Edge, it is getting stuck on the Bitwarden DUO Redirect Connector page. I am able to log into my WebVault using the same DUO authentication methods.

I tried reinstalling the extension thinking that it could be out of date, but that lead to the same behavior described above.

I’ve been experiencing the same problem as @Doohie and @megawattz . Only reason I was able to log into Bitwarden this morning is because I’d installed a Yubikey as a secondary second-factor option and I carry the Yubikey with me just in case. Chrome pops out the Bitwarden DUO Redirect Connector page and then just sits there and spins. There’s nothing wrong or different on the DUO end as far as I can see; it’s only Bitwarden’s 2fa that’s causing problems with it.

EDIT: just tested Leostream, another app my company has that uses DUO for 2fa. It behaves normally and we get a DUO push prompt upon login to verify the user, same as we always do. I used the same Chrome browser on the same PC to connect to Leostream that I did for Bitwarden. Leostream can get an instant DUO push. Bitwarden hangs.

Thank you all for the reports. We’re investigating this issue now.

4 Likes

Not sure if it helps, but I see two errors in the dev console. One where the browser is refusing to apply inline style because of a violated Content Security Policy. The other being an error in duo-redirect.ts stating “Invalid redirect URL”.

Just to be sure, I reported it on GitHub too.

1 Like

Very good! But I’m not sure, if this is already solved now and to be included in the next release: Auth/PM-13103 - Fix Users with Frameless Duo 2FA not being able to login by JaredSnider-Bitwarden · Pull Request #11363 · bitwarden/clients · GitHub ?

Just to let you know that everything is working perfectly again.
Browsers Used - Firefox and Edge.

1 Like