Master Password Re-prompt - configurable grace-period

If we unlock an item with a master password re-prompt, leave the vault unlocked for [30, 60, 90 120] seconds

Feature function

Problem
Some bank sites ask for credentials on two pages, e.g., username on the first page and password on second page. If that bank URL has a master password re-prompt, I need to unlock that item on each page separately.

For example, chase.com has a user + pass with a master password re-prompt. Currently,

  1. Click auto-fill and enter master password.
  2. The first URL only accepts a user name.
  3. Click “Next” to move to the next page.
  4. Click auto-fill and enter master password again.
  5. The second URL only accepts a password.

This issue also occurs with a common bug in credit / debit card entry, where Bitwarden can sometimes requires 2x or 3x auto-fills (on the same URL) to fill all fields (e.g., credit number first time, expiration date second time, and CCV on the third time).

Other times, we need to login into multiple sensitive (i.e., master password re-prompt protected) in a short amount of time, say like two bank accounts to start a transfer. Thus, all re-prompt items should be unlocked and not require a re-prompt in that time.

Solution
It would be helpful if Bitwarden could add global timeout setting that makes the vault with a master password re-prompt have a 30-second (or configurable) window where the vault remains unlocked after being successfully unlocked. Then, you would only need to enter the master password once (unless it takes you longer than 30 seconds to reach the second URL).

It’s not a major issue, though I believe it is a helpful tweak borrowed from LastPass.

Related topics + references

This request is a follow up to the now successfully-implemented Master Password Re-Prompt request.

1 Like