Bitwarden infrastructure/backend (API, database, Docker, etc). https://bitwarden.com
  • C# 83.8%
  • TSQL 9.9%
  • Handlebars 4.2%
  • Rust 0.8%
  • HTML 0.7%
  • Other 0.4%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
cd-bitwarden 77bb391404
[Sm-1588] secrets versioning (#8307)
* Ensuring the creation date and update date are used correctly, and that editorName gets returns to clients side properly

* Record the previous value and date in secret version snapshots

SecretUpdateRequestModel.ToSecret mutates the entity in place and returns
the same reference, so originalSecret aliased the already-updated secret
and every version snapshot stored the new value rather than the previous
one. Capture the value and revision date before ToSecret runs.

VersionDate used the secret's CreationDate, which never changes, so every
version for a secret shared one timestamp. That made OrderByDescending a
total tie, leaving history order arbitrary, and let the retention prune in
CreateAsync delete the newest versions instead of the oldest. Use the
revision date of the value being archived. The restore path had the same
problem using DateTime.UtcNow, which collided with the secret's new
revision date, so it now keeps the date the archived value was set.

Drop EditorName from the version response. Machine account names are
encrypted with the organization key, which the server cannot read, so the
field carried ciphertext for service-account editors and plaintext for
user editors. Callers get EditorServiceAccountId and
EditorOrganizationUserId instead and can resolve a display name from data
they have already decrypted. This also removes the per-version editor
lookups along with the IServiceAccountRepository and IUserRepository
dependencies they needed.

Add tests for the update and restore snapshots, the get-by-ids endpoint,
and the ten-version retention cap, none of which were covered.

* undoing changes to tests that shouldn't have been changed

* Updates to code to allow for editor name to be shown on the secrets versioning UI, extracted logic into a command for adding and updating new Secret Versions. Adding and updating relevant tests

* updating comment to be clearer

* Update src/Core/SecretsManager/Models/Data/SecretVersionDetails.cs

Co-authored-by: Rui Tomé <108268980+r-tome@users.noreply.github.com>

* The API was returning raw ID numbers for the editor, which the UI can't display. I added a way to look up the actual names.

Member names are stored as plain readable text, but machine-account names are encrypted and the server genuinely cannot read them. So these can't be one combined "name" field — the member name is sent as-is, and the machine-account name is sent still-encrypted for the browser to unscramble.

Saving a secret and saving its version-history entry were two separate operations. If the first succeeded and the second failed, the secret was already permanently saved but the user got an error screen — so they'd try again and end up with two copies of the same secret.

The fix is like a bank transfer: both steps now happen inside a single all-or-nothing operation. If the version entry fails, the secret save is undone too, so the user's retry is safe.

* ensure the person reading editor names is allowed

* auditing comments for correctness

* Removing unused code and fixing tests

* adding comments

* fixing backfill issue where secrets without an initial secret version upon change doesn't retain version history

* suggested improvements

* Skip version pruning on the secret create path

A secret created in the same transaction has no version history, so the
retention query in AddWithPruningAsync always came back empty - one wasted
round-trip per secret created.

Extract the id-assignment and mapping step into SecretVersionWriter.AddAsync
and have CreateAsync call that instead. AddWithPruningAsync keeps its pruning
logic and delegates to AddAsync, as does TryBackfillPreviousVersionAsync, so
the ValueGeneratedNever id rule stays defined in one place.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* updating the code to use the feature flag properly now that the PR adding the feature flag has been merged

* fixing claude suggestions

---------

Co-authored-by: Rui Tomé <108268980+r-tome@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 18:45:58 -04:00
.aspire Aspire Integration (#6775) 2026-05-15 16:57:23 +00:00
.claude [PM-39925] feat: scaffold the Bit.Subscription.* and Bit.Invoicing libraries for invoice preview (#8208) 2026-08-26 14:23:36 -05:00
.config [deps] Billing: Update swashbuckle-aspnetcore monorepo to 10.1.7 (#7008) 2026-04-07 09:38:14 -05:00
.devcontainer [deps] BRE: Update mcr.microsoft.com/mssql/server Docker tag to v2025 (#6447) 2026-06-11 11:07:07 -04:00
.git-hooks Migrate to SLNX Style Solution (#7645) 2026-05-15 18:05:38 +00:00
.github Rename PR target workflow for clarity (#8341) 2026-09-11 10:00:30 +02:00
.run Add Rider launch configurations (#2646) 2023-01-31 06:20:46 +10:00
.vscode chore(launch/tasks): Upgrade for .net10 (#7584) 2026-05-05 12:05:49 -04:00
AppHost feat(saml): SimpleSaml local assertion encryption (#8319) 2026-09-09 14:33:26 -04:00
bitwarden_license [Sm-1588] secrets versioning (#8307) 2026-09-14 18:45:58 -04:00
dev feat(saml): SimpleSaml local assertion encryption (#8319) 2026-09-09 14:33:26 -04:00
perf Bumped version to 2026.9.0 (#8321) 2026-09-07 13:43:38 +00:00
src [Sm-1588] secrets versioning (#8307) 2026-09-14 18:45:58 -04:00
test [Sm-1588] secrets versioning (#8307) 2026-09-14 18:45:58 -04:00
util [Sm-1588] secrets versioning (#8307) 2026-09-14 18:45:58 -04:00
.dockerignore Bitwarden Unified Self-Host project (#2410) 2022-11-18 14:39:01 -05:00
.editorconfig Make CA1304 & CA1305 warnings (#6813) 2026-01-13 04:02:56 -05:00
.git-blame-ignore-revs Add instructions (#2232) 2022-08-30 12:17:17 -04:00
.gitattributes Run dotnet format (#1764) 2021-12-16 15:35:09 +01:00
.gitignore [PM-39925] feat: add the invoice preview projection to Bit.Invoicing (#8209) 2026-08-26 15:00:49 -05:00
bitwarden-server.slnx [PM-39925] feat: scaffold the Bit.Subscription.* and Bit.Invoicing libraries for invoice preview (#8208) 2026-08-26 14:23:36 -05:00
CONTRIBUTING.md Update README and CONTRIBUTING to point to contributing.bitwarden.com (#2028) 2022-06-09 12:00:58 +02:00
Directory.Build.props Bumped version to 2026.9.0 (#8321) 2026-09-07 13:43:38 +00:00
global.json Server update sdk (#8128) 2026-08-03 14:40:30 -04:00
LICENSE.txt Update paths to point to main instead of master (#3699) 2024-01-24 09:48:03 -05:00
LICENSE_AGPL.txt split license file out to support bitwarden licensed code (#912) 2020-09-04 13:36:22 -04:00
LICENSE_BITWARDEN.txt Update paths to point to main instead of master (#3699) 2024-01-24 09:48:03 -05:00
LICENSE_FAQ.md Update paths to point to main instead of master (#3699) 2024-01-24 09:48:03 -05:00
README.md Remove Gitter chat badge from README (#7138) 2026-03-04 16:28:31 +00:00
SECURITY.md Update SECURITY.md (#1913) 2022-03-15 15:54:08 -04:00
TRADEMARK_GUIDELINES.md Update TRADEMARK_GUIDELINES.md 2021-03-26 14:04:27 -04:00

Bitwarden

Github Workflow build on main


The Bitwarden Server project contains the APIs, database, and other core infrastructure items needed for the "backend" of all bitwarden client applications.

The server project is written in C# using .NET Core with ASP.NET Core. The database is written in T-SQL/SQL Server. The codebase can be developed, built, run, and deployed cross-platform on Windows, macOS, and Linux distributions.

Developer Documentation

Please refer to the Server Setup Guide in the Contributing Documentation for build instructions, recommended tooling, code style tips, and lots of other great information to get you started.

Deploy

docker

You can deploy Bitwarden using Docker containers on Windows, macOS, and Linux distributions. Use the provided PowerShell and Bash scripts to get started quickly. Find all of the Bitwarden images on GitHub Container Registry.

Full documentation for deploying Bitwarden with Docker can be found in our help center at: https://help.bitwarden.com/article/install-on-premise/

Requirements

These dependencies are free to use.

Linux & macOS

curl -s -L -o bitwarden.sh \
    "https://func.bitwarden.com/api/dl/?app=self-host&platform=linux" \
    && chmod +x bitwarden.sh
./bitwarden.sh install
./bitwarden.sh start

Windows

Invoke-RestMethod -OutFile bitwarden.ps1 `
    -Uri "https://func.bitwarden.com/api/dl/?app=self-host&platform=windows"
.\bitwarden.ps1 -install
.\bitwarden.ps1 -start

Production Container Images

View Current Production Image Hashes (click to expand)

US Production Cluster

Service Image Hash
Admin admin
API api
Billing billing
Events events
EventsProcessor eventsprocessor
Identity identity
Notifications notifications
SCIM scim
SSO sso

EU Production Cluster

Service Image Hash
Admin admin
API api
Billing billing
Events events
EventsProcessor eventsprocessor
Identity identity
Notifications notifications
SCIM scim
SSO sso

We're Hiring!

Interested in contributing in a big way? Consider joining our team! We're hiring for many positions. Please take a look at our Careers page to see what opportunities are currently open as well as what it's like to work at Bitwarden.

Contribute

Code contributions are welcome! Please commit any pull requests against the main branch. Learn more about how to contribute by reading the Contributing Guidelines. Check out the Contributing Documentation for how to get started with your first contribution.

Security audits and feedback are welcome. Please open an issue or email us privately if the report is sensitive in nature. You can read our security policy in the SECURITY.md file. We also run a program on HackerOne.

No grant of any rights in the trademarks, service marks, or logos of Bitwarden is made (except as may be necessary to comply with the notice requirements as applicable), and use of any Bitwarden trademarks must comply with Bitwarden Trademark Guidelines.

Dotnet-format

Consider installing our git pre-commit hook for automatic formatting.

git config --local core.hooksPath .git-hooks