From 6fad5c67b69b4695f7e396ccc378e8475ea27855 Mon Sep 17 00:00:00 2001 From: Christopher Orr Date: Mon, 25 Jan 2021 16:34:34 +0100 Subject: [PATCH] Expand docs about browser permission upgrade in v1.48.0 (#370) * Expand release notes about browser permission upgrade in v1.48.0. By including the text of the dialogs, users can Google the message they see in the somewhat scary looking browser permissions dialog, and land here on the official documentation. * Expand info about browser permissions for Unlock with Biometrics. By including the text of the dialogs, users can Google the message they see in the somewhat scary looking browser permissions dialog, and land here on the official documentation. * Expand security FAQ about nativeMessaging browser permission. By including the text of the dialogs, users can Google the message they see in the somewhat scary looking browser permissions dialog, and land here on the official documentation. --- _articles/account/biometrics.md | 6 ++++-- _articles/faqs/security-faqs.md | 7 +++++-- _articles/getting-started/releasenotes.md | 8 +++++++- 3 files changed, 16 insertions(+), 5 deletions(-) diff --git a/_articles/account/biometrics.md b/_articles/account/biometrics.md index 83fef4f2..4720d3b6 100644 --- a/_articles/account/biometrics.md +++ b/_articles/account/biometrics.md @@ -63,9 +63,11 @@ Once Biometric Unlock is enabled, a new button will be presented on the Unlock s ## Browser Extensions {% callout warning %} -Upon release of Biometric Unlock for Browser Extensions, you may notice that the Browser Extension is flagged by your browser for requiring a new permission. In some cases, browsers will disable the Browser Extension and users will be required to re-enable them. +Version 1.48.0 of the browser extension enables Unlock with Biometrics, if you have at least version 2021-01-19 of the desktop app. -The required permission to `nativeMessaging` is used to facilitate the integration between Browser Extension and Desktop Application that enabled Biometric Unlock, as described in this section. +Note that when your browser updates to this version, you may be asked to accept a new permission called "communicate with cooperating native applications" (in Chromium-based browsers), or "exchange messages with programs other than Firefox." If you don't accept this permission, the extension will remain disabled. + +This permission, also known as `nativeMessaging`, is safe to accept and enables the browser extension to communicate with the Bitwarden desktop app, which is required to enabled Unlock with Biometrics, as described in this section. {% endcallout%} Biometric Unlock is supported for **Firefox** and **Chromium-based** (i.e. Chrome, Edge) Bitwarden Browser Extensions by integration with a native Bitwarden Desktop App. Through the Desktop App's access to Biometric APIs, Browser Extensions support Biometric Unlock: diff --git a/_articles/faqs/security-faqs.md b/_articles/faqs/security-faqs.md index fff28985..f697cb3b 100644 --- a/_articles/faqs/security-faqs.md +++ b/_articles/faqs/security-faqs.md @@ -101,9 +101,12 @@ When this **optional feature** is enabled, clipboard clear will clear any Bitwar #### Q: Why does the Browser Extension need `nativeMessaging` permission? -**A:** Upon the release of [Biometric Unlock for Browser Extensions](https://bitwarden.com/help/article/biometrics/#browser-extensions), you may notice that the Bitwarden Browser Extension is flagged by your browser for requiring a new permission. In some cases, browsers will disable the Browser Extension and users will be required to re-enable them. +**A:** +Version 1.48.0 of the browser extension enables [Biometric Unlock for Browser Extensions](https://bitwarden.com/help/article/biometrics/#browser-extensions). -Bitwarden uses `nativeMessaging` permission to facilitate the integration between Browser Extension and Desktop Application that enables Biometric Unlock. +This permission, also known as `nativeMessaging`, is safe to accept and allows the browser extension to communicate with the Bitwarden desktop app, which is required to enabled Unlock with Biometrics. + +Note that when your browser updates to this version, you may be asked to accept a new permission called "communicate with cooperating native applications" (in Chromium-based browsers), or "exchange messages with programs other than Firefox." If you don't accept this permission, the extension will remain disabled. #### Q: Is Bitwarden FIPS Compliant? diff --git a/_articles/getting-started/releasenotes.md b/_articles/getting-started/releasenotes.md index 947ac93b..7cee74de 100644 --- a/_articles/getting-started/releasenotes.md +++ b/_articles/getting-started/releasenotes.md @@ -22,7 +22,13 @@ Bitwarden believes source code transparency is an absolute requirement for secur ## Release Announcements {% callout info %} -**Browser extensions are getting biometrics** in our 2021-01-19 release! New permission requests are normal (see [here](https://bitwarden.com/help/article/biometrics/#browser-extensions) for details). +**Unlock with Biometrics now works in browser extensions.** + +This is available from v1.48.0 of the browser extension, if you have at least version 2021-01-19 of the desktop app. + +Note that when your browser updates to this version, you may be asked to accept a new permission called "communicate with cooperating native applications," or "exchange messages with programs other than Firefox." This permission is safe to accept, and enables the browser extension to communicate with the Bitwarden desktop app, which is required to enabled Unlock with Biometrics. + +See the [documentation](https://bitwarden.com/help/article/biometrics/#browser-extensions) for more details on how to enable this feature. {% endcallout %} {% callout info %}