# Windows 10 Desktop App and WebAuthn not working (mobile, browser extensions work fine)

**URL:** <https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230>\
**Category:** Help\
**Created:** [October 26, 2021, 5:11pm UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230 "2021-10-26T17:11:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![spacedev](https://avatars.discourse-cdn.com/v4/letter/s/7c8e57/32.png) [@spacedev](https://vaultwarden.discourse.group/u/spacedev)\
**Post date:** [October 26, 2021, 5:11pm UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230/1 "2021-10-26T17:11:06Z")

</div>

I’m on the `testing` build of VaultWarden.

When trying to use FIDO2 WebAuthn login on the Bitwarden desktop app on Windows 10, the app displays “Loading” and never progresses. The following occurs in the vaultwarden logs:

```auto
[2021-10-26 10:07:37.321][request][INFO] POST /api/accounts/prelogin
[2021-10-26 10:07:37.321][response][INFO] POST /api/accounts/prelogin (prelogin) => 200 OK
[2021-10-26 10:07:37.358][request][INFO] POST /identity/connect/token
[2021-10-26 10:07:37.396][error][ERROR] 2FA token not provided
[2021-10-26 10:07:37.396][response][INFO] POST /identity/connect/token (login) => 400 Bad Request

```

The mobile apps and browser extensions work as expected with WebAuthn (including the browser extension for Firefox on the same PC as the Desktop app having this issue).

Vaultwarden is hosted on my server at home and only accessible on my local LAN. I followed the HAProxy for pfSense guide to set up the reverse proxy.

DOMAIN variable is set in Unraid Docker for VaultWarden. Domain is also set in admin panel. No trailing / on the domain ([https://vault.mylocaldomain.com](https://vault.mylocaldomain.com)).

[https://vault.mylocaldomain.com/webauthn-mobile-connector.html](https://vault.mylocaldomain.com/webauthn-mobile-connector.html) correctly resolves the WebAuthn image (which is suppose to appear in the desktop app).

Any ideas?

---

<div class="post-metadata">

**Author:** ![ihavebeenpwned](https://avatars.discourse-cdn.com/v4/letter/i/51bf81/32.png) [@ihavebeenpwned](https://vaultwarden.discourse.group/u/ihavebeenpwned)\
**Post date:** [November 3, 2021, 10:13am UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230/2 "2021-11-03T10:13:40Z")

</div>

I have a similar problem on the desktop application

---

<div class="post-metadata">

**Author:** ![ihavebeenpwned](https://avatars.discourse-cdn.com/v4/letter/i/51bf81/32.png) [@ihavebeenpwned](https://vaultwarden.discourse.group/u/ihavebeenpwned)\
**Post date:** [November 15, 2021, 10:50am UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230/3 "2021-11-15T10:50:06Z")

</div>

vaultwarden server responds with these headers:

HTTP/1.1 200 OK  
Content-Type: text/html; charset=utf-8  
Cache-Control: public, max-age=600  
Server: Rocket  
Feature-Policy: accelerometer ‘none’; ambient-light-sensor ‘none’; autoplay ‘none’; camera ‘none’; encrypted-media ‘none’; fullscreen ‘none’; geolocation ‘none’; gyroscope ‘none’; magnetometer ‘none’; microphone ‘none’; midi ‘none’; payment ‘none’; picture-in-picture ‘none’; sync-xhr ‘self’ [https://haveibeenpwned.com](https://haveibeenpwned.com/) [https://2fa.directory](https://2fa.directory); usb ‘none’; vr ‘none’  
Referrer-Policy: same-origin  
X-Frame-Options: SAMEORIGIN  
X-Content-Type-Options: nosniff  
X-XSS-Protection: 1; mode=block  
Content-Security-Policy: frame-ancestors ‘self’ chrome-extension://nngceckbapebfimnlniiiahkandclblb chrome-extension://jbkfoedolllekgbhcbcoahefnbanhhlh moz-extension://\* ;  
Content-Length: 1181  
Date: Mon, 08 Nov 2021 10:30:18 GMT

We discovered a problem for fido2 webauth authorization with 2 headers: X-Frame-Options and Content-Security-Policy

if we disable the following directives on reverse proxy, fido2 authentication works:  
proxy\_hide\_header Content-Security-Policy;  
proxy\_hide\_header X-Frame-Options;

it’s just a workaround and disabling it is probably not good from a security perspective

this should be fixed in the desktop app

e.g.  
github/dani-garcia/vaultwarden/pull/293

---

<div class="post-metadata">

**Author:** ![spacedev](https://avatars.discourse-cdn.com/v4/letter/s/7c8e57/32.png) [@spacedev](https://vaultwarden.discourse.group/u/spacedev)\
**Post date:** [November 23, 2021, 1:22am UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230/4 "2021-11-23T01:22:34Z")

</div>

I removed all my headers from pfSense HAProxy and still have the issue.

I even directly added the IP:Port of BitWarden to the desktop app instead of using the URL and I still have the issue.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [November 23, 2021, 4:23pm UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230/5 "2021-11-23T16:23:59Z")

</div>

Please continue here: [Windows 10 Desktop app FIDO2 Webauthn stuck on "Loading" · Discussion #2111 · dani-garcia/vaultwarden · GitHub](https://github.com/dani-garcia/vaultwarden/discussions/2111#discussioncomment-1688737) to keep all a bit centralized.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [November 23, 2021, 4:24pm UTC](https://vaultwarden.discourse.group/t/windows-10-desktop-app-and-webauthn-not-working-mobile-browser-extensions-work-fine/1230/6 "2021-11-23T16:24:10Z")

</div>


