Cordero Core 13bb0a0308 fix(webapp): resolve three errors in the webapp typecheck (#356)
`npx tsc -p webapp/tsconfig.json --noEmit`, one of the checks recommended
in CONTRIBUTING.md, currently fails on main with three errors. All three
are declaration defects with correct runtime behavior; none changes
observable behavior.

- api/backup.ts: downloadAdminBackupAttachmentBlob declared a bare
  Uint8Array return. Since TypeScript made typed arrays generic, that
  widens to Uint8Array<ArrayBufferLike> and no longer satisfies fflate's
  Uint8Array<ArrayBuffer>. The body already returns an ArrayBuffer-backed
  value, so this only annotates what it produces.

- backup-center.ts: invalidateRemoteBrowserCacheForDestination declared a
  full PersistedRemoteBrowserState but builds four of its five fields.
  The sole caller reads .cache only, so the return type is narrowed to
  match what the function actually returns.

- password-security-cache.ts: getPasswordSecurityState declared the public
  PasswordSecurityState, but startPasswordSecurityScan needs `controller`,
  which lives on InternalPasswordSecurityState. An internal accessor keeps
  `controller` off the exported type rather than widening the public API.

No change to backup payload shape, archive/import whitelists, or any
persisted format.

Verified with tsc 5.9.3, 6.0.3, and 7.0.2 (all exit 0 for both
webapp/tsconfig.json and tsconfig.json), plus npm run build and
npm run i18n:validate.
2026-08-30 01:31:37 +08:00
2026-06-20 00:01:36 +08:00
2026-07-08 11:59:17 +08:00
2026-07-17 11:38:42 +08:00
2026-07-17 11:38:42 +08:00
2026-06-23 00:07:46 +08:00

NodeWarden Logo

Bitwarden-compatible server running on Cloudflare Workers

Powered by Cloudflare License: LGPL-3.0 Latest Release

Telegram Channel | Telegram Group

中文 | Contributing | Official wiki

Disclaimer
This project is for learning and discussion purposes only. Please back up your vault regularly.
This project is not affiliated with Bitwarden. Please do not report NodeWarden issues to the official Bitwarden team.


Feature comparison with the official Bitwarden server

Feature Bitwarden Free NodeWarden Notes
Web vault Original Web Vault UI
TOTP Includes steam:// support
PWA / offline Installable, offline
Passkey login passwordless auth
API keys CLI keys; create and rotate
Login 2FA TOTP, YubiKey, Passkey
2FA recovery codes One-time 2FA disable codes
Real-time push sync All device sync
Attachments / Send Cloudflare R2 or KV
Import / export Bitwarden JSON / CSV / ZIP
Cloud backup center Scheduled WebDAV / S3 incrementals
Device management Remove devices; trust controls
Login requests Cross-device login approval/unlock
Multi-user Invite-code registration
Domain rules Equivalent domains, global exclusions
Fill-assist POST /fill-assist
Organizations / collections / roles Not implemented
SSO / SCIM / directory Not implemented

Tested clients

  • Windows desktop
  • Mobile app
  • Browser extension
  • Linux desktop
  • ⚠️ macOS desktop not fully verified yet

Visual quick deploy

  1. Fork the NodeWarden repository to your GitHub account
  2. Open Cloudflare Workers & Pages
  3. Choose Continue with GitHub and select your fork
  4. Set build command to npm run build and deploy command to npm run deploy
    • For KV mode, change the deploy command to npm run deploy:kv
  5. After deployment finishes, open the generated Workers URL
  • The default Workers hostname may be unreachable on some networks. To use a custom domain, add it in Workers settings.

  • If the site reports a missing JWT_SECRET, add it as a Secret in Workers settings. In production use a random string of at least 32 characters; do not use temporary or example values.

  • To hide the Web Vault, add a text variable named HIDE_WEB_VAULT with the value 1 under Workers settings → Variables and Secrets. While enabled, server-hosted frontend pages and static assets return 404 Not Found, while the login, sync, attachment, icon, notification, and other server endpoints used by Bitwarden clients remain available; an already installed or cached PWA can continue using its local frontend. Delete the variable (or change it to anything other than 1) to restore the server-hosted Web Vault.

  • In this flow you hand code to Cloudflare to build and deploy. wrangler.toml or wrangler.kv.toml in the repo defines binding names; the Worker initializes the D1 schema on first request—no manual SQL upload.

Tip

Default R2 vs optional KV:

Storage Card required Max single attachment / Send file Free tier
R2 Yes 100 MB (soft limit, adjustable) 10 GB
KV No 25 MiB (Cloudflare limit) 1 GB

How to update

  • Manual: open your fork on GitHub; when the sync banner appears, click Sync forkUpdate branch

CLI deploy

git clone https://github.com/shuaiplus/NodeWarden.git
cd NodeWarden

npm install
npx wrangler login

# Default: R2 mode
npm run deploy

# Optional: KV mode
npm run deploy:kv

# Local development
npm run dev
npm run dev:kv

License

LGPL-3.0 License


Credits


Contributors

NodeWarden contributors

Star History

Star History Chart
Languages
TypeScript 93.4%
CSS 4.7%
JavaScript 1.3%
HTML 0.6%