Sounds like a bug with autocomplete disabled, but I don’t see this as a security issue.
What is the risk with using Bitwarden in this circumstance? That I trust one server of the company but not the other and therefore a bad actor now has my creds?
What is the risk with using Bitwarden in this circumstance? That I trust one server of the company but not the other and therefore a bad actor now has my creds?
To assume that a user trusts the subdomain because she trusts the domain, is something I find insane.