Not matching Subdomains

Options
cspeper
cspeper
Community Member
edited October 2022 in 1Password in the Browser

I have a set of logins that do not show up as suggestions when their sites match a subdomain.
You can see in the screenshot that I can search for a login with the website:

https://deploy-preview-1770--whoosh-staff.netlify.app/login

However, it does not show up automatically when I'm on the site:

https://deploy-preview-1837--whoosh-staff.netlify.app/login

Even though they differ only in their subdomain. Other sites seem to match correctly across subdomains. Is there something I should be doing differently?

Comments

  • ajahn
    ajahn
    Community Member
    Options

    Subdomain support has been talked about here since 2013. Is this support something that is being worked on? We use SSO at work and there are many URLs that get matched because they use the same domain name. (Sorry to hijack your post, cspeper) :-)

  • kirsch
    kirsch
    Community Member
    Options

    This is driving me bonkers. It also doesn't seem from an outsider's point of view as something terribly difficult to implement.

    Any or all of the following would be great:

    • display subdomains in suggestions
    • suggest subdomains first
    • allow us to set a checkbox in the item that says "only match subdomain" or something to that end

    I rely on 1Password to do a lot of development and I have a lot of subdomains with separate logins but different passwords... as I should. 1Password should simplify this best practice. The people most likely to run into this are also most likely to be your power users and most ardent evangelinsts.

    Thanks!

  • ajahn
    ajahn
    Community Member
    Options

    @kirsch Yes. Exactly!

  • willb
    willb
    Community Member
    Options

    Same problem here. All of our test sites on .cloudways or .wpengine or our own dev server show all of the logins for all the subdomains. we have shared vaults for the team and it lists all of everybodies login. yikes! For our test server thats high tens of logins. horrible. its ok for the first month and steadily becomes totally unworkable as the list builds up.

  • @cspeper @ajahn @kirsh @willb

    I apologize for the delay in responding and would like to thank you all for your feedback on this matter. We are aware that many of our users would like to have 1Password support advanced matching rules for browser autofill such as matching subdomains. Although I cannot guarantee if or when it will be implemented, we have an internal feature request for this issue that I will gladly add votes to for each of you to increase visibility for our product team.

    Let me know if you have any other questions or feedback, we are always happy to hear how we can improve 1Password. :)

  • elidor
    elidor
    Community Member
    Options

    That subdomain feature would be helpful for me too. I use different services for a project of mine on several subdomains but i did not implement SSO so every time I want to login to one of them, I have to scroll through a list of 10 or so entries to find the correct login although I tol 1P8 the correct subdomain in the "Website" field.

  • Hey @elidor,

    Thank you for your feedback, I have added your vote.

    Have a great week!

  • DenalB
    DenalB
    Community Member
    Options

    Looks like this feature is implemented in the new beta builds. Just updated to 1Password for Windows 8.9.11 (80911001).

    Here, you can choose the following settings:

    And this setting is available in 1Password beta for Firefox 2.6.1.:

    Actually, I don't know if these settings belong together. Let's test ... 😉

  • Hobyvh
    Hobyvh
    Community Member
    Options

    Is there an update on this, when it might be out of beta? I'd really like 1Password to support both situations with a toggle. I currently have an ongoing need for matching across subdomains that would really benefit from this.

  • Hi @Hobvyh,

    The Autofill Behavior feature is available in the latest stable release (8.10.0) of the 1Password app. Let us know what you think! 🙂

  • BesieDai
    BesieDai
    Community Member
    Options

    This thread was the first time I heard about this feature, and lucky me I am already running 8.10.0 (macOS). I changed all my subdomain logins to "Only fill on this exact domain" and restarted 1Password, but the + \ window hasn't changed, it still suggests everything from that parent domain, and not always in a well-sorted order either.

  • Ben
    Options

    Hi @BesieDai

    Could you please let me know a little more about your setup?

    Also, do the changes you've made affect the in-line menu from 1Password in your browser, but not Quick Access?

    We'll be happy to troubleshoot with you. Thanks!

    Ben

  • BesieDai
    BesieDai
    Community Member
    Options

    I'm using Firefox 110.0.1, with the 1P extension 2.6.0. I also explored this with Chrome 110.0.5481.177 (1P extension 2.7.0).

    In Firefox, nothing is auto-suggested. I prefer to use ⌘ + \ instead of moving my hands to the arrow keys or mouse. And when I do bring up the 1P prompt, it's suggesting all the items for my parent domain in the wrong order.

    In Chrome, there is a dropdown suggestion whenever the cursor is in a password field. And that dropdown seems to sort the most relevant one (the matching subdomain) at the top, with the others matching the parent domain below it. But as soon as I hit ⌘ + \, I get the wrongs ones suggested first.

    And when that happens, I can't determine what the sorting order is, it's not alphabetical. The one almost always suggested first has a local ip as its primary website. So imagine this: I go to portainer.mydomain.com, open the 1Password shortcut, and not only does it first suggest the login for "MinIO Console", but the website shown in the display isn't even the one that should be matching the pattern.

  • spacecaps
    spacecaps
    Community Member
    Options

    I am also seeing problems with subdomain matching where I have two Okta accounts for work that are on different sub-domains, call them acme.okta.com and acme-cloud.okta.com. Both are configured with the new "only match this exact domain" setting.

    What I have observed is:

    On acme.okta.com I only get prompted with that exact login as expected. Verified in Firefox, Chrome, Safari, and 1p Quick Access

    On acme-cloud.okta.com:

    • in 1p Quick Access or Firefox I see both logins and acme.okta.com is the first option
    • in Chrome or Safari I see both logins, but acme-cloud.okta.com is the first option
    • if the acme.okta.com login is favorited in 1p (which is how I have it) then Chrome/Safari show it as the first option just like Firefox and 1p Quick Access do in either case
    • in all these cases I expected that only the acme-cloud.okta.com login would be shown

    1Password for Mac 8.10.4 (81004032)
    1Password for Firefox 2.9.0
    1Password for Chrome 2.9.0
    1Password for Safari 2.9.0

This discussion has been closed.