Skip to main content
September 21, 2026

Bank of Melbourne Internet Banking – fix for 1Password autofill not working

  • September 21, 2026
  • 1 reply
  • 3 views

I’ve had a long-standing problem using 1Password with Bank of Melbourne Internet Banking in Safari: 1Password correctly fills the Customer Access Number, Security Number and Internet Password, but the bank rejects the login. Manually typing the same credentials works.

After doing some fairly extensive debugging, I’ve found the cause and have published a small open-source userscript that fixes it:

GitHub:
https://github.com/garnercx/bank-of-melbourne-password-manager-fix

I’ve tested the published v4.0.0 version end-to-end on macOS/Safari with 1Password: installed directly from GitHub into the Userscripts Safari extension, autofilled with 1Password, and successfully logged into Bank of Melbourne Internet Banking.

What appears to be happening

Bank of Melbourne’s login page does some unusual client-side processing of the Security Number and Internet Password.

Initially I suspected 1Password was bypassing part of that processing, but testing showed something more interesting: the values produced after 1Password autofill were byte-for-byte identical to those produced when I pasted the same credentials manually and allowed the bank’s JavaScript to process them.

So 1Password is not filling the wrong credentials, and the bank’s credential mapping/obfuscation is actually occurring correctly.

The remaining difference turned out to be the field interaction lifecycle.

The bank’s JavaScript attaches processing to focusout on the protected fields and appears to expect those fields to pass through a conventional focus/blur lifecycle. Password-manager autofill doesn’t reproduce that lifecycle in quite the same way as normal user interaction.

The workaround is consequently very small. After detecting password-manager autofill and waiting for it to settle, the userscript gives the Security Number and Internet Password fields a:

focus() -> blur()

cycle.

Importantly, the script does not modify the credentials, implement the bank’s credential mapping, replace the bank’s JavaScript, store or transmit credentials, or submit the login form. It also checks that the values remain unchanged after the workaround is applied.

A couple of other findings

During testing I also reproduced the underlying failure with Apple Passwords, so this doesn’t appear to be a 1Password-specific bug. I haven’t yet tested the finished userscript with Apple Passwords, however, so I’m only claiming tested support for 1Password at this stage.

For 1Password, I have automatic/page-load autofill disabled for the Bank of Melbourne site and deliberately trigger Autofill after the login page has loaded. The README has the complete installation instructions.

I’m posting this partly so that other Bank of Melbourne/1Password users can find the workaround, and partly because the technical cause may be of interest to the 1Password team. If there’s a better way for a userscript to detect completion of a 1Password autofill, or anything in this investigation that would be useful to test from the 1Password side, I’m happy to investigate further.

1 reply

garnercxAuthor
September 23, 2026

I just realised this will probably work for St George Bank and Westpac as they are all part of the same group.