Skip to main content
July 13, 2022
Question

Feature Request: Support Universal Autofill in apps created using WebCatalog

  • July 13, 2022
  • 37 replies
  • 2177 views

Long time 1Password user here!

Universal Autofill — one of the hands-down best features of version 8 — stopped working for me in most of my apps due to this change in https://releases.1password.com/mac/8.7/#1password-for-mac-8.7.1: We now verify the code signature of apps before we allow filling using Universal Autofill.

I use over 20 site-specific browser apps (SSBs) created with https://webcatalog.io/webcatalog/. These were all working in 8.7.0, but are now all broken in the later releases of 1Password. I can't describe how hugely disappointing this is, first the joy of having the feature, and then having it taken away without providing an alternative. Universal Autofill really is "magic" and so, so useful. It's a "killer feature".

I have also tested other SSB applications and can confirm this change in 1Password has broken Universal Autofill in them as well. This includes both https://www.bzgapps.com/coherence and https://www.bzgapps.com/unite from https://www.bzgapps.com.

I emailed the BZG and WebCatalog teams, and they confirmed that their apps are indeed signed, so it is something to do with how 1Password verifies the signatures.

I'm just leaving this here for the 1Password team to pick up, with the hope that an appropriate solution can be found (quickly) to restore the feature (even an option to turn off signature verification with a warning would be better), and for anyone else who went through hours of trying to configure accessibility options inside macOS and reinstalling applications only to discover that 1Password quietly removed the feature in an update and without much warning!!

Big love to all the 1Password team.


1Password Version: 8.7.3
Extension Version: 2.3.7
OS Version: macOS 12.4
Browser:_ n/a

37 replies

November 23, 2022

Hi Is this still not working? I too need Universal Autofill working with WebCatalog. Also could anyone confirm if you need the paid for version of WebCatalog for this to work? Thanks

February 3, 2023

I'm a paying customer of https://join.meetsidekick.com/5bjql. Unfortunately their support has been basically non-existent, and the app has a lot of problems. Extensions are part of "Labs" and 1Password along with several other Chrome extensions show up with an error message that says, "This extension is not supported (Manifest V3)."

I started using Sidekick browser and - wow - it is providing all the value I was after with WebCatalog. I tried to stick with the free version but recently switched to Pro because it actually handled my multiple google accounts without a hitch.

The one thing WebCatalog does that's different is creating an app icon for task switching with CMD-tab. Not sure I have a good equivalent for that with Sidekick yet. That said, the experience in Sidekick with Chrome extensions has been flawless so far.

monty

February 6, 2023

This is not a problem with WebCatalog - it's a problem with 1Password. It worked flawlessly with WebCatalog until 1Password decided to remove the Universal Autofill feature for unsigned apps. They have good reason to do so, but have not provided an alternative, or a means for us as end users to override. Even Apple provide a mechanism for us to reduce the security of our systems, with adequate warning, so we can make the best judgement for ourselves. I'm a bit cross with 1Password that they've not done this, and gone totally silent on the issue. I use Coherence X, which does allow for the 1Password Google Chrome plugin to work, but it's flaky and often crashes on me. WebCatalog is still the best SSB I've found, but sadly it is utterly unsupported by 1Password.

February 10, 2023

I too would like to see WebCatalog apps supported, and am disappointed in the response from 1Password.

April 6, 2023

+1 for webcatalog support.

1P_Dave
1Password Employee
April 6, 2023

Thank you for all of your feedback. I've passed on your requests and comments to our development team.

-Dave

ref: dev/core/core#18923
ref: dev/core/core#16253
ref: dev/core/core#23349

June 16, 2023

@1P_Dave Hi Dave -- I've just come back to this thread (a year later from my original post) to see if there's been any update. Universal Autofill is still a dead feature to me due to the restrictions brought in by the 8.7.1 update.

Really disappointed that I was told that Will was on the case, and that hopefully I'd have an update soon (see above). A year later, and no update and no explanation. I've been a customer for over 10 years but this lack of response has left me really disappointed, and tarnished an otherwise fantastic product. Please do take this feedback seriously.

BUT -- Apple announced at WWDC that Safari 17 will be able to create standalone web apps. https://webkit.org/blog/14205/news-from-wwdc23-webkit-features-in-safari-17-beta/#web-apps that "Web apps work with AutoFill credentials from iCloud Keychain and from third-party apps that have adopted the Credential Provider Extension API."

Can you confirm that you are planning to support the Credential Provider Extension API, and therefore password AutoFill should work in standalone web apps produced by Safari 17? This will be a great solution and one that would solve the problem for me.

1P_Dave
1Password Employee
June 19, 2023

@ianjukes

Thank you for following up. The team member that you referred to is on the customer support team, once their initial investigation confirmed the relevant details an internal issue was filed with our development team so that our developers could investigate further. That internal issue is still in our developer's backlog and I don't have any updates to share at the moment. I'm sorry that I'm not able to provide more news.

BUT -- Apple announced at WWDC that Safari 17 will be able to create standalone web apps. I have read that "Web apps work with AutoFill credentials from iCloud Keychain and from third-party apps that have adopted the Credential Provider Extension API."

We don't currently support the Credential Provider Extension API since 1Password already supports filling credentials on macOS using 1Password in the browser and Universal Autofill. I understand that these options don't work for your specific use case and, while I can't make any promises, I've filed a feature request on your behalf to have the team look into supporting the the Credential Provider Extension API in the future.

For the time being, have you considered using a Chromium-based browser to create web apps out of websites? If you create a web app using a browser like Chrome then 1Password in the browser is able to fill into that web app.

-Dave

ref: PB-33771517

June 27, 2023

@1P_Dave

That internal issue is still in our developer's backlog and I don't have any updates to share at the moment.

That's incredibly disappointing on a number of levels. The initial point I made remains: you released a new feature that was so incredibly helpful, and then pulled it from a later release. A year later still no updates to share.

We don't currently support the Credential Provider Extension API since 1Password already supports filling credentials on macOS using 1Password in the browser and Universal Autofill.

I believe the Credential Provider Extension API is a new feature of macOS Sonoma (?) so I'm not surprised you don't currently support it. My comment was really the hope that you might support it by release of Sonoma later this year, and then 1Password will work with the new Safari web apps when they launch with Sonoma. Please please consider this.

For the time being, have you considered using a Chromium-based browser to create web apps out of websites? If you create a web app using a browser like Chrome then 1Password in the browser is able to fill into that web app.

Yes. I have investigated every option. I won't go into why this is a poor solution for my use case.

1P_Dave
1Password Employee
June 27, 2023

I'm sorry for the disappointment. For security reasons, Universal Autofill currently requires a valid code signature on all apps that it fills into. WebCatalog apps use "adhoc" code signatures which have no cryptographic proof to back up their validity and are not compatible with Universal AutoFill.

Universal Autofill initially working with apps that use ad-hoc signatures was a bug that was resolved in version 8.7.1 (as you said in your initial post): We now verify the code signature of apps before we allow filling using Universal Autofill.

As mentioned, we do have an internal work item open to investigate supporting ad-hoc signatures without compromising on the security of Universal Autofill but I can't make any promises on when, or if, our development team will be able to build this support. Supporting ad-hoc signatures requires both security and development work and, to be honest, we've received only a limited number of requests to build this support so far.

I know that this isn't the answer that you were hoping for. The request remains filed with the team internally and the team and I will continue to track requests from customers and to advocate to our development team that this is something that some folks find necessary for their workflow.

-Dave