Skip to main content
May 3, 2022
Question

How do I disable form autosubmit?

  • May 3, 2022
  • 135 replies
  • 10183 views

In 1Password 8 when I fill a login in Safari, it automatically submits the login. I would like 1Password to fill out the fields but not hit the submit button.

In earlier versions of 1Password, I was able to do that but I can’t find the equivalent setting in 1Password 8.

Note: I’m using the Cmd-\ quick access panel to fill in passwords.


1Password Version: 8.7.0
Extension Version: Not Provided
OS Version: macOS 12.3.1

135 replies

May 25, 2022

Ah, I was just coming here to post about this and saw this from earlier this morning. Yes!, Pease, please, please allow us to turn auto-submit off. It's driving me mad. There are just too many cases where I want to do something after auto-filling:

  • I tend to fire auto-fill pretty quickly after loading a page, often before I notice there's a "stay logged in" checkbox that I want to turned on. With auto-submit, I miss the opportunity to toggle it, which means I have to log in again next time I go to the site/app, at which point I repeat the cycle. It's vicious -- takes me a dozen-plus tries to break it sometimes. (Yes, I'm very dense. Or really, just very routine-driven.)

  • I have multiple logins for many things, many logins for a few. As a result, I sometimes choose the wrong one. Up through v7, this wasn't a big deal - I would simply look to see which account got filled and redo it if necessary. Now, I'm slammed into the account whether it's the right one or not, which means I have to wait for the site/app to load, find the logout function and click it, then try it all again. And in some cases (especially when SSO is being used), switching accounts doesn't always work reliably, which means it might take a few tries or even force clearing cookies or switching browsers. And with direct support for contexts outside the browser, there are all new unintended consequences that can happen, like downloading content to the machine with Dropbox or similar, accidentally purchasing an app with the wrong account in the App Store (thus locking it to the wrong account), or accidentally saving a file to the wrong account (MS Office). And some of those unintended consequences can have further consequences with one's employer, compliance, etc.

  • Some sites have secondary controls that appear as you're going through the login process; this is the OP's point. Sometimes, these are on the first page and visible right off the bat, which means I can deal with them if I'm not moving too quickly (see first item above). However, at other times, they only become visible once you fill in the username portion, or worse, they're only visible on the second or third page of a multi-step login process. In these cases, the only thing I can do is go back to my mid-'90s pre-password manager days and copy/paste the credential.

1P_PeterG
Community Manager
Community Manager
May 27, 2022

Hi Former Member, thanks for raising this concern.

So, auto-submit was disabled partly as a security feature in 7.2 and now it is forcibly enabled?

Auto-submit wasn't removed for any security-related reasons. At the time it was based on considerations around usability and the reliability of the experience.

However, I can understand where this might have come from. We have discussed auto-fill options and potential security risks around those in the past, but those potential behaviors diverge from how Quick Access acts.

This is from a blog that our security specialist Goldberg wrote a while back:

Automatically filling a web form with no user intervention other than visiting the page can, if combined with something that works around the anti-phishing mechanism [of 1Password], lead to an attack where lots your usernames and passwords are submitted to a malicious site in a way that is silent and invisible to you.

There are some important considerations here. The original discussion pertained to auto-fill that would be triggered by nothing other than visiting a web page. In the case of Quick Access, you have to tell it to fill. This is the difference between "manual auto-fill" (what Quick Access does) and "automatic auto-fill" (which we are not doing).

Secondly, 1Password's anti-phishing protection offers an additional important measure of security that's worth noting. 1Password won't fill your credentials from domain A into domain B, even if you manually invoke autofill functionality on that site. It has to match the domain you've assigned to the item (although, like in all aspects of security, nothing is bulletproof and our engineers have designed other aspects of 1Password to provide protection in case a malicious website is somehow able to get around this particular defense measure).

We're happy to receive feedback on Quick Access, and whether our current approach is the right one, but I did want to specify that we aren't reversing any previous security design principles or going back on prior reasoning with this feature. 👍

For additional context, I'd highly suggest checking out Goldberg's 2017 blog post in full here, which is, characteristically, an edifying read.

May 27, 2022

Hi @1P_PeterG, I wonder if the mention that Former Member is noting is from this link:
https://blog.1password.com/1password-7.2-for-mac-welcome-to-the-dark-side/#mojave-mo-secure

I don't exactly read that as stating that the removal was for security, but it does seem a reasonable interference from the title of the section (Mojave, mo’ secure) and previous material.

That is the same section that notes:

You’ll also notice that 1Password 7.2 no longer automatically submits passwords once they have been filled. This was a difficult decision to make, but we made it for a few reasons that we wanted to share:

...

We feel strongly that removing the ability to automatically submit passwords is the right call. I’ll be fully transparent, it’s taken some getting used to, but now that it’s part of my workflow… autosubmit? I don’t miss it.

Personally I agree with that, please at least restore this as a user configurable option! The current behavior is pretty broken for many sites I use.

May 27, 2022

1Password 8 will happily auto fill the wrong credentials on subdomains. Which “may” not be a security issue but it sure is annoying. On Wordpress sites auto submit occurs with empty 2FA fields. @1P_PeterG , can you guarantee that 1Password will NEVER accidentally put login information into the wrong fields?

Mostly annoying though is that you are dictating how 1Password works for individual users. You had settings that allowed each user to choose what to do, and you have chosen to remove that choice for users. Pretty I am not alone on this. Sadly 1Password team seems to be sitting on their laurels now that they have market share. This is disappointing, as gone are the days when you listen to your users. 😕

Looking at your own blog, let’s focus on the auto submit portion:

Sometimes a website doesn’t behave as 1Password might expect, resulting in passwords being filled sub-optimally, or fields being left blank. If 1Password were to automatically submit forms in these cases, users are left with an experience that we don’t feel reflects how we want 1Password to work and can lead to confusion.

This hasn’t changed, it is still the case, why has your team deemed your own sales pitch, and this valid issue, now invalid?

@1P_PeterG since you are appearing to deflect by comparing auto fill with auto submit, let me quote the article:

If you are using a password manager that doesn’t allow you to turn that feature off, switch password managers.

This to me, and I suspect to all your users, could apply to auto submit as well.

Any developer worth his salt, knows when to say “we screwed up.” Maybe time for your team to consider this? Forcing auto submit is only one small issue with 1Password 8.

Don’t get me wrong, which is probably easy to do with my rant style here, I do think 1Password could one day be great again. But you need to take a step back and consider that just maybe, some of your decisions are wrong. You are not too big to fail.

Good luck!

Gilles
May 27, 2022

I am very happy with auto-submit
But it would certainly re-assure some people if you make it optional

But please do not remove it

May 27, 2022

Agree 100% with @Gilles. The intent isn't to dictate how a user should use the app, but give them the option to use it how that want, within limits of course. Some users will want to use auto-submit which is fine. Freedom of choice and all that jazz. Which makes me think, could each login have an over ride. For example, if I set auto-submit to false globally, there might be some sites that auto-submit would be preferable on. Could I then enable auto-submit on those specific domains. Or perhaps the other way, global auto-submit is true and then opt out of auto-submit on a few troublesome sites?

I did just discover that using Firefox resolves many of these issues. Safari and 1Password appear to be the big issue here, where firefox doesn't have auto-submit, and 2FA works on sites that won't work in Safari. Hmm.

May 27, 2022

Count me in as one more user who wants a way to disable auto-submit.

I often hit Cmd+Backslash before realizing that I left a "remember me" checkbox unchecked.

May 29, 2022

+1 on being able to disable auto-submit. Went to sign into my lululemon account (on the UK site) and instead of logging me in it filled out the "sign up for our mailing list" box below the login form and submitted that. I note the US site doesn't have that same box in case you try it. It's basically useless if I can't trust it to fill out my details into the right place - will have to stick to 1Password 7 until then.

June 1, 2022

Another +1 for disabling autosubmit, globally across all passwords.

I won't be updating me or my family members to version 8 before this is possible.

I can't believe what I'm seeing, no explanation will suffice why this is not possible anymore in 8.

I will give it a few weeks before starting to look at other options for a password manager, but seeing how big 1Password has become, I fear we're not getting the feature back in years if ever... The personal touch and attention to detail we had with 1Password 10 years ago is long gone.

Jack_P_1P
1Password Employee
1Password Employee
June 3, 2022

Hey @deeogo / @BobW / @mattmaker:

Thanks for your feedback on auto-submit. While I can't promise anything, I'll share your thoughts with the team.

In the meantime, if there's fields you need to edit after the fact (a second portion of the password for example), using the inline menu or the 1Password pop-up to autofill would be your best bet. Let me know how you get on with that!

Jack

ref: dev/core/core#14506