Bug 405355 - Bypass of password login in kscreenlocker after resuming screens from energy save mode.
Summary: Bypass of password login in kscreenlocker after resuming screens from energy ...
Status: RESOLVED WORKSFORME
Alias: None
Product: kscreenlocker
Classification: Plasma
Component: general (show other bugs)
Version: unspecified
Platform: Arch Linux Linux
: VHI critical
Target Milestone: ---
Assignee: Plasma Bugs List
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-03-11 17:02 UTC by Oskar Roesler
Modified: 2020-02-20 18:55 UTC (History)
4 users (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Oskar Roesler 2019-03-11 17:02:43 UTC
SUMMARY
After resuming and screens get on (no standby), you get a similar problem like on this issue (https://bugs.kde.org/show_bug.cgi?id=360421), but without any heavy CPU load. Switching to another tty and back and you're logged in without typing a password.

STEPS TO REPRODUCE
1. Wait that your screens get locked and off.
2. Resume from energy save mode. Probably, like in the other named issue, mouse and keyboard will both work, but don't get recognized by plasma.
3. Switch to a diffrent tty and back to the tty of xserver

OBSERVED RESULT
You're logged in without typing in the password.

EXPECTED RESULT
You see the login screen and get asked for password when using mouse or typing.


SOFTWARE/OS VERSIONS
Linux/KDE Plasma: Arch Linux kernel 5.0.0-1
(available in About System)
KDE Plasma Version: 5.15.2
KDE Frameworks Version: 5.55.0
Qt Version: 5.12.1

ADDITIONAL INFORMATION
Similarities with this bug: https://bugs.kde.org/show_bug.cgi?id=360421
Video of Bug: https://ipfs.io/ipfs/QmcuiLnyWHHqLmuhSi3GGyiRZn7H3ZLZcqbMBwHZr4pyDc
Comment 1 Oskar Roesler 2019-03-11 17:10:49 UTC
kscreenlocker 5.15.2-1
Comment 2 Oskar Roesler 2019-03-17 09:57:51 UTC
I can't reproduce this behavior with kscreenlocker 5.15.3-1. 
Can someone confirm this?
Comment 3 spinnix 2020-01-17 02:56:58 UTC
I did it.

Watch my bug report.

https://bugs.kde.org/show_bug.cgi?id=416344
Comment 4 David Edmundson 2020-02-20 18:55:52 UTC
works for oskar, lets only have spinnix's