fix: cancel session on interactive auth failure
- Completes PAM transactions on failed passwords while preserving non-interactive sessions for retries. Signed-off-by: Ganga Ram <Ganga.Ram@tii.ae>
This commit is contained in:
parent
cb66d41005
commit
98df07df93
1 changed files with 9 additions and 4 deletions
|
|
@ -1556,12 +1556,17 @@ impl cosmic::Application for App {
|
||||||
self.send_request(Request::PostAuthMessageResponse { response });
|
self.send_request(Request::PostAuthMessageResponse { response });
|
||||||
}
|
}
|
||||||
Message::AuthError(error) => {
|
Message::AuthError(error) => {
|
||||||
|
self.common.error_opt = Some(error);
|
||||||
|
if self.authenticating {
|
||||||
|
// Cancel failed password session so pam_faillock records the attempt.
|
||||||
|
self.authenticating = false;
|
||||||
|
self.send_request(Request::CancelSession);
|
||||||
|
} else {
|
||||||
// The conversation continues, so acknowledge like any other
|
// The conversation continues, so acknowledge like any other
|
||||||
// non-interactive auth message rather than cancelling the session.
|
// non-interactive auth message rather than cancelling the session.
|
||||||
self.common.error_opt = Some(error);
|
|
||||||
self.authenticating = false;
|
|
||||||
self.send_request(Request::PostAuthMessageResponse { response: None });
|
self.send_request(Request::PostAuthMessageResponse { response: None });
|
||||||
}
|
}
|
||||||
|
}
|
||||||
Message::Login => {
|
Message::Login => {
|
||||||
self.common.prompt_opt = None;
|
self.common.prompt_opt = None;
|
||||||
self.common.error_opt = None;
|
self.common.error_opt = None;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue