Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is force_login supposed to prompt user to re-enter their PIN? #535

Open
totszwai opened this issue Jun 21, 2024 · 0 comments
Open

Is force_login supposed to prompt user to re-enter their PIN? #535

totszwai opened this issue Jun 21, 2024 · 0 comments
Labels

Comments

@totszwai
Copy link

https://github.com/OpenSC/libp11/blob/master/src/eng_back.c#L211

Looking at the code, if force_login is set, and they are already logged in, it just returns true.

Shouldn't we force it to log out first if force_login is enabled?

+	if (ctx->force_login && slot_logged_in(ctx, slot))
+        	PKCS11_logout(slot);
+
 	if (!(ctx->force_login || tok->loginRequired) || slot_logged_in(ctx, slot))
 		return 1;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants