[lockscreen] Typed-in passcode is preserved on the lockscreen even after locking the device
Device:
- OS: postmarketOS edge aarch64 (updated today)
- Host: Pine64 PinePhone (1.2)
- Kernel: 5.13.12
Description:
When on the lockscreen, if a user types in a passcode without pressing the submit button, and locks their screen with the power button, the typed-in passcode will still be preserved after turning it back on again - allowing anyone to press "submit" to access the device.
Steps to Reproduce:
- Turn on device
- Use passcode to log in (it seems I cannot lock it without logging in first - another issue?)
- Lock device and turn it back on
- Type in full passcode without hitting the submit button
- Lock device and turn it back on
- Observe that the passcode is still available to be submitted
Expected Behavior:
Plasma Mobile would wipe anything that is typed in on the lockscreen upon locking the device, or at least bring back the default screen of the lockscreen.
Actual Behavior:
Plasma Mobile left me at the passcode screen open and did not wipe the typed-in passcode, potentially allowing access into the device.
Edited by Devin Lin