VPN configuration can be disabled from lock screen without authentication
Affected version
GNOME 46.1
Bug summary
The VPN configuration (Wireguard) can be disabled from the lock screen without any authentication which can lead to IP leak and other security issues based on why the VPN is used.
Steps to reproduce
- Setup Wireguard configuration
- Use
wg-quick up config
to enable the configuration - Lock the session using
Super + L
- Access menu on right hand corner
- Click on VPN button to disable the VPN configuration
What happened
VPN configuration have been disabled without any authentication required.
What did you expect to happen
I expect the option not to be present while screen is locked, being grayed out, or asking for password on click.
Relevant logs, screenshots, screencasts etc.
Edited by Colin Heurteaux