It's currently possible to add or delete fingerprints from a session without asking again for user authentication. This can be a serious security issue as any temporary guest using the machine could enroll his fingerprints and then have access.
Created attachment 137936 [details] [review] device policy: only allow enroll for authenticated users Ensure a password prompt is shown when enrolling, and fingerprint management is requested.
Fairly certain this wasn't tested (or at least wasn't tested after the "auth keep" had timed out). *** This bug has been marked as a duplicate of bug 89407 ***
Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.