votingworks / vxsuite

https://voting.works
GNU General Public License v3.0
30 stars 6 forks source link

bmd: what do we do when inserting the "wrong" admin card? #707

Closed eventualbuddha closed 2 years ago

eventualbuddha commented 3 years ago

We likely want to allow unconfiguring, but currently we don't check the election hash matches before allowing you to change settings. This means all admin cards are effectively the same for purposes of "authentication". Should we make it so all you can do when putting in an admin card that doesn't match is unconfigure?

benadida commented 2 years ago

this will be solved by the new authentication approach, where admin cards for a diff election have no power, and superadmin can unconfigure.