Use pam_succeed_if to make it implicitly ask for the user name and verify that the provided one is correct. This can safely run as user.
Use pam_succeed_if to make it implicitly ask for the user name and verify that the provided one is correct. This can safely run as user.