The user having the right to unlock their session isn't the issue, rather there are a number of supported mechanisms for unlocking, namely A) password B) fingerprint. AFAIK pressing a game controller button isn't one of them. Either this should be fixed/mitigated in gnome-shell, or somewhere lower in the stack like PAM or systemd
The ublue project serves to integrate a whole bunch of software in their images outside of flatpak which means a lot of software is being run in the same security context
It's pretty ridiculous you would have to do that in the first place because people will know about this development and use it as ammunition to show that Gnome developers are out of touch