You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
function setUp() which initialise the super user is not guided from being called by normal users, even thou this function can only be called once, it can be forgotten by the deployer and smart users can triggers the function earlier than the authorised users and the lost of this control leads to the lost of total control of the protocol.
Recommendation:
it should be treated with carefulness after deployment by calling the init function right after deployment to avoid other unrecognised account calling the function or add a check of who can call the function to secure the setUp() function.
The text was updated successfully, but these errors were encountered:
Description:
function setUp() which initialise the super user is not guided from being called by normal users, even thou this function can only be called once, it can be forgotten by the deployer and smart users can triggers the function earlier than the authorised users and the lost of this control leads to the lost of total control of the protocol.
Context:
AccessControlFacet.sol SLOC10.
Recommendation:
it should be treated with carefulness after deployment by calling the init function right after deployment to avoid other unrecognised account calling the function or add a check of who can call the function to secure the setUp() function.
The text was updated successfully, but these errors were encountered: