What
revoke_delegation (progress-tracker lib.rs:1889) calls Self::require_not_paused(&env) at line 1890, which means learners cannot revoke a delegation while the contract is emergency-paused.
Why
If a delegate address becomes compromised or acts maliciously, the emergency pause is exactly when a learner would most need to revoke delegation. Blocking revocation during pause leaves learners stuck with a potentially malicious delegate who can still submit progress, quiz scores, and retakes on their behalf (since complete_module_for, submit_quiz_score_for, retake_quiz_for all check pause too -- but once unpaused, the malicious delegate can immediately act).
The pause mechanism should freeze state-mutating operations that ADD risk, not operations that REMOVE risk. Revoking a delegation reduces risk and should be allowed at all times.
Scope
Remove Self::require_not_paused(&env); from revoke_delegation (line 1890). This makes revocation always available, matching the principle that safety-critical operations should not be blocked during emergencies.
Acceptance Criteria
revoke_delegation succeeds even when the contract is paused
delegate_progress remains blocked during pause (no change)
- Test verifies revocation works during pause
Technical Context
contracts/progress-tracker/src/lib.rs:1889-1899 -- revoke_delegation
contracts/progress-tracker/src/lib.rs:1857-1870 -- delegate_progress (should stay paused)
What
revoke_delegation(progress-tracker lib.rs:1889) callsSelf::require_not_paused(&env)at line 1890, which means learners cannot revoke a delegation while the contract is emergency-paused.Why
If a delegate address becomes compromised or acts maliciously, the emergency pause is exactly when a learner would most need to revoke delegation. Blocking revocation during pause leaves learners stuck with a potentially malicious delegate who can still submit progress, quiz scores, and retakes on their behalf (since
complete_module_for,submit_quiz_score_for,retake_quiz_forall check pause too -- but once unpaused, the malicious delegate can immediately act).The pause mechanism should freeze state-mutating operations that ADD risk, not operations that REMOVE risk. Revoking a delegation reduces risk and should be allowed at all times.
Scope
Remove
Self::require_not_paused(&env);fromrevoke_delegation(line 1890). This makes revocation always available, matching the principle that safety-critical operations should not be blocked during emergencies.Acceptance Criteria
revoke_delegationsucceeds even when the contract is pauseddelegate_progressremains blocked during pause (no change)Technical Context
contracts/progress-tracker/src/lib.rs:1889-1899--revoke_delegationcontracts/progress-tracker/src/lib.rs:1857-1870--delegate_progress(should stay paused)