Skip to content

revoke_delegation is blocked during pause, preventing learners from revoking malicious delegates #492

Description

@DeFiVC

What

revoke_delegation (progress-tracker lib.rs:1889) calls Self::require_not_paused(&env) at line 1890, which means learners cannot revoke a delegation while the contract is emergency-paused.

Why

If a delegate address becomes compromised or acts maliciously, the emergency pause is exactly when a learner would most need to revoke delegation. Blocking revocation during pause leaves learners stuck with a potentially malicious delegate who can still submit progress, quiz scores, and retakes on their behalf (since complete_module_for, submit_quiz_score_for, retake_quiz_for all check pause too -- but once unpaused, the malicious delegate can immediately act).

The pause mechanism should freeze state-mutating operations that ADD risk, not operations that REMOVE risk. Revoking a delegation reduces risk and should be allowed at all times.

Scope

Remove Self::require_not_paused(&env); from revoke_delegation (line 1890). This makes revocation always available, matching the principle that safety-critical operations should not be blocked during emergencies.

Acceptance Criteria

  • revoke_delegation succeeds even when the contract is paused
  • delegate_progress remains blocked during pause (no change)
  • Test verifies revocation works during pause

Technical Context

  • contracts/progress-tracker/src/lib.rs:1889-1899 -- revoke_delegation
  • contracts/progress-tracker/src/lib.rs:1857-1870 -- delegate_progress (should stay paused)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programbugSomething isn't workingmediumFunctionality impaired but workaround exists, edge case, partial featurerustRust languagesecuritySecurity concern

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions