What
batch_claim_reward (learn-token lib.rs:717) does not call Self::require_not_paused(&env), while the single claim_reward (lib.rs:634) does. This means batch reward claims can mint tokens even when the contract is emergency-paused.
// claim_reward checks pause:
pub fn claim_reward(...) {
Self::require_not_paused(&env); // line 634
...
}
// batch_claim_reward does NOT:
pub fn batch_claim_reward(...) {
learner.require_auth(); // line 723 -- no pause check
...
}
Why
batch_claim_reward mints tokens just like claim_reward. If the contract is paused to stop token minting (e.g., due to a discovered exploit), batch_claim_reward remains functional and can still mint tokens.
Scope
Add Self::require_not_paused(&env); at line 723, before learner.require_auth().
Acceptance Criteria
batch_claim_reward panics when the contract is paused
- Test verifies batch claims are blocked during pause
Technical Context
contracts/learn-token/src/lib.rs:634 -- claim_reward (checks pause)
contracts/learn-token/src/lib.rs:717-780 -- batch_claim_reward (missing pause check)
What
batch_claim_reward(learn-token lib.rs:717) does not callSelf::require_not_paused(&env), while the singleclaim_reward(lib.rs:634) does. This means batch reward claims can mint tokens even when the contract is emergency-paused.Why
batch_claim_rewardmints tokens just likeclaim_reward. If the contract is paused to stop token minting (e.g., due to a discovered exploit),batch_claim_rewardremains functional and can still mint tokens.Scope
Add
Self::require_not_paused(&env);at line 723, beforelearner.require_auth().Acceptance Criteria
batch_claim_rewardpanics when the contract is pausedTechnical Context
contracts/learn-token/src/lib.rs:634--claim_reward(checks pause)contracts/learn-token/src/lib.rs:717-780--batch_claim_reward(missing pause check)