Skip to content

batch_claim_reward bypasses pause check while claim_reward checks it #497

Description

@DeFiVC

What

batch_claim_reward (learn-token lib.rs:717) does not call Self::require_not_paused(&env), while the single claim_reward (lib.rs:634) does. This means batch reward claims can mint tokens even when the contract is emergency-paused.

// claim_reward checks pause:
pub fn claim_reward(...) {
    Self::require_not_paused(&env);  // line 634
    ...
}

// batch_claim_reward does NOT:
pub fn batch_claim_reward(...) {
    learner.require_auth();  // line 723 -- no pause check
    ...
}

Why

batch_claim_reward mints tokens just like claim_reward. If the contract is paused to stop token minting (e.g., due to a discovered exploit), batch_claim_reward remains functional and can still mint tokens.

Scope

Add Self::require_not_paused(&env); at line 723, before learner.require_auth().

Acceptance Criteria

  • batch_claim_reward panics when the contract is paused
  • Test verifies batch claims are blocked during pause

Technical Context

  • contracts/learn-token/src/lib.rs:634 -- claim_reward (checks pause)
  • contracts/learn-token/src/lib.rs:717-780 -- batch_claim_reward (missing pause check)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programbugSomething isn't workinghighSignificant functionality broken, no workaround, affects multiple usersrustRust language

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions