Skip to content

create_vesting bypasses pause state check in learn-token #499

Description

@DeFiVC

What

create_vesting (learn-token lib.rs:1479) does not call Self::require_not_paused(&env). The admin can create new vesting schedules while the contract is emergency-paused.

Compare with claim_vested (lib.rs:1523) which correctly checks pause.

// create_vesting -- no pause check:
pub fn create_vesting(...) {
    let admin = storage::get_admin(&env);
    admin.require_auth();  // line 1487 -- no require_not_paused
    ...
}

// claim_vested -- checks pause:
pub fn claim_vested(...) {
    Self::require_not_paused(&env);  // line 1523
    ...
}

Why

During an emergency pause, an admin could create vesting schedules that lock tokens, potentially as part of an attack or to prepare actions for when the contract is unpaused. The pause should freeze all state-changing operations.

Scope

Add Self::require_not_paused(&env); at line 1486, before admin.require_auth().

Acceptance Criteria

  • create_vesting panics when the contract is paused
  • Test verifies vesting creation is blocked during pause

Technical Context

  • contracts/learn-token/src/lib.rs:1479-1514 -- create_vesting (missing pause check)
  • contracts/learn-token/src/lib.rs:1522-1598 -- claim_vested (checks pause)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programbugSomething isn't workingmediumFunctionality impaired but workaround exists, edge case, partial featurerustRust language

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions