What
create_vesting (learn-token lib.rs:1479) does not call Self::require_not_paused(&env). The admin can create new vesting schedules while the contract is emergency-paused.
Compare with claim_vested (lib.rs:1523) which correctly checks pause.
// create_vesting -- no pause check:
pub fn create_vesting(...) {
let admin = storage::get_admin(&env);
admin.require_auth(); // line 1487 -- no require_not_paused
...
}
// claim_vested -- checks pause:
pub fn claim_vested(...) {
Self::require_not_paused(&env); // line 1523
...
}
Why
During an emergency pause, an admin could create vesting schedules that lock tokens, potentially as part of an attack or to prepare actions for when the contract is unpaused. The pause should freeze all state-changing operations.
Scope
Add Self::require_not_paused(&env); at line 1486, before admin.require_auth().
Acceptance Criteria
create_vesting panics when the contract is paused
- Test verifies vesting creation is blocked during pause
Technical Context
contracts/learn-token/src/lib.rs:1479-1514 -- create_vesting (missing pause check)
contracts/learn-token/src/lib.rs:1522-1598 -- claim_vested (checks pause)
What
create_vesting(learn-token lib.rs:1479) does not callSelf::require_not_paused(&env). The admin can create new vesting schedules while the contract is emergency-paused.Compare with
claim_vested(lib.rs:1523) which correctly checks pause.Why
During an emergency pause, an admin could create vesting schedules that lock tokens, potentially as part of an attack or to prepare actions for when the contract is unpaused. The pause should freeze all state-changing operations.
Scope
Add
Self::require_not_paused(&env);at line 1486, beforeadmin.require_auth().Acceptance Criteria
create_vestingpanics when the contract is pausedTechnical Context
contracts/learn-token/src/lib.rs:1479-1514--create_vesting(missing pause check)contracts/learn-token/src/lib.rs:1522-1598--claim_vested(checks pause)