Skip to content

Multiple learn-token admin and configuration functions bypass pause state check #500

Description

@DeFiVC

What

Eight learn-token admin/configuration functions do not check require_not_paused:

  1. set_transfer_restriction (lib.rs:211) -- can change transfer rules during pause
  2. add_to_whitelist (lib.rs:227) -- can modify whitelist during pause
  3. remove_from_whitelist (lib.rs:238) -- can modify whitelist during pause
  4. snapshot (lib.rs:255) -- can create snapshots during pause
  5. record_balance_snapshot (lib.rs:275) -- can record snapshots during pause
  6. grant_role (lib.rs:858) -- can grant admin roles during pause
  7. revoke_role (lib.rs:868) -- can revoke admin roles during pause
  8. add_admin (lib.rs:880) -- can add admins during pause
  9. remove_admin (lib.rs:893) -- can remove admins during pause
  10. increase_allowance (lib.rs:1274) -- can modify allowances during pause

Why

During an emergency pause, an admin could:

  • Change transfer restrictions to freeze all non-whitelisted holders
  • Grant roles to compromised addresses
  • Remove legitimate admins
  • Modify allowances to prepare for attacks after unpause

The pause should freeze ALL state-changing operations, not just token transfers.

Scope

Add Self::require_not_paused(&env); to each function listed above, after the auth check.

Acceptance Criteria

  • All listed functions panic when the contract is paused
  • Tests verify they are blocked during pause

Technical Context

  • contracts/learn-token/src/lib.rs -- all functions listed above

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programbugSomething isn't workingmediumFunctionality impaired but workaround exists, edge case, partial featurerustRust language

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions