Commit 898958e
committed
fix: Address audit findings for Allowlist contract
- Add two-step process enforcement for weight decrease (Issue #1)
- Introduce decreasePending flag to track valid decrease requests
- Prevent bypassing the intended authorization flow
- Add zero address validation (Issue #3)
- Validate walletRegistry in initialize()
- Validate stakingProvider in addStakingProvider()
- Add zero weight validation (Issue #5)
- Prevent adding staking providers with zero weight
- Avoid potential duplicate additions
- Restrict seize function access (Issue #8)
- Only allow WalletRegistry to call seize()
- Prevent event spam from unauthorized callers
- Add comprehensive test coverage for all security fixes1 parent 8281c38 commit 898958e
2 files changed
+70
-6
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
34 | 35 | | |
35 | 36 | | |
36 | 37 | | |
| |||
59 | 60 | | |
60 | 61 | | |
61 | 62 | | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
62 | 66 | | |
63 | 67 | | |
64 | 68 | | |
65 | 69 | | |
66 | 70 | | |
67 | 71 | | |
68 | 72 | | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
69 | 77 | | |
70 | 78 | | |
71 | 79 | | |
| |||
80 | 88 | | |
81 | 89 | | |
82 | 90 | | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
83 | 99 | | |
84 | 100 | | |
85 | 101 | | |
| |||
124 | 140 | | |
125 | 141 | | |
126 | 142 | | |
| 143 | + | |
127 | 144 | | |
128 | 145 | | |
129 | 146 | | |
| |||
151 | 168 | | |
152 | 169 | | |
153 | 170 | | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
154 | 175 | | |
155 | 176 | | |
156 | 177 | | |
157 | 178 | | |
| 179 | + | |
158 | 180 | | |
159 | 181 | | |
160 | 182 | | |
| |||
181 | 203 | | |
182 | 204 | | |
183 | 205 | | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
184 | 210 | | |
185 | 211 | | |
186 | 212 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
8 | 7 | | |
9 | 8 | | |
10 | 9 | | |
| |||
51 | 50 | | |
52 | 51 | | |
53 | 52 | | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
54 | 62 | | |
55 | 63 | | |
56 | 64 | | |
| |||
100 | 108 | | |
101 | 109 | | |
102 | 110 | | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
103 | 127 | | |
104 | 128 | | |
105 | 129 | | |
| |||
278 | 302 | | |
279 | 303 | | |
280 | 304 | | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
281 | 319 | | |
282 | 320 | | |
283 | 321 | | |
| |||
330 | 368 | | |
331 | 369 | | |
332 | 370 | | |
333 | | - | |
| 371 | + | |
334 | 372 | | |
335 | 373 | | |
336 | 374 | | |
337 | 375 | | |
338 | 376 | | |
339 | 377 | | |
340 | | - | |
| 378 | + | |
341 | 379 | | |
342 | 380 | | |
343 | 381 | | |
| |||
348 | 386 | | |
349 | 387 | | |
350 | 388 | | |
351 | | - | |
| 389 | + | |
352 | 390 | | |
353 | 391 | | |
354 | 392 | | |
| |||
360 | 398 | | |
361 | 399 | | |
362 | 400 | | |
363 | | - | |
| 401 | + | |
364 | 402 | | |
365 | 403 | | |
366 | 404 | | |
| |||
0 commit comments