Skip to content

[L-05] Dangerous role setting  #34

@madMax92221

Description

@madMax92221

In SingeSidedReinsurancePool.sol we can observe the function setRole which sets a particular role for the given user. The problem here is that every person with a particular role can call this function and give the same role to everybody which can be problematic in some scenarios.

A better idea would be for one person, such as the admin, to have the ability to call that function and set all roles. This would be much more secure.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions