-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
In SingeSidedReinsurancePool.sol we can observe the function setRole which sets a particular role for the given user. The problem here is that every person with a particular role can call this function and give the same role to everybody which can be problematic in some scenarios.
A better idea would be for one person, such as the admin, to have the ability to call that function and set all roles. This would be much more secure.
Metadata
Metadata
Assignees
Labels
No labels