Predictify-org / Predictify-org/predictify-contracts

[GrantFox][High] Audit administrator and upgrade authorization

Open
#1,381 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

GrantFox OSS Maybe Rewarded priority:high Third Campaign
Dominant language
Rust
Stars
10
Forks
312
Avg merge
12h 1m
Merged PRs (30d)
19

Description

Summary

Audit administrator and upgrade authorization

Why this matters

Upgrade and emergency controls must not be reachable through alternate caller paths.

Scope

Create an entrypoint authorization matrix and test role transitions.

Acceptance criteria

  • All admin/upgrade paths reject unauthorized callers.
  • Role rotation cannot widen access unexpectedly.
  • Events identify the actor and action.
  • Negative tests cover every privileged variant.

Validation

Add regression coverage for existing behavior, failure modes, authorization boundaries, and compatibility. The implementation must pass the repository CI checks.

Non-goals

  • Typo-only, formatting-only, or documentation-only changes.
  • Unrelated refactors or dependency upgrades.
  • Weakening existing security, authorization, CI, or production safeguards.

Contributor application

Before implementation, comment with relevant experience, a 1–4 bullet approach, and an estimate for opening the first draft PR. Wait for maintainer assignment before coding.

PR requirements

Use a feature branch, include Closes #<issue-number>, check every acceptance criterion, link criteria to code/tests, explain security and failure-mode considerations, and pass CI.

Reward-readiness

This is a substantive GrantFox campaign issue. Merge and CI success do not by themselves guarantee reward eligibility; final reward-readiness is determined by campaign review.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by inventorying every administrator, upgrade, emergency, and role-rotation entrypoint in the Rust contracts, then map callers, state transitions, and emitted events. Add regression and negative tests for each privileged variant and run the repository CI checks. Done means unauthorized paths fail, role rotation does not widen access, and events identify the actor and action.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
authorization, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.