Verification of set up process / authorization exhaustiveness
Open
- Dominant language
- GCC Machine Description
- Stars
- 45
- Forks
- 24
- PR merge metrics
- No merged PRs in 30d
Description
The security of dss relies heavily on the fact certain functions are only callable by certain interface contracts. So far, all of our specs have only assumed certain addresses have been given allowance, not excluding the possibility of other access points.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files or tests. Start by locating the existing specs that assume addresses have allowance, then map the callable interface contracts and check whether unauthorized access paths are covered. Done means the authorization setup is verified exhaustively rather than only for permitted addresses.
Written by the indexing model from the issue text.
Assessment
- Domain
- authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100