crypto-dappy icon indicating copy to clipboard operation
crypto-dappy copied to clipboard

Mint function does not strictly check Vault type

Open Lucklyric opened this issue 3 years ago • 2 comments

Describe the bug All mint-related functions expect a paymeValut which is in standard @FungibleToken.Vault inteface. https://github.com/bebner/crypto-dappy/blob/9ad2d82b514cb62326471fb17a39540e93dc56e6/cadence/contracts/DappyContract.cdc#L211

It should strictly define the Vault type e.g @FUSD.Valut otherwise anyone can deploy a FungibleToken and mint Dappies.

To Reproduce Steps to reproduce the behaviour:

  1. Deploy a FakeUSD contract and mint to self
  2. Create Transaction and pass &FakeUSD.Vault resource as payment to mintDappy
  3. The current CrpytoDappy contract will still allow the minting

Lucklyric avatar Sep 22 '21 08:09 Lucklyric

Hi @Lucklyric, great catch! 💪 As you might know, CryptoDappy is an educational app for the community - and I think what you spotted here is a great lesson to sensitise beginners for smart contract security. Would you be willing to document this process in a short video, that we could leverage for the CryptoDappy learning hub (repo / website) as a mission "Smart Contract Security"?

bebner avatar Sep 24 '21 13:09 bebner

Dear, @bebner. I am from  ChainIDE team, and our main objective is to assist developers in learning and working on dapps. We are glad to contribute to a course about Smart Contract Security on your learning hub. We might be able to make it next month, depending on our workload.

Lucklyric avatar Sep 28 '21 09:09 Lucklyric