flow icon indicating copy to clipboard operation
flow copied to clipboard

Docs: Security Best Practices for Cadence

Open alxflw opened this issue 1 year ago • 2 comments

Take content from https://github.com/HalbornSecurity/Security-Best-Practices-for-Cadence-Developers-Flow-

and merge it into the Cadence section (https://docs.onflow.org/cadence/), likely best as a new page

alxflw avatar Jul 21 '22 19:07 alxflw

I think this is too brief ( not diving in to detail ), in my opinion it can have very bad influence on developers. We already have low composability, this suggestions will kill it a bit more.

Also some stuff like e.g. re-entry, getType() behaviour should also be mentioned. I would love to have some examples (cadence code) in those items to illustrate new users how vulnerability can happen.

To be totally honest, some items even I ( as familiar with the security concepts), had to re-read to understand.

bluesign avatar Jul 22 '22 08:07 bluesign

@franklywatson it seems the content here needs more discussion. @wise4rmgod could help get it onto the docs page but let's make sure we iterate on the content. can you please response to @bluesign feedback?

alxflw avatar Jul 22 '22 23:07 alxflw

hey @bluesign - we've discussed your feedback and decided to get a first version of this onto the docs right away + iterate on it later. this content is adding value and given our limited resources to improve it right now, we will have to address some points either later. if you have the ability to improve it based on your suggestions, a PR would be very welcome. thanks!

alxflw avatar Aug 17 '22 17:08 alxflw