Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set permissions to set permissions on circulation account to impossible #101

Merged
merged 1 commit into from
Jul 23, 2024

Conversation

kantp
Copy link
Collaborator

@kantp kantp commented Jul 22, 2024

This is a prudent measure to prevent a malicious deployer from changing permissions on the circulation account after deployment. There is no concrete attack vector identified with that, but since there is no valid reason to change the permissions, we might as well explicitly forbid it.

This is a prudent measure to prevent a malicious deployer from changing permissions on the
circulation account after deployment. There is no concrete attack vector identified with that, but
since there is no valid reason to change the permissions, we might as well explicitly forbid it.
@kantp kantp linked an issue Jul 22, 2024 that may be closed by this pull request
@kantp kantp added this pull request to the merge queue Jul 23, 2024
Merged via the queue into main with commit f685477 Jul 23, 2024
3 checks passed
@kantp kantp deleted the 100-prevent-setting-permissions-on-circulation-account branch July 23, 2024 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Prevent setting permissions on circulation account
2 participants