[BUG] Owners can set min-confirmation > 20 and by doing so they can lock safe permanently.
Closed this issue · 5 comments
LNow commented
Lines 124 to 130 in e5a3768
There should be one more asserts!
that ensures value
is less than or equal 20.
LNow commented
It can be also set up to be greater than current number of owners and result will be the same - permanent contract lock.
LNow commented
Hey @talhasch! There is still a loophole I mentioned in 2nd comment.
You can change min-confirmation
to be greater than current number of safe owners and you'll end up with locked safe.
talhasch commented
Yeah thats right! Also min-confirmation has to be checked while removing and owner...
talhasch commented
Validations added to guarantee that min-confirmation
always equal or lower than owner count.