iExecBlockchainComputing/PoCo

[CS AUDIT] Arbitrary Contract are trusted

Closed this issue · 2 comments

[CS AUDIT] Arbitrary Contract are trusted
Amxx commented

proposed solution is not enough.

Functions like rewardForWork are under threat of forged workorder.
workorder must be authentic to trigger a reward, and must be removed lose it's flag once inalized to avoid further rewarding