ConsenSysMesh / singulardtv-contracts

19 stars 16 forks source link

another user can force another user or the workshop to withdrawRevenue #35

Closed ethers closed 8 years ago

ethers commented 8 years ago

another user can force another user or the workshop to withdrawRevenue by transferring a single token to them. (this is a sideffect of the fix to #6)

Maybe this doesn't need to be mitigated, but let's keep this open to increase awareness of this

ethers commented 8 years ago

actually, transferring 0 tokens also causes the same behavior: forced withdrawRevenue

Georgi87 commented 8 years ago

This is on purpose and is required for the fix. I don't see any other solution for this yet.

Georgi87 commented 8 years ago

Fixed in 087aa17708b16dfc5fb5b406ea4b57d2eb1abe81