The-Poolz / Poolz-Back

smart contracts using solidity for erc20 tokens to eth and erc20 to erc20
https://www.poolz.finance
MIT License
14 stars 9 forks source link

Bug #151

Closed Borelis closed 3 years ago

Borelis commented 3 years ago

Describe the bug So the bug is quite simple but most likely can be a BIG trouble in the future if not fixed now. Basically anyone can create pool on your MAINNET website. In my case the tab was open since yesterday of the main net link https://go.poolz.finance/dashboard and I was able to create the pool. And everyone using same link can lock their funds and create a pool.

To Reproduce To reproduce it simply just go to https://go.poolz.finance/dashboard and create a pool as simple as that.

Expected behavior A clear and concise description of what you expected to happen. What I think happened was either someone forgot to lock the create pools option, or the https://go.poolz.finance/dashboard link was supposed to be inaccessible.

Screenshots image image image

Desktop (please complete the following information):

Additional context Yeah so this was an accident by me, I thought at first this was supposed to happen and everyone was allowed to create Poolz, that's why I did it. But talking with CM guy in telegram he said this wasn't supposed to happen. Sooo the main question for me is AM I and YOU somehow is still able to delete my pool and refund deposited POOLZ tokens? Also I hope this information helps for future development of POOLZ

Wallet address ERC20 wallet for POZ rewards 0x7f59ae2aDC2cE3E3C1A9C09680307Fd5D785370A

Lomet commented 3 years ago

it's not a bug, it's a DeFi system. we want that all can make a pool in Mainnet - its the OTC future, Right now - you can open a pool only for Poolz token, we will add soon more OTC tokens. If someone wants to sell the token, he can make a pool to sell it - less gas and fixed price.

Borelis commented 3 years ago

Ohh, ok cool, I basically posted this because I was the only one with created pool and other telegram admins said this wasn't supposed to happen lol. Sooo Dem, actually that's quite nice if anyone can create any pools they want, even better platform than I originally thought. Also, a random thought but maybe some kind of remove pool option would be useful as well. In my case I didn't saw that I set the time for this pool for whole week :|

Borelis commented 3 years ago

Also, I will get my pools when the time ends yes?

Lomet commented 3 years ago

In "my poolz", you will have the "withdrawal" (leftovers) option, if you did not sell all. There is a TokenFilter. so we can allow Tokens, (Later on, the governance system will do it) - we don't want "bad" tokens inside. and remove pool will be "breaking" the contract you made with the "world", "No backsies". next time make less than a week :)