code-423n4 / 2023-01-ondo-findings

0 stars 0 forks source link

QA Report #309

Closed code423n4 closed 1 year ago

code423n4 commented 1 year ago

See the markdown file with the details of this report here.

c4-judge commented 1 year ago

trust1995 marked the issue as grade-c

tom2o17 commented 1 year ago

I like this one cc @ypatil12 @cameronclifton @ali2251

c4-sponsor commented 1 year ago

tom2o17 marked the issue as sponsor confirmed

cameronclifton commented 1 year ago

"While KYC can be approved to user from sanctions list" - This is intentional, KYC approval is different than sanctions status. When we call getKYCStatus we take the logical AND between KYC state and sanctions state, so it is OK if our internal KYC state is set to true when the user is "Sanctioned"