near-daos / sputnik-dao-contract

Smart contracts for https://app.astrodao.com
https://astrodao.com/
MIT License
107 stars 79 forks source link

Prevent delegation to non registered users #156

Closed ctindogaru closed 2 years ago

ctindogaru commented 2 years ago

Issue reported by Halborn during the audit.

Full description: The internal_delegate() function does not check if the delegated user is registered or not, it is possible to delegate to non-registered users.

It is seen that there is a comment “/// The other user must be registered.