_setupRole not in constructor #107
Labels
1 (Low Risk)
Assets are not at risk. State handling, function incorrect as to spec, issues with comments
bug
Something isn't working
invalid
This doesn't seem right
sponsor disputed
Sponsor cannot duplicate the issue, or otherwise disagrees this is an issue
Handle
pauliax
Vulnerability details
Impact
_setupRole is used in function setSentinel. This is not a recommended approach.
See the warning: https://github.com/OpenZeppelin/openzeppelin-contracts/blob/v3.1.0/contracts/access/AccessControl.sol#L183-L189
Recommended Mitigation Steps
OZ suggests using _grantRole when you need to assign roles not from the constructor.
The text was updated successfully, but these errors were encountered: