Define role already granted - #624
Open
d3v-active wants to merge 3 commits into
Open
Conversation
|
@d3v-active Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #431
Added RoleAlreadyGranted Error Code: Introduced AdminError::RoleAlreadyGranted (= 7) to the AdminError enum inside the admin core module (contracts/admin/src/lib.rs). This clearly distinguishes between an invalid grant versus other failures.
Added Validation Check in Role Assignment: Integrated a new validation step within the internal _grant_role function. It now proactively checks has_role(env, role, address) and safely panics with RoleAlreadyGranted if the target address already holds the requested role.
Why this change was made
Previously, re-granting an already held role would overwrite the existing persistent storage state and extend the time-to-live unnecessarily without indicating to the caller that the role was already granted. This explicit failure ensures strict access control logic, optimizes gas by failing early, and guarantees that no redundant storage modifications are processed.
Acceptance Criteria met
Function logic operates securely: The state change is strictly guarded; the function aborts before interacting with the persistent ledger storage.
Events/Errors are properly defined/emitted: Added the specific error RoleAlreadyGranted alongside existing errors.
No unauthorized state modifications: Stops duplicate grants from being recorded or triggering duplicate grant events.