Skip to content

fix: reject zero-address claimant in ClaimsProcessor.submit_claim - #665

Merged
nonsobethel0-dev merged 1 commit into
Parashield-Protocol:mainfrom
OlolaJaco:fix/issue-586-zero-address-claimant
Sep 27, 2026
Merged

nonsobethel0-dev merged 1 commit into
Parashield-Protocol:mainfrom
OlolaJaco:fix/issue-586-zero-address-claimant

Conversation

@OlolaJaco

Copy link
Copy Markdown
Contributor

Closes #587 (PolicyEngine end_time > start_time) — already fixed. buy_policy_inner in contracts/policy-engine/src/lib.rs:711-712 panics with InvalidDurationRange if end_time <= start_time, plus a duration_days == 0 check earlier.
Closes #585 (RiskPool empty category Symbol) — already fixed. RiskPool::initialize in contracts/risk-pool/src/lib.rs:254 rejects an empty category symbol.
Closes #586 (ClaimsProcessor zero-address claimant) — was not fixed, so I added it:

The all-zero Stellar account address has no private key, so a claim
filed for it would settle a payout nobody can ever collect. Validate
claimant != zero address in both submit_claim and batch_submit_claims
(issue Parashield-Protocol#586).
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@OlolaJaco Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@nonsobethel0-dev
nonsobethel0-dev merged commit bfe0552 into Parashield-Protocol:main Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants