Prevent re-entrancy, fix balance check logic

This commit is contained in:
Oleksii Matiiasevych 2016-10-26 12:41:56 +03:00 committed by GitHub
parent 4936bec6c9
commit ee24dffae2

View file

@ -27,10 +27,12 @@ contract chequebook is mortal {
if(owner != ecrecover(hash, sig_v, sig_r, sig_s)) return; if(owner != ecrecover(hash, sig_v, sig_r, sig_s)) return;
// Attempt sending the difference between the cumulative amount on the cheque // Attempt sending the difference between the cumulative amount on the cheque
// and the cumulative amount on the last cashed cheque to beneficiary. // and the cumulative amount on the last cashed cheque to beneficiary.
if (amount - sent[beneficiary] >= this.balance) { if (amount - sent[beneficiary] <= this.balance) {
if (beneficiary.send(amount - sent[beneficiary])) { // Update the cumulative amount upfront to prevent re-entrancy.
// Upon success, update the cumulative amount. sent[beneficiary] = amount;
sent[beneficiary] = amount; if (!beneficiary.send(amount - sent[beneficiary])) {
// Upon failure, rollback.
throw;
} }
} else { } else {
// Upon failure, punish owner for writing a bounced cheque. // Upon failure, punish owner for writing a bounced cheque.