Although the function checks shorter == msg.sender
, the user can still buy time for liquidation. Because mas.sender may be another account of the shorter
https://github.com/Cyfrin/2023-09-ditto/blob/main/contracts/facets/MarginCallPrimaryFacet.sol#L49
the user can still buy time for liquidation.
manual
I think this is a design issue, maybe a whitelist of liquidators can be designed to only allow specific users to liquidate
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.