rules / HM005
HM005 unguarded-public-decrypt HIGH
Anyone can mark an encrypted value publicly decryptable
Why it matters
`FHE.makePubliclyDecryptable` (formerly `allowForDecryption`) is irreversible: once a handle is public, any observer can obtain its plaintext through the KMS. Exposing it from a function without access control or a state guard lets an attacker reveal confidential state at will, for example decrypting vote tallies before the deadline or a sealed bid before the auction closes.
Fix
Guard the call: restrict the caller (`onlyOwner`, a role check on `msg.sender`) and/or enforce the protocol state (`require(block.timestamp > deadline)`, `require(status == Closed)`). Never expose it as a bare public entry point.
Check locally
homomorph scan . --rules HM005