▐ homomorph ▌

rules / HM005

HM005 unguarded-public-decrypt HIGH

Anyone can mark an encrypted value publicly decryptable

Why it matters

`FHE.makePubliclyDecryptable` (formerly `allowForDecryption`) is irreversible: once a handle is public, any observer can obtain its plaintext through the KMS. Exposing it from a function without access control or a state guard lets an attacker reveal confidential state at will, for example decrypting vote tallies before the deadline or a sealed bid before the auction closes.

Fix

Guard the call: restrict the caller (`onlyOwner`, a role check on `msg.sender`) and/or enforce the protocol state (`require(block.timestamp > deadline)`, `require(status == Closed)`). Never expose it as a bare public entry point.

Check locally

homomorph scan . --rules HM005