Alert Source Discuss
📢 Last Call Standards Track: SRC

SRC-5216: SRC-1155 Allowance Extension

Extension for SRC-1155 secure approvals

Authors Iván Mañús (@ivanmmurciaua), Juan Carlos CantĂł (@EscuelaCryptoES)
Created 2022-07-11
Last Call Deadline 2022-11-12
Requires SIP-20, SIP-165, SIP-1155

Abstract

This SRC defines standard functions for granular approval of SRC-1155 tokens by both id and amount. This SRC extends SRC-1155.

Motivation

SRC-1155’s popularity means that multi-token management transactions occur on a daily basis. Although it can be used as a more comprehensive alternative to SRC-721, SRC-1155 is most commonly used as intended: creating multiple ids, each with multiple tokens. While many projects interface with these semi-fungible tokens, by far the most common interactions are with NFT marketplaces.

Due to the nature of the blockchain, programming errors or malicious operators can cause permanent loss of funds. It is therefore essential that transactions are as trustless as possible. SRC-1155 uses the setApprovalForAll function, which approves ALL tokens with a specific id. This system has obvious minimum required trust flaws. This SRC combines ideas from SRC-20 and SRC-721 in order to create a trust mechanism where an owner can allow a third party, such as a marketplace, to approve a limited (instead of unlimited) number of tokens of one id.

Specification

The keywords “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in RFC 2119.

Contracts using this SRC MUST implement the ISRC5216 interface.

Interface implementation

/**
 * @title SRC-1155 Allowance Extension
 * Note: the SRC-165 identifier for this interface is 0x1be07d74
 */
interface ISRC5216 is ISRC1155 {

    /**
     * @notice Emitted when `account` grants or revokes permission to `operator` to transfer their tokens, according to
     * `id` and with an amount: `amount`.
     */
    event Approval(address indexed account, address indexed operator, uint256 id, uint256 amount);

    /**
     * @notice Grants permission to `operator` to transfer the caller's tokens, according to `id`, and an amount: `amount`.
     * Emits an {Approval} event.
     *
     * Requirements:
     * - `operator` cannot be the caller.
     */
    function approve(address operator, uint256 id, uint256 amount) external;

    /**
     * @notice Returns the amount allocated to `operator` approved to transfer `account`'s tokens, according to `id`.
     */
    function allowance(address account, address operator, uint256 id) external view returns (uint256);
}

The approve(address operator, uint256 id, uint256 amount) function MUST be either public or external.

The allowance(address account, address operator, uint256 id) function MUST be either public or external and MUST be view.

The safeTrasferFrom function (as defined by SRC-1155) MUST:

  • Not revert if the user has approved msg.sender with a sufficient amount
  • Subtract the transferred amount of tokens from the approved amount if msg.sender is not approved with setApprovalForAll

In addition, the safeBatchTransferFrom MUST:

  • Add an extra condition that checks if the allowance of all ids have the approved amounts (See _checkApprovalForBatch function reference implementation)

The Approval event MUST be emitted when a certain number of tokens are approved.

The supportsInterface method MUST return true when called with 0x1be07d74.

Rationale

The name “SRC-1155 Allowance Extension” was chosen because it is a succinct description of this SRC. Users can approve their tokens by id and amount to operators.

By having a way to approve and revoke in a manner similar to SRC-20, the trust level can be more directly managed by users:

  • Using the approve function, users can approve an operator to spend an amount of tokens for each id.
  • Using the allowance function, users can see the approval that an operator has for each id.

The SRC-20 name patterns were used due to similarities with SRC-20 approvals.

Backwards Compatibility

This standard is compatible with SRC-1155.

Reference Implementation

The reference implementation can be found here.

Security Considerations

Users of this SRC must thoroughly consider the amount of tokens they give permission to operators, and should revoke unused authorizations.

Copyright and related rights waived via CC0.

Citation

Please cite this document as:

Iván Mañús (@ivanmmurciaua), Juan Carlos CantĂł (@EscuelaCryptoES), "SRC-5216: SRC-1155 Allowance Extension [LAST CALL]," Sila Improvement Proposals, no. 5216, July 2022. Available: https://sips.sila.org/SIPS/sip-5216.