ERC721.sol 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483
  1. // SPDX-License-Identifier: MIT
  2. // OpenZeppelin Contracts (last updated v5.0.0-rc.0) (token/ERC721/ERC721.sol)
  3. pragma solidity ^0.8.20;
  4. import {IERC721} from "./IERC721.sol";
  5. import {IERC721Receiver} from "./IERC721Receiver.sol";
  6. import {IERC721Metadata} from "./extensions/IERC721Metadata.sol";
  7. import {Context} from "../../utils/Context.sol";
  8. import {Strings} from "../../utils/Strings.sol";
  9. import {IERC165, ERC165} from "../../utils/introspection/ERC165.sol";
  10. import {IERC721Errors} from "../../interfaces/draft-IERC6093.sol";
  11. /**
  12. * @dev Implementation of https://eips.ethereum.org/EIPS/eip-721[ERC721] Non-Fungible Token Standard, including
  13. * the Metadata extension, but not including the Enumerable extension, which is available separately as
  14. * {ERC721Enumerable}.
  15. */
  16. abstract contract ERC721 is Context, ERC165, IERC721, IERC721Metadata, IERC721Errors {
  17. using Strings for uint256;
  18. // Token name
  19. string private _name;
  20. // Token symbol
  21. string private _symbol;
  22. mapping(uint256 tokenId => address) private _owners;
  23. mapping(address owner => uint256) private _balances;
  24. mapping(uint256 tokenId => address) private _tokenApprovals;
  25. mapping(address owner => mapping(address operator => bool)) private _operatorApprovals;
  26. /**
  27. * @dev Initializes the contract by setting a `name` and a `symbol` to the token collection.
  28. */
  29. constructor(string memory name_, string memory symbol_) {
  30. _name = name_;
  31. _symbol = symbol_;
  32. }
  33. /**
  34. * @dev See {IERC165-supportsInterface}.
  35. */
  36. function supportsInterface(bytes4 interfaceId) public view virtual override(ERC165, IERC165) returns (bool) {
  37. return
  38. interfaceId == type(IERC721).interfaceId ||
  39. interfaceId == type(IERC721Metadata).interfaceId ||
  40. super.supportsInterface(interfaceId);
  41. }
  42. /**
  43. * @dev See {IERC721-balanceOf}.
  44. */
  45. function balanceOf(address owner) public view virtual returns (uint256) {
  46. if (owner == address(0)) {
  47. revert ERC721InvalidOwner(address(0));
  48. }
  49. return _balances[owner];
  50. }
  51. /**
  52. * @dev See {IERC721-ownerOf}.
  53. */
  54. function ownerOf(uint256 tokenId) public view virtual returns (address) {
  55. return _requireOwned(tokenId);
  56. }
  57. /**
  58. * @dev See {IERC721Metadata-name}.
  59. */
  60. function name() public view virtual returns (string memory) {
  61. return _name;
  62. }
  63. /**
  64. * @dev See {IERC721Metadata-symbol}.
  65. */
  66. function symbol() public view virtual returns (string memory) {
  67. return _symbol;
  68. }
  69. /**
  70. * @dev See {IERC721Metadata-tokenURI}.
  71. */
  72. function tokenURI(uint256 tokenId) public view virtual returns (string memory) {
  73. _requireOwned(tokenId);
  74. string memory baseURI = _baseURI();
  75. return bytes(baseURI).length > 0 ? string.concat(baseURI, tokenId.toString()) : "";
  76. }
  77. /**
  78. * @dev Base URI for computing {tokenURI}. If set, the resulting URI for each
  79. * token will be the concatenation of the `baseURI` and the `tokenId`. Empty
  80. * by default, can be overridden in child contracts.
  81. */
  82. function _baseURI() internal view virtual returns (string memory) {
  83. return "";
  84. }
  85. /**
  86. * @dev See {IERC721-approve}.
  87. */
  88. function approve(address to, uint256 tokenId) public virtual {
  89. _approve(to, tokenId, _msgSender());
  90. }
  91. /**
  92. * @dev See {IERC721-getApproved}.
  93. */
  94. function getApproved(uint256 tokenId) public view virtual returns (address) {
  95. _requireOwned(tokenId);
  96. return _getApproved(tokenId);
  97. }
  98. /**
  99. * @dev See {IERC721-setApprovalForAll}.
  100. */
  101. function setApprovalForAll(address operator, bool approved) public virtual {
  102. _setApprovalForAll(_msgSender(), operator, approved);
  103. }
  104. /**
  105. * @dev See {IERC721-isApprovedForAll}.
  106. */
  107. function isApprovedForAll(address owner, address operator) public view virtual returns (bool) {
  108. return _operatorApprovals[owner][operator];
  109. }
  110. /**
  111. * @dev See {IERC721-transferFrom}.
  112. */
  113. function transferFrom(address from, address to, uint256 tokenId) public virtual {
  114. if (to == address(0)) {
  115. revert ERC721InvalidReceiver(address(0));
  116. }
  117. // Setting an "auth" arguments enables the `_isAuthorized` check which verifies that the token exists
  118. // (from != 0). Therefore, it is not needed to verify that the return value is not 0 here.
  119. address previousOwner = _update(to, tokenId, _msgSender());
  120. if (previousOwner != from) {
  121. revert ERC721IncorrectOwner(from, tokenId, previousOwner);
  122. }
  123. }
  124. /**
  125. * @dev See {IERC721-safeTransferFrom}.
  126. */
  127. function safeTransferFrom(address from, address to, uint256 tokenId) public {
  128. safeTransferFrom(from, to, tokenId, "");
  129. }
  130. /**
  131. * @dev See {IERC721-safeTransferFrom}.
  132. */
  133. function safeTransferFrom(address from, address to, uint256 tokenId, bytes memory data) public virtual {
  134. transferFrom(from, to, tokenId);
  135. _checkOnERC721Received(from, to, tokenId, data);
  136. }
  137. /**
  138. * @dev Returns the owner of the `tokenId`. Does NOT revert if token doesn't exist
  139. *
  140. * IMPORTANT: Any overrides to this function that add ownership of tokens not tracked by the
  141. * core ERC721 logic MUST be matched with the use of {_increaseBalance} to keep balances
  142. * consistent with ownership. The invariant to preserve is that for any address `a` the value returned by
  143. * `balanceOf(a)` must be equal to the number of tokens such that `_ownerOf(tokenId)` is `a`.
  144. */
  145. function _ownerOf(uint256 tokenId) internal view virtual returns (address) {
  146. return _owners[tokenId];
  147. }
  148. /**
  149. * @dev Returns the approved address for `tokenId`. Returns 0 if `tokenId` is not minted.
  150. */
  151. function _getApproved(uint256 tokenId) internal view virtual returns (address) {
  152. return _tokenApprovals[tokenId];
  153. }
  154. /**
  155. * @dev Returns whether `spender` is allowed to manage `owner`'s tokens, or `tokenId` in
  156. * particular (ignoring whether it is owned by `owner`).
  157. *
  158. * WARNING: This function assumes that `owner` is the actual owner of `tokenId` and does not verify this
  159. * assumption.
  160. */
  161. function _isAuthorized(address owner, address spender, uint256 tokenId) internal view virtual returns (bool) {
  162. return
  163. spender != address(0) &&
  164. (owner == spender || isApprovedForAll(owner, spender) || _getApproved(tokenId) == spender);
  165. }
  166. /**
  167. * @dev Checks if `spender` can operate on `tokenId`, assuming the provided `owner` is the actual owner.
  168. * Reverts if `spender` does not have approval from the provided `owner` for the given token or for all its assets
  169. * the `spender` for the specific `tokenId`.
  170. *
  171. * WARNING: This function assumes that `owner` is the actual owner of `tokenId` and does not verify this
  172. * assumption.
  173. */
  174. function _checkAuthorized(address owner, address spender, uint256 tokenId) internal view virtual {
  175. if (!_isAuthorized(owner, spender, tokenId)) {
  176. if (owner == address(0)) {
  177. revert ERC721NonexistentToken(tokenId);
  178. } else {
  179. revert ERC721InsufficientApproval(spender, tokenId);
  180. }
  181. }
  182. }
  183. /**
  184. * @dev Unsafe write access to the balances, used by extensions that "mint" tokens using an {ownerOf} override.
  185. *
  186. * NOTE: the value is limited to type(uint128).max. This protect against _balance overflow. It is unrealistic that
  187. * a uint256 would ever overflow from increments when these increments are bounded to uint128 values.
  188. *
  189. * WARNING: Increasing an account's balance using this function tends to be paired with an override of the
  190. * {_ownerOf} function to resolve the ownership of the corresponding tokens so that balances and ownership
  191. * remain consistent with one another.
  192. */
  193. function _increaseBalance(address account, uint128 value) internal virtual {
  194. unchecked {
  195. _balances[account] += value;
  196. }
  197. }
  198. /**
  199. * @dev Transfers `tokenId` from its current owner to `to`, or alternatively mints (or burns) if the current owner
  200. * (or `to`) is the zero address. Returns the owner of the `tokenId` before the update.
  201. *
  202. * The `auth` argument is optional. If the value passed is non 0, then this function will check that
  203. * `auth` is either the owner of the token, or approved to operate on the token (by the owner).
  204. *
  205. * Emits a {Transfer} event.
  206. *
  207. * NOTE: If overriding this function in a way that tracks balances, see also {_increaseBalance}.
  208. */
  209. function _update(address to, uint256 tokenId, address auth) internal virtual returns (address) {
  210. address from = _ownerOf(tokenId);
  211. // Perform (optional) operator check
  212. if (auth != address(0)) {
  213. _checkAuthorized(from, auth, tokenId);
  214. }
  215. // Execute the update
  216. if (from != address(0)) {
  217. // Clear approval. No need to re-authorize or emit the Approval event
  218. _approve(address(0), tokenId, address(0), false);
  219. unchecked {
  220. _balances[from] -= 1;
  221. }
  222. }
  223. if (to != address(0)) {
  224. unchecked {
  225. _balances[to] += 1;
  226. }
  227. }
  228. _owners[tokenId] = to;
  229. emit Transfer(from, to, tokenId);
  230. return from;
  231. }
  232. /**
  233. * @dev Mints `tokenId` and transfers it to `to`.
  234. *
  235. * WARNING: Usage of this method is discouraged, use {_safeMint} whenever possible
  236. *
  237. * Requirements:
  238. *
  239. * - `tokenId` must not exist.
  240. * - `to` cannot be the zero address.
  241. *
  242. * Emits a {Transfer} event.
  243. */
  244. function _mint(address to, uint256 tokenId) internal {
  245. if (to == address(0)) {
  246. revert ERC721InvalidReceiver(address(0));
  247. }
  248. address previousOwner = _update(to, tokenId, address(0));
  249. if (previousOwner != address(0)) {
  250. revert ERC721InvalidSender(address(0));
  251. }
  252. }
  253. /**
  254. * @dev Mints `tokenId`, transfers it to `to` and checks for `to` acceptance.
  255. *
  256. * Requirements:
  257. *
  258. * - `tokenId` must not exist.
  259. * - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon a safe transfer.
  260. *
  261. * Emits a {Transfer} event.
  262. */
  263. function _safeMint(address to, uint256 tokenId) internal {
  264. _safeMint(to, tokenId, "");
  265. }
  266. /**
  267. * @dev Same as {xref-ERC721-_safeMint-address-uint256-}[`_safeMint`], with an additional `data` parameter which is
  268. * forwarded in {IERC721Receiver-onERC721Received} to contract recipients.
  269. */
  270. function _safeMint(address to, uint256 tokenId, bytes memory data) internal virtual {
  271. _mint(to, tokenId);
  272. _checkOnERC721Received(address(0), to, tokenId, data);
  273. }
  274. /**
  275. * @dev Destroys `tokenId`.
  276. * The approval is cleared when the token is burned.
  277. * This is an internal function that does not check if the sender is authorized to operate on the token.
  278. *
  279. * Requirements:
  280. *
  281. * - `tokenId` must exist.
  282. *
  283. * Emits a {Transfer} event.
  284. */
  285. function _burn(uint256 tokenId) internal {
  286. address previousOwner = _update(address(0), tokenId, address(0));
  287. if (previousOwner == address(0)) {
  288. revert ERC721NonexistentToken(tokenId);
  289. }
  290. }
  291. /**
  292. * @dev Transfers `tokenId` from `from` to `to`.
  293. * As opposed to {transferFrom}, this imposes no restrictions on msg.sender.
  294. *
  295. * Requirements:
  296. *
  297. * - `to` cannot be the zero address.
  298. * - `tokenId` token must be owned by `from`.
  299. *
  300. * Emits a {Transfer} event.
  301. */
  302. function _transfer(address from, address to, uint256 tokenId) internal {
  303. if (to == address(0)) {
  304. revert ERC721InvalidReceiver(address(0));
  305. }
  306. address previousOwner = _update(to, tokenId, address(0));
  307. if (previousOwner == address(0)) {
  308. revert ERC721NonexistentToken(tokenId);
  309. } else if (previousOwner != from) {
  310. revert ERC721IncorrectOwner(from, tokenId, previousOwner);
  311. }
  312. }
  313. /**
  314. * @dev Safely transfers `tokenId` token from `from` to `to`, checking that contract recipients
  315. * are aware of the ERC721 standard to prevent tokens from being forever locked.
  316. *
  317. * `data` is additional data, it has no specified format and it is sent in call to `to`.
  318. *
  319. * This internal function is like {safeTransferFrom} in the sense that it invokes
  320. * {IERC721Receiver-onERC721Received} on the receiver, and can be used to e.g.
  321. * implement alternative mechanisms to perform token transfer, such as signature-based.
  322. *
  323. * Requirements:
  324. *
  325. * - `tokenId` token must exist and be owned by `from`.
  326. * - `to` cannot be the zero address.
  327. * - `from` cannot be the zero address.
  328. * - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon a safe transfer.
  329. *
  330. * Emits a {Transfer} event.
  331. */
  332. function _safeTransfer(address from, address to, uint256 tokenId) internal {
  333. _safeTransfer(from, to, tokenId, "");
  334. }
  335. /**
  336. * @dev Same as {xref-ERC721-_safeTransfer-address-address-uint256-}[`_safeTransfer`], with an additional `data` parameter which is
  337. * forwarded in {IERC721Receiver-onERC721Received} to contract recipients.
  338. */
  339. function _safeTransfer(address from, address to, uint256 tokenId, bytes memory data) internal virtual {
  340. _transfer(from, to, tokenId);
  341. _checkOnERC721Received(from, to, tokenId, data);
  342. }
  343. /**
  344. * @dev Approve `to` to operate on `tokenId`
  345. *
  346. * The `auth` argument is optional. If the value passed is non 0, then this function will check that `auth` is
  347. * either the owner of the token, or approved to operate on all tokens held by this owner.
  348. *
  349. * Emits an {Approval} event.
  350. *
  351. * Overrides to this logic should be done to the variant with an additional `bool emitEvent` argument.
  352. */
  353. function _approve(address to, uint256 tokenId, address auth) internal {
  354. _approve(to, tokenId, auth, true);
  355. }
  356. /**
  357. * @dev Variant of `_approve` with an optional flag to enable or disable the {Approval} event. The event is not
  358. * emitted in the context of transfers.
  359. */
  360. function _approve(address to, uint256 tokenId, address auth, bool emitEvent) internal virtual {
  361. // Avoid reading the owner unless necessary
  362. if (emitEvent || auth != address(0)) {
  363. address owner = _requireOwned(tokenId);
  364. // We do not use _isAuthorized because single-token approvals should not be able to call approve
  365. if (auth != address(0) && owner != auth && !isApprovedForAll(owner, auth)) {
  366. revert ERC721InvalidApprover(auth);
  367. }
  368. if (emitEvent) {
  369. emit Approval(owner, to, tokenId);
  370. }
  371. }
  372. _tokenApprovals[tokenId] = to;
  373. }
  374. /**
  375. * @dev Approve `operator` to operate on all of `owner` tokens
  376. *
  377. * Requirements:
  378. * - operator can't be the address zero.
  379. *
  380. * Emits an {ApprovalForAll} event.
  381. */
  382. function _setApprovalForAll(address owner, address operator, bool approved) internal virtual {
  383. if (operator == address(0)) {
  384. revert ERC721InvalidOperator(operator);
  385. }
  386. _operatorApprovals[owner][operator] = approved;
  387. emit ApprovalForAll(owner, operator, approved);
  388. }
  389. /**
  390. * @dev Reverts if the `tokenId` doesn't have a current owner (it hasn't been minted, or it has been burned).
  391. * Returns the owner.
  392. *
  393. * Overrides to ownership logic should be done to {_ownerOf}.
  394. */
  395. function _requireOwned(uint256 tokenId) internal view returns (address) {
  396. address owner = _ownerOf(tokenId);
  397. if (owner == address(0)) {
  398. revert ERC721NonexistentToken(tokenId);
  399. }
  400. return owner;
  401. }
  402. /**
  403. * @dev Private function to invoke {IERC721Receiver-onERC721Received} on a target address. This will revert if the
  404. * recipient doesn't accept the token transfer. The call is not executed if the target address is not a contract.
  405. *
  406. * @param from address representing the previous owner of the given token ID
  407. * @param to target address that will receive the tokens
  408. * @param tokenId uint256 ID of the token to be transferred
  409. * @param data bytes optional data to send along with the call
  410. */
  411. function _checkOnERC721Received(address from, address to, uint256 tokenId, bytes memory data) private {
  412. if (to.code.length > 0) {
  413. try IERC721Receiver(to).onERC721Received(_msgSender(), from, tokenId, data) returns (bytes4 retval) {
  414. if (retval != IERC721Receiver.onERC721Received.selector) {
  415. revert ERC721InvalidReceiver(to);
  416. }
  417. } catch (bytes memory reason) {
  418. if (reason.length == 0) {
  419. revert ERC721InvalidReceiver(to);
  420. } else {
  421. /// @solidity memory-safe-assembly
  422. assembly {
  423. revert(add(32, reason), mload(reason))
  424. }
  425. }
  426. }
  427. }
  428. }
  429. }