Contract Name:
Contract Source Code:
// SPDX-License-Identifier: LYAA
pragma solidity ^0.8.26;
import "@openzeppelin/contracts/token/ERC721/ERC721.sol";
import "@openzeppelin/contracts/access/Ownable.sol";
import "@openzeppelin/contracts/utils/Base64.sol";
import "@openzeppelin/contracts/utils/Strings.sol";
/// @author PhiMarHal
/// @notice Infinite Onchain Story
/// @dev Stores text, builds dynamic onchain NFTs
contract Contributors is ERC721, Ownable {
using Strings for uint256;
using Strings for address;
uint256 immutable public NAME_LENGTH = 22;
uint256 immutable public CONT_AMOUNT = 16;
uint256 immutable public CONT_LENGTH = 256;
uint256 immutable public PAGE_LENGTH = CONT_LENGTH * CONT_AMOUNT + CONT_AMOUNT; // adding whitespaces
string constant public RUNE_STRING = unicode"ᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤᛆᛆᛚᚮᛁᚤ";
uint256 public next_contribution_cost = 0.0002 ether; // 200000000000000 wei
uint256 public currentPage = 0;
uint256 public currentContribution = 0;
uint256 public totalSupply = 0;
struct s_contribution {
string script;
address author;
struct s_page {
string script;
address editor;
uint256 cost;
mapping(uint256 => s_contribution) public contribution;
mapping(uint256 => s_page) public page;
mapping(address => uint256) public etherBalance;
mapping(address => string) public addressToName;
mapping(string => address) public nameToAddress;
event BatchMetadataUpdate(uint256 _fromTokenId, uint256 _toTokenId);
modifier validateString(string memory _input, uint _length) {
require(bytes(_input).length > 0, "Contributors: input text is empty");
require(bytes(_input).length <= _length, "Contributors: too many characters");
modifier validateAlphanumeric(string memory _str) {
bytes memory b = bytes(_str);
for (uint256 i; i < b.length; i++) {
bytes1 _char = b[i];
(_char >= 0x30 && _char <= 0x39) || // 0-9
(_char >= 0x41 && _char <= 0x5A) || // A-Z
(_char >= 0x61 && _char <= 0x7A) || // a-z
(_char == 0x5F) || // underscore
(_char == 0x2D), // hyphen
"Contributors: only alphanumeric, underscore, hyphen"
// set deployer as admin, initialize cost for first page
constructor() ERC721("Contributors", "CONT") {
page[0].cost = next_contribution_cost;
/// @notice Registers a unique name for the caller's address
/// @dev The name must be alphanumeric, underscore, or hyphen, and within the NAME_LENGTH limit
/// @param _name The desired name to register
function register(string memory _name) validateString(_name, NAME_LENGTH) validateAlphanumeric(_name) public {
require(nameToAddress[_name] == address(0), "Contributors: name already taken");
addressToName[msg.sender] = _name;
nameToAddress[_name] = msg.sender;
/// @notice Allows users to withdraw their accumulated ether balance
/// @dev Transfers the entire balance associated with the caller's address
function withdraw() public {
uint256 _reward = etherBalance[msg.sender];
etherBalance[msg.sender] = 0;
(bool success, ) = payable(msg.sender).call{value: _reward}("");
require(success, "Contributors: reward withdrawal failed");
/// @notice Triggers a metadata update for all tokens in a specific page
/// @dev Emits a BatchMetadataUpdate event for the specified page's token range
/// @param _pageId The ID of the page to update metadata for
function updateMetadata(uint256 _pageId) public {
uint256 _startId = _pageId * CONT_AMOUNT * 2;
uint256 _endId = _startId + (CONT_AMOUNT * 2) - 1;
emit BatchMetadataUpdate(_startId, _endId);
/// @notice Allows users to contribute to the current page by paying ETH
/// @dev Mints two NFTs: one for the contribution and one for the full page
/// @param _words Text content of the contribution
function contribute(string memory _words) validateString(_words, CONT_LENGTH) public payable {
require(msg.value == page[currentPage].cost, "Contributors: not right amount of ETH to contribute");
// add contribution
contribution[currentContribution].script = _words;
contribution[currentContribution].author = msg.sender;
// mint NFTs, first contribution then full page
_mint(msg.sender, totalSupply);
_mint(msg.sender, totalSupply);
// increment counter
// update metadata
// move on to next page if we filled it with enough contributions
if(currentContribution % CONT_AMOUNT == 0) {
page[currentPage].cost = next_contribution_cost;
/// @notice Finalizes and publishes a completed page
/// @dev Only callable by the contract owner, distributes rewards to editor and admin
/// @param _script Finalized script content for the page
/// @param _editor Address of the editor for this page
/// @param _pageId ID of the page to be published
function publish(string memory _script, address _editor, uint256 _pageId) validateString(_script, PAGE_LENGTH) onlyOwner public {
require(currentContribution / CONT_AMOUNT > _pageId, "Contributors: need more contributions");
require(bytes(page[_pageId].script).length == 0, "Contributors: page is already finalized");
page[_pageId].script = _script;
page[_pageId].editor = _editor;
uint256 _reward = page[_pageId].cost * CONT_AMOUNT / 2;
etherBalance[page[_pageId].editor] += _reward;
etherBalance[msg.sender] += _reward;
// update metadata
/// @notice Updates contribution cost for the next page
/// @dev Only callable by the contract owner
/// @param _cost New contribution cost in wei
function reprice(uint256 _cost) onlyOwner public {
next_contribution_cost = _cost;
/// @notice Retrieves contract-level metadata
/// @dev Returns a data URI containing a JSON object with contract details
/// @return A string containing the data URI for the contract metadata
function contractURI() public view returns (string memory) {
string memory _description = string(abi.encodePacked(
string memory _svgBody = generateContributionSVG("CONTRIBUTORS", _description, "SCROLL", RUNE_STRING);
string memory _image = Base64.encode(bytes(_svgBody));
string memory _json = Base64.encode(bytes(string(abi.encodePacked(
'"name": "CONTRIBUTORS",'
'"description": "', _description, '",',
'"image": "data:image/svg+xml;base64,', _image, '",'
'"banner_image": "data:image/svg+xml;base64,', _image, '",'
'"featured_image": "data:image/svg+xml;base64,', _image, '",'
'"collaborators": ["', Strings.toHexString(uint160(owner()), 20), '"]'
return string(abi.encodePacked('data:application/json;base64,', _json));
/// @notice Generates and returns the token URI for a given token ID
/// @dev Even ID = contribution, uneven ID = page
/// @param _tokenId The ID of the token to generate the URI for
/// @return A string containing the data URI for the token metadata
function tokenURI(uint256 _tokenId) public view override returns (string memory) {
string memory svgBody;
string memory title;
string memory content;
string memory author;
uint256 pageNumber = _tokenId / 2 / CONT_AMOUNT;
title = string(abi.encodePacked(pageNumber.toString(), unicode"ᛈ"));
content = tokenDescription(_tokenId);
author = string(abi.encodePacked("by ", authorDescription(_tokenId)));
if (_tokenId % 2 == 1) { // Page NFT
// Calculate scrolling mechanics
uint256 charCount = bytes(content).length;
uint256 baseChars = PAGE_LENGTH;
uint256 baseTranslation = 2400;
uint256 baseStart = 800;
uint256 ratio = (baseChars * 1000) / baseTranslation; // mul * 1000 because solidity can't do decimals
uint256 verticalTranslation = (charCount * 1000) / ratio + 40; // +40 as a buffer for tiny char count
// Calculate the animation duration
uint256 baseDuration = 120;
uint256 totalPixels = baseStart + verticalTranslation;
uint256 duration = (totalPixels * baseDuration) / (baseStart + baseTranslation);
svgBody = generatePageSVG(title, content, verticalTranslation, duration, RUNE_STRING);
} else { // Contribution NFT
uint256 contNumber = _tokenId / 2;
title = string.concat(title, contNumber.toString(), unicode"ᛢ");
svgBody = generateContributionSVG(title, content, author, RUNE_STRING);
// Encode SVG image in Base64
string memory image = Base64.encode(bytes(svgBody));
// Construct JSON metadata
string memory json = Base64.encode(bytes(string(abi.encodePacked(
'{"name": "', _tokenId.toString(), unicode"ᚦ", title, '", ',
'"description": "Token ', _tokenId.toString(), ' script: ', content, '", ',
'"image": "data:image/svg+xml;base64,', image, '"}'
// Return the final tokenURI
return string(abi.encodePacked('data:application/json;base64,', json));
/// @notice Generates an SVG image for a full page of content
/// @dev Internal function used by tokenURI for page NFTs
/// @param title Title of the page
/// @param content Content of the page
/// @param verticalTranslation Vertical translation value for scrolling animation
/// @param duration Duration of the scrolling animation
/// @param runeString String of runes to be displayed on the sides
/// @return A string containing the SVG markup for the page image
function generatePageSVG(string memory title, string memory content, uint256 verticalTranslation, uint256 duration, string memory runeString) internal pure returns (string memory) {
return string(abi.encodePacked(
'<svg xmlns="" viewBox="0 0 600 900" preserveAspectRatio="xMidYMid meet">',
'<clipPath id="svg-clip"><rect x="0" y="0" width="600" height="900"/></clipPath>',
'<clipPath id="scroll-clip"><rect x="50" y="60" width="500" height="2400"/></clipPath>',
'.scroll-container {width: 100%; height: 100%;}',
'.cylinder-container {width: 600px; height: 60px;}',
'.scroll-body {fill: #F5E5B3; stroke: black; stroke-width: 3;}',
'.cylinder {fill: #F5E5B3; stroke: black; stroke-width: 3;}',
'.handle {fill: #8B4513; stroke: black; stroke-width: 3;}',
'.title { font-family: Arial, sans-serif; font-size: 30px; text-anchor: middle; }',
'.author { font-family: Arial, sans-serif; font-size: 24px; text-anchor: middle; }',
'.content {font-family: Arial, sans-serif; font-size: 16px; }',
'.runes {font-family: Arial, sans-serif; font-size: 16px; }',
'<g clip-path="url(#svg-clip)">',
'<rect width="100%" height="100%" fill="#ffffff"/>',
'<rect class="scroll-body" x="50" y="58.5" width="500" height="783"/>',
'<path id="leftRunePath" d="M55 60v780"/>',
'<path id="rightRunePath" d="M533 60v780"/>',
'<text class="runes">',
'<textPath href="#leftRunePath">',
'<animate attributeName="startOffset" from="0" to="-400" dur="15s" repeatCount="indefinite"/>',
'<textPath href="#leftRunePath">',
'<animate attributeName="startOffset" from="400" to="0" dur="15s" repeatCount="indefinite"/>',
'<textPath href="#leftRunePath">',
'<animate attributeName="startOffset" from="800" to="400" dur="15s" repeatCount="indefinite"/>',
'<text class="runes">',
'<textPath href="#rightRunePath">',
'<animate attributeName="startOffset" from="0" to="-400" dur="15s" repeatCount="indefinite"/>',
'<textPath href="#rightRunePath">',
'<animate attributeName="startOffset" from="400" to="0" dur="15s" repeatCount="indefinite"/>',
'<textPath href="#rightRunePath">',
'<animate attributeName="startOffset" from="800" to="400" dur="15s" repeatCount="indefinite"/>',
'<g clip-path="url(#scroll-clip)">',
'<foreignObject x="70" y="80" width="460" height="2400">',
'<div xmlns="" style="font-family: Arial, sans-serif; font-size: 16px; line-height: 1.5; overflow-wrap: break-word; word-break: break-word;">',
'<animateTransform attributeName="transform" type="translate" values="0 800; 0 -',
'" dur="',
's" repeatCount="indefinite"/>',
'<g class="cylinder-container">',
'<rect class="handle" x="1.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="handle" x="561.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="cylinder" x="20" y="1.5" width="560" height="57" rx="28.5" ry="28.5"/>',
'<text class="title" x="300" y="38">CONTRIBUTORS</text>',
'<g class="cylinder-container" transform="translate(0, 840)">',
'<rect class="handle" x="1.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="handle" x="561.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="cylinder" x="20" y="1.5" width="560" height="57" rx="28.5" ry="28.5"/>',
'<text class="author" x="300" y="38">', title, '</text>',
/// @notice Generates an SVG image for a single contribution
/// @dev Internal function used by tokenURI for contribution NFTs
/// @param title Title of the contribution
/// @param content Content of the contribution
/// @param author Author of the contribution
/// @param runeString String of runes to be displayed on the sides
/// @return A string containing the SVG markup for the contribution image
function generateContributionSVG(string memory title, string memory content, string memory author, string memory runeString) internal pure returns (string memory) {
return string(abi.encodePacked(
'<svg xmlns="" viewBox="0 0 400 400" preserveAspectRatio="xMidYMid meet">',
'<clipPath id="content-clip"><rect x="20" y="60" width="360" height="280"/></clipPath>',
'.scroll-container { width: 100%; height: 100%; }',
'.cylinder-container { width: 400px; height: 60px; }',
'.scroll-body { fill: #F5E5B3; stroke: black; stroke-width: 2; }',
'.cylinder { fill: #F5E5B3; stroke: black; stroke-width: 2; }',
'.handle { fill: #8B4513; stroke: black; stroke-width: 2; }',
'.title { font-family: Arial, sans-serif; font-size: 24px; text-anchor: middle; }',
'.author { font-family: Arial, sans-serif; font-size: 20px; text-anchor: middle; }',
'.content { font-family: Arial, sans-serif; font-size: 14px; fill: black; }',
'.runes { font-family: Arial, sans-serif; font-size: 12px; opacity: 0.7; }',
'<rect width="100%" height="100%" fill="#ffffff"/>',
'<rect class="scroll-body" x="50" y="58.5" width="300" height="283"/>',
'<text class="runes" x="60" y="60" writing-mode="tb" textLength="280">',
'<text class="runes" x="340" y="60" writing-mode="tb" textLength="280">',
'<g clip-path="url(#content-clip)">',
'<foreignObject x="70" y="70" width="260" height="260">',
'<div xmlns="" style="font-family: Arial, sans-serif; font-size: 15px; line-height: 1.5; overflow-wrap: break-word; word-break: break-word;">',
'<g class="cylinder-container">',
'<rect class="handle" x="1.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="handle" x="361.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="cylinder" x="20" y="1.5" width="360" height="57" rx="28.5" ry="28.5"/>',
'<text class="title" x="200" y="38">', title, '</text>',
'<g class="cylinder-container" transform="translate(0, 340)">',
'<rect class="handle" x="1.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="handle" x="361.5" y="11.5" width="37" height="37" rx="8.5" ry="8.5"/>',
'<rect class="cylinder" x="20" y="1.5" width="360" height="57" rx="28.5" ry="28.5"/>',
'<text class="author" x="200" y="38">', author, '</text>',
/// @notice Retrieves the appropriate script content for a given token ID
/// @dev Handles both page and contribution tokens
/// @param _tokenId The ID of the token to get the description for
/// @return A string containing the script content
function tokenDescription(uint256 _tokenId) public view returns (string memory) {
if (_tokenId % 2 == 1) {
uint256 _pageID = _tokenId / 2 / CONT_AMOUNT;
return pageScript(_pageID);
} else {
return contribution[_tokenId / 2].script;
/// @notice Retrieves the author or editor name for a given token ID
/// @dev Returns name if one is registered, else returns address truncated to NAME_LENGTH
/// @param _tokenId ID of the token to get the author description for
/// @return A string containing the author or editor name/address
function authorDescription(uint256 _tokenId) public view returns (string memory) {
uint256 _mappingId;
address _author;
if(_tokenId % 2 == 1) {
_mappingId = _tokenId / 2 / CONT_AMOUNT;
_author = page[_mappingId].editor;
else {
_mappingId = _tokenId / 2;
_author = contribution[_mappingId].author;
if(bytes(addressToName[_author]).length > 0) {
return addressToName[_author];
} else {
return addressToString(_author);
/// @notice Converts an address to a string representation
/// @dev Used when an address hasn't registered a name
/// @param _adr The address to convert
/// @return A string representation of the address
function addressToString(address _adr) public pure returns (string memory) {
bytes memory data = abi.encodePacked(_adr);
bytes memory alphabet = "0123456789abcdef";
bytes memory str = new bytes(22);
str[0] = "0";
str[1] = "x";
for (uint i = 0; i < 10; i++) {
str[2+i*2] = alphabet[uint8(data[i] >> 4)];
str[3+i*2] = alphabet[uint8(data[i] & 0x0f)];
return string(str);
/// @notice Retrieves the script content for a specific page
/// @dev Returns the finalized script if page is finished, otherwise concatenates all contributions
/// @param _id ID of the page to retrieve the script for
/// @return A string containing the page script
function pageScript(uint256 _id) public view returns (string memory) {
if(bytes(page[_id].script).length > 0) {
return page[_id].script;
} else {
uint256 _firstContribution = _id * CONT_AMOUNT;
string memory _tempScript;
for(uint i = 0; i < CONT_AMOUNT; i++) {
_tempScript = string.concat(_tempScript, contribution[_firstContribution].script, " ");
return _tempScript;
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (utils/Strings.sol)
pragma solidity ^0.8.20;
import {Math} from "./math/Math.sol";
import {SignedMath} from "./math/SignedMath.sol";
* @dev String operations.
library Strings {
bytes16 private constant HEX_DIGITS = "0123456789abcdef";
uint8 private constant ADDRESS_LENGTH = 20;
* @dev The `value` string doesn't fit in the specified `length`.
error StringsInsufficientHexLength(uint256 value, uint256 length);
* @dev Converts a `uint256` to its ASCII `string` decimal representation.
function toString(uint256 value) internal pure returns (string memory) {
unchecked {
uint256 length = Math.log10(value) + 1;
string memory buffer = new string(length);
uint256 ptr;
/// @solidity memory-safe-assembly
assembly {
ptr := add(buffer, add(32, length))
while (true) {
/// @solidity memory-safe-assembly
assembly {
mstore8(ptr, byte(mod(value, 10), HEX_DIGITS))
value /= 10;
if (value == 0) break;
return buffer;
* @dev Converts a `int256` to its ASCII `string` decimal representation.
function toStringSigned(int256 value) internal pure returns (string memory) {
return string.concat(value < 0 ? "-" : "", toString(SignedMath.abs(value)));
* @dev Converts a `uint256` to its ASCII `string` hexadecimal representation.
function toHexString(uint256 value) internal pure returns (string memory) {
unchecked {
return toHexString(value, Math.log256(value) + 1);
* @dev Converts a `uint256` to its ASCII `string` hexadecimal representation with fixed length.
function toHexString(uint256 value, uint256 length) internal pure returns (string memory) {
uint256 localValue = value;
bytes memory buffer = new bytes(2 * length + 2);
buffer[0] = "0";
buffer[1] = "x";
for (uint256 i = 2 * length + 1; i > 1; --i) {
buffer[i] = HEX_DIGITS[localValue & 0xf];
localValue >>= 4;
if (localValue != 0) {
revert StringsInsufficientHexLength(value, length);
return string(buffer);
* @dev Converts an `address` with fixed length of 20 bytes to its not checksummed ASCII `string` hexadecimal
* representation.
function toHexString(address addr) internal pure returns (string memory) {
return toHexString(uint256(uint160(addr)), ADDRESS_LENGTH);
* @dev Returns true if the two strings are equal.
function equal(string memory a, string memory b) internal pure returns (bool) {
return bytes(a).length == bytes(b).length && keccak256(bytes(a)) == keccak256(bytes(b));
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.2) (utils/Base64.sol)
pragma solidity ^0.8.20;
* @dev Provides a set of functions to operate with Base64 strings.
library Base64 {
* @dev Base64 Encoding/Decoding Table
string internal constant _TABLE = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
* @dev Converts a `bytes` to its Bytes64 `string` representation.
function encode(bytes memory data) internal pure returns (string memory) {
* Inspired by Brecht Devos (Brechtpd) implementation - MIT licence
if (data.length == 0) return "";
// Loads the table into memory
string memory table = _TABLE;
// Encoding takes 3 bytes chunks of binary data from `bytes` data parameter
// and split into 4 numbers of 6 bits.
// The final Base64 length should be `bytes` data length multiplied by 4/3 rounded up
// - `data.length + 2` -> Round up
// - `/ 3` -> Number of 3-bytes chunks
// - `4 *` -> 4 characters for each chunk
string memory result = new string(4 * ((data.length + 2) / 3));
/// @solidity memory-safe-assembly
assembly {
// Prepare the lookup table (skip the first "length" byte)
let tablePtr := add(table, 1)
// Prepare result pointer, jump over length
let resultPtr := add(result, 0x20)
let dataPtr := data
let endPtr := add(data, mload(data))
// In some cases, the last iteration will read bytes after the end of the data. We cache the value, and
// set it to zero to make sure no dirty bytes are read in that section.
let afterPtr := add(endPtr, 0x20)
let afterCache := mload(afterPtr)
mstore(afterPtr, 0x00)
// Run over the input, 3 bytes at a time
for {
} lt(dataPtr, endPtr) {
} {
// Advance 3 bytes
dataPtr := add(dataPtr, 3)
let input := mload(dataPtr)
// To write each character, shift the 3 byte (24 bits) chunk
// 4 times in blocks of 6 bits for each character (18, 12, 6, 0)
// and apply logical AND with 0x3F to bitmask the least significant 6 bits.
// Use this as an index into the lookup table, mload an entire word
// so the desired character is in the least significant byte, and
// mstore8 this least significant byte into the result and continue.
mstore8(resultPtr, mload(add(tablePtr, and(shr(18, input), 0x3F))))
resultPtr := add(resultPtr, 1) // Advance
mstore8(resultPtr, mload(add(tablePtr, and(shr(12, input), 0x3F))))
resultPtr := add(resultPtr, 1) // Advance
mstore8(resultPtr, mload(add(tablePtr, and(shr(6, input), 0x3F))))
resultPtr := add(resultPtr, 1) // Advance
mstore8(resultPtr, mload(add(tablePtr, and(input, 0x3F))))
resultPtr := add(resultPtr, 1) // Advance
// Reset the value that was cached
mstore(afterPtr, afterCache)
// When data `bytes` is not exactly 3 bytes long
// it is padded with `=` characters at the end
switch mod(mload(data), 3)
case 1 {
mstore8(sub(resultPtr, 1), 0x3d)
mstore8(sub(resultPtr, 2), 0x3d)
case 2 {
mstore8(sub(resultPtr, 1), 0x3d)
return result;
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.7.0) (access/Ownable.sol)
pragma solidity ^0.8.0;
import "../utils/Context.sol";
* @dev Contract module which provides a basic access control mechanism, where
* there is an account (an owner) that can be granted exclusive access to
* specific functions.
* By default, the owner account will be the one that deploys the contract. This
* can later be changed with {transferOwnership}.
* This module is used through inheritance. It will make available the modifier
* `onlyOwner`, which can be applied to your functions to restrict their use to
* the owner.
abstract contract Ownable is Context {
address private _owner;
event OwnershipTransferred(address indexed previousOwner, address indexed newOwner);
* @dev Initializes the contract setting the deployer as the initial owner.
constructor() {
* @dev Throws if called by any account other than the owner.
modifier onlyOwner() {
* @dev Returns the address of the current owner.
function owner() public view virtual returns (address) {
return _owner;
* @dev Throws if the sender is not the owner.
function _checkOwner() internal view virtual {
require(owner() == _msgSender(), "Ownable: caller is not the owner");
* @dev Leaves the contract without owner. It will not be possible to call
* `onlyOwner` functions anymore. Can only be called by the current owner.
* NOTE: Renouncing ownership will leave the contract without an owner,
* thereby removing any functionality that is only available to the owner.
function renounceOwnership() public virtual onlyOwner {
* @dev Transfers ownership of the contract to a new account (`newOwner`).
* Can only be called by the current owner.
function transferOwnership(address newOwner) public virtual onlyOwner {
require(newOwner != address(0), "Ownable: new owner is the zero address");
* @dev Transfers ownership of the contract to a new account (`newOwner`).
* Internal function without access restriction.
function _transferOwnership(address newOwner) internal virtual {
address oldOwner = _owner;
_owner = newOwner;
emit OwnershipTransferred(oldOwner, newOwner);
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (token/ERC721/ERC721.sol)
pragma solidity ^0.8.20;
import {IERC721} from "./IERC721.sol";
import {IERC721Receiver} from "./IERC721Receiver.sol";
import {IERC721Metadata} from "./extensions/IERC721Metadata.sol";
import {Context} from "../../utils/Context.sol";
import {Strings} from "../../utils/Strings.sol";
import {IERC165, ERC165} from "../../utils/introspection/ERC165.sol";
import {IERC721Errors} from "../../interfaces/draft-IERC6093.sol";
* @dev Implementation of[ERC721] Non-Fungible Token Standard, including
* the Metadata extension, but not including the Enumerable extension, which is available separately as
* {ERC721Enumerable}.
abstract contract ERC721 is Context, ERC165, IERC721, IERC721Metadata, IERC721Errors {
using Strings for uint256;
// Token name
string private _name;
// Token symbol
string private _symbol;
mapping(uint256 tokenId => address) private _owners;
mapping(address owner => uint256) private _balances;
mapping(uint256 tokenId => address) private _tokenApprovals;
mapping(address owner => mapping(address operator => bool)) private _operatorApprovals;
* @dev Initializes the contract by setting a `name` and a `symbol` to the token collection.
constructor(string memory name_, string memory symbol_) {
_name = name_;
_symbol = symbol_;
* @dev See {IERC165-supportsInterface}.
function supportsInterface(bytes4 interfaceId) public view virtual override(ERC165, IERC165) returns (bool) {
interfaceId == type(IERC721).interfaceId ||
interfaceId == type(IERC721Metadata).interfaceId ||
* @dev See {IERC721-balanceOf}.
function balanceOf(address owner) public view virtual returns (uint256) {
if (owner == address(0)) {
revert ERC721InvalidOwner(address(0));
return _balances[owner];
* @dev See {IERC721-ownerOf}.
function ownerOf(uint256 tokenId) public view virtual returns (address) {
return _requireOwned(tokenId);
* @dev See {IERC721Metadata-name}.
function name() public view virtual returns (string memory) {
return _name;
* @dev See {IERC721Metadata-symbol}.
function symbol() public view virtual returns (string memory) {
return _symbol;
* @dev See {IERC721Metadata-tokenURI}.
function tokenURI(uint256 tokenId) public view virtual returns (string memory) {
string memory baseURI = _baseURI();
return bytes(baseURI).length > 0 ? string.concat(baseURI, tokenId.toString()) : "";
* @dev Base URI for computing {tokenURI}. If set, the resulting URI for each
* token will be the concatenation of the `baseURI` and the `tokenId`. Empty
* by default, can be overridden in child contracts.
function _baseURI() internal view virtual returns (string memory) {
return "";
* @dev See {IERC721-approve}.
function approve(address to, uint256 tokenId) public virtual {
_approve(to, tokenId, _msgSender());
* @dev See {IERC721-getApproved}.
function getApproved(uint256 tokenId) public view virtual returns (address) {
return _getApproved(tokenId);
* @dev See {IERC721-setApprovalForAll}.
function setApprovalForAll(address operator, bool approved) public virtual {
_setApprovalForAll(_msgSender(), operator, approved);
* @dev See {IERC721-isApprovedForAll}.
function isApprovedForAll(address owner, address operator) public view virtual returns (bool) {
return _operatorApprovals[owner][operator];
* @dev See {IERC721-transferFrom}.
function transferFrom(address from, address to, uint256 tokenId) public virtual {
if (to == address(0)) {
revert ERC721InvalidReceiver(address(0));
// Setting an "auth" arguments enables the `_isAuthorized` check which verifies that the token exists
// (from != 0). Therefore, it is not needed to verify that the return value is not 0 here.
address previousOwner = _update(to, tokenId, _msgSender());
if (previousOwner != from) {
revert ERC721IncorrectOwner(from, tokenId, previousOwner);
* @dev See {IERC721-safeTransferFrom}.
function safeTransferFrom(address from, address to, uint256 tokenId) public {
safeTransferFrom(from, to, tokenId, "");
* @dev See {IERC721-safeTransferFrom}.
function safeTransferFrom(address from, address to, uint256 tokenId, bytes memory data) public virtual {
transferFrom(from, to, tokenId);
_checkOnERC721Received(from, to, tokenId, data);
* @dev Returns the owner of the `tokenId`. Does NOT revert if token doesn't exist
* IMPORTANT: Any overrides to this function that add ownership of tokens not tracked by the
* core ERC721 logic MUST be matched with the use of {_increaseBalance} to keep balances
* consistent with ownership. The invariant to preserve is that for any address `a` the value returned by
* `balanceOf(a)` must be equal to the number of tokens such that `_ownerOf(tokenId)` is `a`.
function _ownerOf(uint256 tokenId) internal view virtual returns (address) {
return _owners[tokenId];
* @dev Returns the approved address for `tokenId`. Returns 0 if `tokenId` is not minted.
function _getApproved(uint256 tokenId) internal view virtual returns (address) {
return _tokenApprovals[tokenId];
* @dev Returns whether `spender` is allowed to manage `owner`'s tokens, or `tokenId` in
* particular (ignoring whether it is owned by `owner`).
* WARNING: This function assumes that `owner` is the actual owner of `tokenId` and does not verify this
* assumption.
function _isAuthorized(address owner, address spender, uint256 tokenId) internal view virtual returns (bool) {
spender != address(0) &&
(owner == spender || isApprovedForAll(owner, spender) || _getApproved(tokenId) == spender);
* @dev Checks if `spender` can operate on `tokenId`, assuming the provided `owner` is the actual owner.
* Reverts if `spender` does not have approval from the provided `owner` for the given token or for all its assets
* the `spender` for the specific `tokenId`.
* WARNING: This function assumes that `owner` is the actual owner of `tokenId` and does not verify this
* assumption.
function _checkAuthorized(address owner, address spender, uint256 tokenId) internal view virtual {
if (!_isAuthorized(owner, spender, tokenId)) {
if (owner == address(0)) {
revert ERC721NonexistentToken(tokenId);
} else {
revert ERC721InsufficientApproval(spender, tokenId);
* @dev Unsafe write access to the balances, used by extensions that "mint" tokens using an {ownerOf} override.
* NOTE: the value is limited to type(uint128).max. This protect against _balance overflow. It is unrealistic that
* a uint256 would ever overflow from increments when these increments are bounded to uint128 values.
* WARNING: Increasing an account's balance using this function tends to be paired with an override of the
* {_ownerOf} function to resolve the ownership of the corresponding tokens so that balances and ownership
* remain consistent with one another.
function _increaseBalance(address account, uint128 value) internal virtual {
unchecked {
_balances[account] += value;
* @dev Transfers `tokenId` from its current owner to `to`, or alternatively mints (or burns) if the current owner
* (or `to`) is the zero address. Returns the owner of the `tokenId` before the update.
* The `auth` argument is optional. If the value passed is non 0, then this function will check that
* `auth` is either the owner of the token, or approved to operate on the token (by the owner).
* Emits a {Transfer} event.
* NOTE: If overriding this function in a way that tracks balances, see also {_increaseBalance}.
function _update(address to, uint256 tokenId, address auth) internal virtual returns (address) {
address from = _ownerOf(tokenId);
// Perform (optional) operator check
if (auth != address(0)) {
_checkAuthorized(from, auth, tokenId);
// Execute the update
if (from != address(0)) {
// Clear approval. No need to re-authorize or emit the Approval event
_approve(address(0), tokenId, address(0), false);
unchecked {
_balances[from] -= 1;
if (to != address(0)) {
unchecked {
_balances[to] += 1;
_owners[tokenId] = to;
emit Transfer(from, to, tokenId);
return from;
* @dev Mints `tokenId` and transfers it to `to`.
* WARNING: Usage of this method is discouraged, use {_safeMint} whenever possible
* Requirements:
* - `tokenId` must not exist.
* - `to` cannot be the zero address.
* Emits a {Transfer} event.
function _mint(address to, uint256 tokenId) internal {
if (to == address(0)) {
revert ERC721InvalidReceiver(address(0));
address previousOwner = _update(to, tokenId, address(0));
if (previousOwner != address(0)) {
revert ERC721InvalidSender(address(0));
* @dev Mints `tokenId`, transfers it to `to` and checks for `to` acceptance.
* Requirements:
* - `tokenId` must not exist.
* - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon a safe transfer.
* Emits a {Transfer} event.
function _safeMint(address to, uint256 tokenId) internal {
_safeMint(to, tokenId, "");
* @dev Same as {xref-ERC721-_safeMint-address-uint256-}[`_safeMint`], with an additional `data` parameter which is
* forwarded in {IERC721Receiver-onERC721Received} to contract recipients.
function _safeMint(address to, uint256 tokenId, bytes memory data) internal virtual {
_mint(to, tokenId);
_checkOnERC721Received(address(0), to, tokenId, data);
* @dev Destroys `tokenId`.
* The approval is cleared when the token is burned.
* This is an internal function that does not check if the sender is authorized to operate on the token.
* Requirements:
* - `tokenId` must exist.
* Emits a {Transfer} event.
function _burn(uint256 tokenId) internal {
address previousOwner = _update(address(0), tokenId, address(0));
if (previousOwner == address(0)) {
revert ERC721NonexistentToken(tokenId);
* @dev Transfers `tokenId` from `from` to `to`.
* As opposed to {transferFrom}, this imposes no restrictions on msg.sender.
* Requirements:
* - `to` cannot be the zero address.
* - `tokenId` token must be owned by `from`.
* Emits a {Transfer} event.
function _transfer(address from, address to, uint256 tokenId) internal {
if (to == address(0)) {
revert ERC721InvalidReceiver(address(0));
address previousOwner = _update(to, tokenId, address(0));
if (previousOwner == address(0)) {
revert ERC721NonexistentToken(tokenId);
} else if (previousOwner != from) {
revert ERC721IncorrectOwner(from, tokenId, previousOwner);
* @dev Safely transfers `tokenId` token from `from` to `to`, checking that contract recipients
* are aware of the ERC721 standard to prevent tokens from being forever locked.
* `data` is additional data, it has no specified format and it is sent in call to `to`.
* This internal function is like {safeTransferFrom} in the sense that it invokes
* {IERC721Receiver-onERC721Received} on the receiver, and can be used to e.g.
* implement alternative mechanisms to perform token transfer, such as signature-based.
* Requirements:
* - `tokenId` token must exist and be owned by `from`.
* - `to` cannot be the zero address.
* - `from` cannot be the zero address.
* - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon a safe transfer.
* Emits a {Transfer} event.
function _safeTransfer(address from, address to, uint256 tokenId) internal {
_safeTransfer(from, to, tokenId, "");
* @dev Same as {xref-ERC721-_safeTransfer-address-address-uint256-}[`_safeTransfer`], with an additional `data` parameter which is
* forwarded in {IERC721Receiver-onERC721Received} to contract recipients.
function _safeTransfer(address from, address to, uint256 tokenId, bytes memory data) internal virtual {
_transfer(from, to, tokenId);
_checkOnERC721Received(from, to, tokenId, data);
* @dev Approve `to` to operate on `tokenId`
* The `auth` argument is optional. If the value passed is non 0, then this function will check that `auth` is
* either the owner of the token, or approved to operate on all tokens held by this owner.
* Emits an {Approval} event.
* Overrides to this logic should be done to the variant with an additional `bool emitEvent` argument.
function _approve(address to, uint256 tokenId, address auth) internal {
_approve(to, tokenId, auth, true);
* @dev Variant of `_approve` with an optional flag to enable or disable the {Approval} event. The event is not
* emitted in the context of transfers.
function _approve(address to, uint256 tokenId, address auth, bool emitEvent) internal virtual {
// Avoid reading the owner unless necessary
if (emitEvent || auth != address(0)) {
address owner = _requireOwned(tokenId);
// We do not use _isAuthorized because single-token approvals should not be able to call approve
if (auth != address(0) && owner != auth && !isApprovedForAll(owner, auth)) {
revert ERC721InvalidApprover(auth);
if (emitEvent) {
emit Approval(owner, to, tokenId);
_tokenApprovals[tokenId] = to;
* @dev Approve `operator` to operate on all of `owner` tokens
* Requirements:
* - operator can't be the address zero.
* Emits an {ApprovalForAll} event.
function _setApprovalForAll(address owner, address operator, bool approved) internal virtual {
if (operator == address(0)) {
revert ERC721InvalidOperator(operator);
_operatorApprovals[owner][operator] = approved;
emit ApprovalForAll(owner, operator, approved);
* @dev Reverts if the `tokenId` doesn't have a current owner (it hasn't been minted, or it has been burned).
* Returns the owner.
* Overrides to ownership logic should be done to {_ownerOf}.
function _requireOwned(uint256 tokenId) internal view returns (address) {
address owner = _ownerOf(tokenId);
if (owner == address(0)) {
revert ERC721NonexistentToken(tokenId);
return owner;
* @dev Private function to invoke {IERC721Receiver-onERC721Received} on a target address. This will revert if the
* recipient doesn't accept the token transfer. The call is not executed if the target address is not a contract.
* @param from address representing the previous owner of the given token ID
* @param to target address that will receive the tokens
* @param tokenId uint256 ID of the token to be transferred
* @param data bytes optional data to send along with the call
function _checkOnERC721Received(address from, address to, uint256 tokenId, bytes memory data) private {
if (to.code.length > 0) {
try IERC721Receiver(to).onERC721Received(_msgSender(), from, tokenId, data) returns (bytes4 retval) {
if (retval != IERC721Receiver.onERC721Received.selector) {
revert ERC721InvalidReceiver(to);
} catch (bytes memory reason) {
if (reason.length == 0) {
revert ERC721InvalidReceiver(to);
} else {
/// @solidity memory-safe-assembly
assembly {
revert(add(32, reason), mload(reason))
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (utils/math/SignedMath.sol)
pragma solidity ^0.8.20;
* @dev Standard signed math utilities missing in the Solidity language.
library SignedMath {
* @dev Returns the largest of two signed numbers.
function max(int256 a, int256 b) internal pure returns (int256) {
return a > b ? a : b;
* @dev Returns the smallest of two signed numbers.
function min(int256 a, int256 b) internal pure returns (int256) {
return a < b ? a : b;
* @dev Returns the average of two signed numbers without overflow.
* The result is rounded towards zero.
function average(int256 a, int256 b) internal pure returns (int256) {
// Formula from the book "Hacker's Delight"
int256 x = (a & b) + ((a ^ b) >> 1);
return x + (int256(uint256(x) >> 255) & (a ^ b));
* @dev Returns the absolute unsigned value of a signed value.
function abs(int256 n) internal pure returns (uint256) {
unchecked {
// must be unchecked in order to support `n = type(int256).min`
return uint256(n >= 0 ? n : -n);
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (utils/math/Math.sol)
pragma solidity ^0.8.20;
* @dev Standard math utilities missing in the Solidity language.
library Math {
* @dev Muldiv operation overflow.
error MathOverflowedMulDiv();
enum Rounding {
Floor, // Toward negative infinity
Ceil, // Toward positive infinity
Trunc, // Toward zero
Expand // Away from zero
* @dev Returns the addition of two unsigned integers, with an overflow flag.
function tryAdd(uint256 a, uint256 b) internal pure returns (bool, uint256) {
unchecked {
uint256 c = a + b;
if (c < a) return (false, 0);
return (true, c);
* @dev Returns the subtraction of two unsigned integers, with an overflow flag.
function trySub(uint256 a, uint256 b) internal pure returns (bool, uint256) {
unchecked {
if (b > a) return (false, 0);
return (true, a - b);
* @dev Returns the multiplication of two unsigned integers, with an overflow flag.
function tryMul(uint256 a, uint256 b) internal pure returns (bool, uint256) {
unchecked {
// Gas optimization: this is cheaper than requiring 'a' not being zero, but the
// benefit is lost if 'b' is also tested.
// See:
if (a == 0) return (true, 0);
uint256 c = a * b;
if (c / a != b) return (false, 0);
return (true, c);
* @dev Returns the division of two unsigned integers, with a division by zero flag.
function tryDiv(uint256 a, uint256 b) internal pure returns (bool, uint256) {
unchecked {
if (b == 0) return (false, 0);
return (true, a / b);
* @dev Returns the remainder of dividing two unsigned integers, with a division by zero flag.
function tryMod(uint256 a, uint256 b) internal pure returns (bool, uint256) {
unchecked {
if (b == 0) return (false, 0);
return (true, a % b);
* @dev Returns the largest of two numbers.
function max(uint256 a, uint256 b) internal pure returns (uint256) {
return a > b ? a : b;
* @dev Returns the smallest of two numbers.
function min(uint256 a, uint256 b) internal pure returns (uint256) {
return a < b ? a : b;
* @dev Returns the average of two numbers. The result is rounded towards
* zero.
function average(uint256 a, uint256 b) internal pure returns (uint256) {
// (a + b) / 2 can overflow.
return (a & b) + (a ^ b) / 2;
* @dev Returns the ceiling of the division of two numbers.
* This differs from standard division with `/` in that it rounds towards infinity instead
* of rounding towards zero.
function ceilDiv(uint256 a, uint256 b) internal pure returns (uint256) {
if (b == 0) {
// Guarantee the same behavior as in a regular Solidity division.
return a / b;
// (a + b - 1) / b can overflow on addition, so we distribute.
return a == 0 ? 0 : (a - 1) / b + 1;
* @notice Calculates floor(x * y / denominator) with full precision. Throws if result overflows a uint256 or
* denominator == 0.
* @dev Original credit to Remco Bloemen under MIT license ( with further edits by
* Uniswap Labs also under MIT license.
function mulDiv(uint256 x, uint256 y, uint256 denominator) internal pure returns (uint256 result) {
unchecked {
// 512-bit multiply [prod1 prod0] = x * y. Compute the product mod 2^256 and mod 2^256 - 1, then use
// use the Chinese Remainder Theorem to reconstruct the 512 bit result. The result is stored in two 256
// variables such that product = prod1 * 2^256 + prod0.
uint256 prod0 = x * y; // Least significant 256 bits of the product
uint256 prod1; // Most significant 256 bits of the product
assembly {
let mm := mulmod(x, y, not(0))
prod1 := sub(sub(mm, prod0), lt(mm, prod0))
// Handle non-overflow cases, 256 by 256 division.
if (prod1 == 0) {
// Solidity will revert if denominator == 0, unlike the div opcode on its own.
// The surrounding unchecked block does not change this fact.
// See
return prod0 / denominator;
// Make sure the result is less than 2^256. Also prevents denominator == 0.
if (denominator <= prod1) {
revert MathOverflowedMulDiv();
// 512 by 256 division.
// Make division exact by subtracting the remainder from [prod1 prod0].
uint256 remainder;
assembly {
// Compute remainder using mulmod.
remainder := mulmod(x, y, denominator)
// Subtract 256 bit number from 512 bit number.
prod1 := sub(prod1, gt(remainder, prod0))
prod0 := sub(prod0, remainder)
// Factor powers of two out of denominator and compute largest power of two divisor of denominator.
// Always >= 1. See
uint256 twos = denominator & (0 - denominator);
assembly {
// Divide denominator by twos.
denominator := div(denominator, twos)
// Divide [prod1 prod0] by twos.
prod0 := div(prod0, twos)
// Flip twos such that it is 2^256 / twos. If twos is zero, then it becomes one.
twos := add(div(sub(0, twos), twos), 1)
// Shift in bits from prod1 into prod0.
prod0 |= prod1 * twos;
// Invert denominator mod 2^256. Now that denominator is an odd number, it has an inverse modulo 2^256 such
// that denominator * inv = 1 mod 2^256. Compute the inverse by starting with a seed that is correct for
// four bits. That is, denominator * inv = 1 mod 2^4.
uint256 inverse = (3 * denominator) ^ 2;
// Use the Newton-Raphson iteration to improve the precision. Thanks to Hensel's lifting lemma, this also
// works in modular arithmetic, doubling the correct bits in each step.
inverse *= 2 - denominator * inverse; // inverse mod 2^8
inverse *= 2 - denominator * inverse; // inverse mod 2^16
inverse *= 2 - denominator * inverse; // inverse mod 2^32
inverse *= 2 - denominator * inverse; // inverse mod 2^64
inverse *= 2 - denominator * inverse; // inverse mod 2^128
inverse *= 2 - denominator * inverse; // inverse mod 2^256
// Because the division is now exact we can divide by multiplying with the modular inverse of denominator.
// This will give us the correct result modulo 2^256. Since the preconditions guarantee that the outcome is
// less than 2^256, this is the final result. We don't need to compute the high bits of the result and prod1
// is no longer required.
result = prod0 * inverse;
return result;
* @notice Calculates x * y / denominator with full precision, following the selected rounding direction.
function mulDiv(uint256 x, uint256 y, uint256 denominator, Rounding rounding) internal pure returns (uint256) {
uint256 result = mulDiv(x, y, denominator);
if (unsignedRoundsUp(rounding) && mulmod(x, y, denominator) > 0) {
result += 1;
return result;
* @dev Returns the square root of a number. If the number is not a perfect square, the value is rounded
* towards zero.
* Inspired by Henry S. Warren, Jr.'s "Hacker's Delight" (Chapter 11).
function sqrt(uint256 a) internal pure returns (uint256) {
if (a == 0) {
return 0;
// For our first guess, we get the biggest power of 2 which is smaller than the square root of the target.
// We know that the "msb" (most significant bit) of our target number `a` is a power of 2 such that we have
// `msb(a) <= a < 2*msb(a)`. This value can be written `msb(a)=2**k` with `k=log2(a)`.
// This can be rewritten `2**log2(a) <= a < 2**(log2(a) + 1)`
// → `sqrt(2**k) <= sqrt(a) < sqrt(2**(k+1))`
// → `2**(k/2) <= sqrt(a) < 2**((k+1)/2) <= 2**(k/2 + 1)`
// Consequently, `2**(log2(a) / 2)` is a good first approximation of `sqrt(a)` with at least 1 correct bit.
uint256 result = 1 << (log2(a) >> 1);
// At this point `result` is an estimation with one bit of precision. We know the true value is a uint128,
// since it is the square root of a uint256. Newton's method converges quadratically (precision doubles at
// every iteration). We thus need at most 7 iteration to turn our partial result with one bit of precision
// into the expected uint128 result.
unchecked {
result = (result + a / result) >> 1;
result = (result + a / result) >> 1;
result = (result + a / result) >> 1;
result = (result + a / result) >> 1;
result = (result + a / result) >> 1;
result = (result + a / result) >> 1;
result = (result + a / result) >> 1;
return min(result, a / result);
* @notice Calculates sqrt(a), following the selected rounding direction.
function sqrt(uint256 a, Rounding rounding) internal pure returns (uint256) {
unchecked {
uint256 result = sqrt(a);
return result + (unsignedRoundsUp(rounding) && result * result < a ? 1 : 0);
* @dev Return the log in base 2 of a positive value rounded towards zero.
* Returns 0 if given 0.
function log2(uint256 value) internal pure returns (uint256) {
uint256 result = 0;
unchecked {
if (value >> 128 > 0) {
value >>= 128;
result += 128;
if (value >> 64 > 0) {
value >>= 64;
result += 64;
if (value >> 32 > 0) {
value >>= 32;
result += 32;
if (value >> 16 > 0) {
value >>= 16;
result += 16;
if (value >> 8 > 0) {
value >>= 8;
result += 8;
if (value >> 4 > 0) {
value >>= 4;
result += 4;
if (value >> 2 > 0) {
value >>= 2;
result += 2;
if (value >> 1 > 0) {
result += 1;
return result;
* @dev Return the log in base 2, following the selected rounding direction, of a positive value.
* Returns 0 if given 0.
function log2(uint256 value, Rounding rounding) internal pure returns (uint256) {
unchecked {
uint256 result = log2(value);
return result + (unsignedRoundsUp(rounding) && 1 << result < value ? 1 : 0);
* @dev Return the log in base 10 of a positive value rounded towards zero.
* Returns 0 if given 0.
function log10(uint256 value) internal pure returns (uint256) {
uint256 result = 0;
unchecked {
if (value >= 10 ** 64) {
value /= 10 ** 64;
result += 64;
if (value >= 10 ** 32) {
value /= 10 ** 32;
result += 32;
if (value >= 10 ** 16) {
value /= 10 ** 16;
result += 16;
if (value >= 10 ** 8) {
value /= 10 ** 8;
result += 8;
if (value >= 10 ** 4) {
value /= 10 ** 4;
result += 4;
if (value >= 10 ** 2) {
value /= 10 ** 2;
result += 2;
if (value >= 10 ** 1) {
result += 1;
return result;
* @dev Return the log in base 10, following the selected rounding direction, of a positive value.
* Returns 0 if given 0.
function log10(uint256 value, Rounding rounding) internal pure returns (uint256) {
unchecked {
uint256 result = log10(value);
return result + (unsignedRoundsUp(rounding) && 10 ** result < value ? 1 : 0);
* @dev Return the log in base 256 of a positive value rounded towards zero.
* Returns 0 if given 0.
* Adding one to the result gives the number of pairs of hex symbols needed to represent `value` as a hex string.
function log256(uint256 value) internal pure returns (uint256) {
uint256 result = 0;
unchecked {
if (value >> 128 > 0) {
value >>= 128;
result += 16;
if (value >> 64 > 0) {
value >>= 64;
result += 8;
if (value >> 32 > 0) {
value >>= 32;
result += 4;
if (value >> 16 > 0) {
value >>= 16;
result += 2;
if (value >> 8 > 0) {
result += 1;
return result;
* @dev Return the log in base 256, following the selected rounding direction, of a positive value.
* Returns 0 if given 0.
function log256(uint256 value, Rounding rounding) internal pure returns (uint256) {
unchecked {
uint256 result = log256(value);
return result + (unsignedRoundsUp(rounding) && 1 << (result << 3) < value ? 1 : 0);
* @dev Returns whether a provided rounding mode is considered rounding up for unsigned integers.
function unsignedRoundsUp(Rounding rounding) internal pure returns (bool) {
return uint8(rounding) % 2 == 1;
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (interfaces/draft-IERC6093.sol)
pragma solidity ^0.8.20;
* @dev Standard ERC20 Errors
* Interface of the[ERC-6093] custom errors for ERC20 tokens.
interface IERC20Errors {
* @dev Indicates an error related to the current `balance` of a `sender`. Used in transfers.
* @param sender Address whose tokens are being transferred.
* @param balance Current balance for the interacting account.
* @param needed Minimum amount required to perform a transfer.
error ERC20InsufficientBalance(address sender, uint256 balance, uint256 needed);
* @dev Indicates a failure with the token `sender`. Used in transfers.
* @param sender Address whose tokens are being transferred.
error ERC20InvalidSender(address sender);
* @dev Indicates a failure with the token `receiver`. Used in transfers.
* @param receiver Address to which tokens are being transferred.
error ERC20InvalidReceiver(address receiver);
* @dev Indicates a failure with the `spender`’s `allowance`. Used in transfers.
* @param spender Address that may be allowed to operate on tokens without being their owner.
* @param allowance Amount of tokens a `spender` is allowed to operate with.
* @param needed Minimum amount required to perform a transfer.
error ERC20InsufficientAllowance(address spender, uint256 allowance, uint256 needed);
* @dev Indicates a failure with the `approver` of a token to be approved. Used in approvals.
* @param approver Address initiating an approval operation.
error ERC20InvalidApprover(address approver);
* @dev Indicates a failure with the `spender` to be approved. Used in approvals.
* @param spender Address that may be allowed to operate on tokens without being their owner.
error ERC20InvalidSpender(address spender);
* @dev Standard ERC721 Errors
* Interface of the[ERC-6093] custom errors for ERC721 tokens.
interface IERC721Errors {
* @dev Indicates that an address can't be an owner. For example, `address(0)` is a forbidden owner in EIP-20.
* Used in balance queries.
* @param owner Address of the current owner of a token.
error ERC721InvalidOwner(address owner);
* @dev Indicates a `tokenId` whose `owner` is the zero address.
* @param tokenId Identifier number of a token.
error ERC721NonexistentToken(uint256 tokenId);
* @dev Indicates an error related to the ownership over a particular token. Used in transfers.
* @param sender Address whose tokens are being transferred.
* @param tokenId Identifier number of a token.
* @param owner Address of the current owner of a token.
error ERC721IncorrectOwner(address sender, uint256 tokenId, address owner);
* @dev Indicates a failure with the token `sender`. Used in transfers.
* @param sender Address whose tokens are being transferred.
error ERC721InvalidSender(address sender);
* @dev Indicates a failure with the token `receiver`. Used in transfers.
* @param receiver Address to which tokens are being transferred.
error ERC721InvalidReceiver(address receiver);
* @dev Indicates a failure with the `operator`’s approval. Used in transfers.
* @param operator Address that may be allowed to operate on tokens without being their owner.
* @param tokenId Identifier number of a token.
error ERC721InsufficientApproval(address operator, uint256 tokenId);
* @dev Indicates a failure with the `approver` of a token to be approved. Used in approvals.
* @param approver Address initiating an approval operation.
error ERC721InvalidApprover(address approver);
* @dev Indicates a failure with the `operator` to be approved. Used in approvals.
* @param operator Address that may be allowed to operate on tokens without being their owner.
error ERC721InvalidOperator(address operator);
* @dev Standard ERC1155 Errors
* Interface of the[ERC-6093] custom errors for ERC1155 tokens.
interface IERC1155Errors {
* @dev Indicates an error related to the current `balance` of a `sender`. Used in transfers.
* @param sender Address whose tokens are being transferred.
* @param balance Current balance for the interacting account.
* @param needed Minimum amount required to perform a transfer.
* @param tokenId Identifier number of a token.
error ERC1155InsufficientBalance(address sender, uint256 balance, uint256 needed, uint256 tokenId);
* @dev Indicates a failure with the token `sender`. Used in transfers.
* @param sender Address whose tokens are being transferred.
error ERC1155InvalidSender(address sender);
* @dev Indicates a failure with the token `receiver`. Used in transfers.
* @param receiver Address to which tokens are being transferred.
error ERC1155InvalidReceiver(address receiver);
* @dev Indicates a failure with the `operator`’s approval. Used in transfers.
* @param operator Address that may be allowed to operate on tokens without being their owner.
* @param owner Address of the current owner of a token.
error ERC1155MissingApprovalForAll(address operator, address owner);
* @dev Indicates a failure with the `approver` of a token to be approved. Used in approvals.
* @param approver Address initiating an approval operation.
error ERC1155InvalidApprover(address approver);
* @dev Indicates a failure with the `operator` to be approved. Used in approvals.
* @param operator Address that may be allowed to operate on tokens without being their owner.
error ERC1155InvalidOperator(address operator);
* @dev Indicates an array length mismatch between ids and values in a safeBatchTransferFrom operation.
* Used in batch transfers.
* @param idsLength Length of the array of token identifiers
* @param valuesLength Length of the array of token amounts
error ERC1155InvalidArrayLength(uint256 idsLength, uint256 valuesLength);
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (utils/introspection/ERC165.sol)
pragma solidity ^0.8.20;
import {IERC165} from "./IERC165.sol";
* @dev Implementation of the {IERC165} interface.
* Contracts that want to implement ERC165 should inherit from this contract and override {supportsInterface} to check
* for the additional interface id that will be supported. For example:
* ```solidity
* function supportsInterface(bytes4 interfaceId) public view virtual override returns (bool) {
* return interfaceId == type(MyInterface).interfaceId || super.supportsInterface(interfaceId);
* }
* ```
abstract contract ERC165 is IERC165 {
* @dev See {IERC165-supportsInterface}.
function supportsInterface(bytes4 interfaceId) public view virtual returns (bool) {
return interfaceId == type(IERC165).interfaceId;
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.1) (utils/Context.sol)
pragma solidity ^0.8.20;
* @dev Provides information about the current execution context, including the
* sender of the transaction and its data. While these are generally available
* via msg.sender and, they should not be accessed in such a direct
* manner, since when dealing with meta-transactions the account sending and
* paying for execution may not be the actual sender (as far as an application
* is concerned).
* This contract is only required for intermediate, library-like contracts.
abstract contract Context {
function _msgSender() internal view virtual returns (address) {
return msg.sender;
function _msgData() internal view virtual returns (bytes calldata) {
function _contextSuffixLength() internal view virtual returns (uint256) {
return 0;
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (token/ERC721/extensions/IERC721Metadata.sol)
pragma solidity ^0.8.20;
import {IERC721} from "../IERC721.sol";
* @title ERC-721 Non-Fungible Token Standard, optional metadata extension
* @dev See
interface IERC721Metadata is IERC721 {
* @dev Returns the token collection name.
function name() external view returns (string memory);
* @dev Returns the token collection symbol.
function symbol() external view returns (string memory);
* @dev Returns the Uniform Resource Identifier (URI) for `tokenId` token.
function tokenURI(uint256 tokenId) external view returns (string memory);
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (token/ERC721/IERC721Receiver.sol)
pragma solidity ^0.8.20;
* @title ERC721 token receiver interface
* @dev Interface for any contract that wants to support safeTransfers
* from ERC721 asset contracts.
interface IERC721Receiver {
* @dev Whenever an {IERC721} `tokenId` token is transferred to this contract via {IERC721-safeTransferFrom}
* by `operator` from `from`, this function is called.
* It must return its Solidity selector to confirm the token transfer.
* If any other value is returned or the interface is not implemented by the recipient, the transfer will be
* reverted.
* The selector can be obtained in Solidity with `IERC721Receiver.onERC721Received.selector`.
function onERC721Received(
address operator,
address from,
uint256 tokenId,
bytes calldata data
) external returns (bytes4);
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (token/ERC721/IERC721.sol)
pragma solidity ^0.8.20;
import {IERC165} from "../../utils/introspection/IERC165.sol";
* @dev Required interface of an ERC721 compliant contract.
interface IERC721 is IERC165 {
* @dev Emitted when `tokenId` token is transferred from `from` to `to`.
event Transfer(address indexed from, address indexed to, uint256 indexed tokenId);
* @dev Emitted when `owner` enables `approved` to manage the `tokenId` token.
event Approval(address indexed owner, address indexed approved, uint256 indexed tokenId);
* @dev Emitted when `owner` enables or disables (`approved`) `operator` to manage all of its assets.
event ApprovalForAll(address indexed owner, address indexed operator, bool approved);
* @dev Returns the number of tokens in ``owner``'s account.
function balanceOf(address owner) external view returns (uint256 balance);
* @dev Returns the owner of the `tokenId` token.
* Requirements:
* - `tokenId` must exist.
function ownerOf(uint256 tokenId) external view returns (address owner);
* @dev Safely transfers `tokenId` token from `from` to `to`.
* Requirements:
* - `from` cannot be the zero address.
* - `to` cannot be the zero address.
* - `tokenId` token must exist and be owned by `from`.
* - If the caller is not `from`, it must be approved to move this token by either {approve} or {setApprovalForAll}.
* - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon
* a safe transfer.
* Emits a {Transfer} event.
function safeTransferFrom(address from, address to, uint256 tokenId, bytes calldata data) external;
* @dev Safely transfers `tokenId` token from `from` to `to`, checking first that contract recipients
* are aware of the ERC721 protocol to prevent tokens from being forever locked.
* Requirements:
* - `from` cannot be the zero address.
* - `to` cannot be the zero address.
* - `tokenId` token must exist and be owned by `from`.
* - If the caller is not `from`, it must have been allowed to move this token by either {approve} or
* {setApprovalForAll}.
* - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon
* a safe transfer.
* Emits a {Transfer} event.
function safeTransferFrom(address from, address to, uint256 tokenId) external;
* @dev Transfers `tokenId` token from `from` to `to`.
* WARNING: Note that the caller is responsible to confirm that the recipient is capable of receiving ERC721
* or else they may be permanently lost. Usage of {safeTransferFrom} prevents loss, though the caller must
* understand this adds an external call which potentially creates a reentrancy vulnerability.
* Requirements:
* - `from` cannot be the zero address.
* - `to` cannot be the zero address.
* - `tokenId` token must be owned by `from`.
* - If the caller is not `from`, it must be approved to move this token by either {approve} or {setApprovalForAll}.
* Emits a {Transfer} event.
function transferFrom(address from, address to, uint256 tokenId) external;
* @dev Gives permission to `to` to transfer `tokenId` token to another account.
* The approval is cleared when the token is transferred.
* Only a single account can be approved at a time, so approving the zero address clears previous approvals.
* Requirements:
* - The caller must own the token or be an approved operator.
* - `tokenId` must exist.
* Emits an {Approval} event.
function approve(address to, uint256 tokenId) external;
* @dev Approve or remove `operator` as an operator for the caller.
* Operators can call {transferFrom} or {safeTransferFrom} for any token owned by the caller.
* Requirements:
* - The `operator` cannot be the address zero.
* Emits an {ApprovalForAll} event.
function setApprovalForAll(address operator, bool approved) external;
* @dev Returns the account approved for `tokenId` token.
* Requirements:
* - `tokenId` must exist.
function getApproved(uint256 tokenId) external view returns (address operator);
* @dev Returns if the `operator` is allowed to manage all of the assets of `owner`.
* See {setApprovalForAll}
function isApprovedForAll(address owner, address operator) external view returns (bool);
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v5.0.0) (utils/introspection/IERC165.sol)
pragma solidity ^0.8.20;
* @dev Interface of the ERC165 standard, as defined in the
* Implementers can declare support of contract interfaces, which can then be
* queried by others ({ERC165Checker}).
* For an implementation, see {ERC165}.
interface IERC165 {
* @dev Returns true if this contract implements the interface defined by
* `interfaceId`. See the corresponding
*[EIP section]
* to learn more about how these ids are created.
* This function call must use less than 30 000 gas.
function supportsInterface(bytes4 interfaceId) external view returns (bool);