Parse decimal and hexadecimal owner token IDs exactly - #16
Conversation
Signed-off-by: GelatoGenesis <1407802+GelatoGenesis@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Comment |
6529bot WCAG 2.2 AA analysis - dbdf509Verdict: No WCAG findings This PR is a backend/library change (token ID parsing, dependency bumps, test and CI updates) in |
6529bot general PR review - dbdf509Verdict: Good to merge The core change is a genuine correctness fix. The old code always prepended Nice-to-have
No blocking or correctness concerns. The dependency bumps ( |
6529bot i18n analysis - dbdf509Verdict: No i18n findings This PR is a backend/library change in
There is no React UI, no |
6529bot crypto security analysis - dbdf509Verdict: No security findings The core change to
One CI note worth flagging for maintainers (not a code-level finding in the reviewed source): adding a Nothing blocking from a crypto/security standpoint. |
Signed-off-by: GelatoGenesis <1407802+GelatoGenesis@users.noreply.github.com>
6529bot follow-up commit review - e4471e8Verdict: No new findings The two follow-up commits directly address the prior nice-to-have suggestions and introduce no regressions. Resolved since last review
Both changes preserve correct behavior: the regex remains fully anchored, |
|



Issue
Historical Alchemy owner snapshots interpreted every token ID as hexadecimal. A decimal response for token 10 therefore became token 16, producing empty or incorrect allowlists.
Fix
Parse decimal IDs as decimal and use hexadecimal only with an explicit 0x prefix. Preserve BigInt precision and reject malformed or out-of-range uint256 IDs instead of truncating them.
Changes
Validation
Risk
Review Notes
The companion API adapter normalizes IDs to explicit hex, so EMMA can retain its tested dependency while this package is released independently.
Companion API fix and staging deployment evidence: 6529-Collections/allowlist-api#74. The reviewed change is merged into staging and main; 6529bot follow-up reports no new findings and all checks are green.
Published as 0.0.137 by the validated npm release workflow. Registry version and artifact checksum were verified after publication.