Conversation
|
Warning Review limit reachedNext included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: forbole/kastle/.coderabbit.yml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Note
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Moderate issues remain around error handling and preventing fetches with a stale network client.
Review effort: Lite
Findings: 2
Open (2)
What changed in this PR
Adds read-only KRON KCC-20 balance discovery and verified token display for mainnet dashboard assets.
Changes:
- Adds the KRON SDK dependency.
- Implements KCC-20 decoding, ownership checks, balance aggregation, and metadata verification.
- Adds mainnet-gated fetching, dashboard integration, and unit coverage.
| File | Description |
|---|---|
tests/kcc20-unit.spec.ts |
Tests ownership behavior. |
package.json |
Adds the KRON SDK dependency. |
package-lock.json |
Locks the KRON SDK version. |
lib/kcc20/useKcc20Tokens.ts |
Provides the mainnet-only token-fetching hook. |
lib/kcc20/index.ts |
Handles KCC-20 discovery, validation, aggregation, and metadata. |
components/dashboard/TokenListItem.tsx |
Renders KCC-20 balances. |
components/dashboard/Assets.tsx |
Integrates KCC-20 rows into the dashboard. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| const { ok } = await verify.verifyTokenListEntry( | ||
| entry, | ||
| verify.kaspaRestFetchTx(restApi), | ||
| ); | ||
| if (!ok) return undefined; | ||
| const { symbol, name, decimals, logoURI } = entry; | ||
| return { symbol, name, decimals, logoURI }; |
| const { data } = useSWR( | ||
| enabled ? ["kcc20Tokens", address] : null, | ||
| () => fetchKcc20Tokens(address!, rpcClient!, restApis[NetworkType.Mainnet]), | ||
| { refreshInterval: 30_000 }, |
…ng (#357) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…play only) Mainnet only. The indexer's figures are never trusted: a balance counts only if the node holds that outpoint at P2SH(redeem) under the token's covenant id and the decoded state is spendable by this wallet. Name/symbol/decimals/logo come from the KRON registry entry, used only when kron-sdk's verifyTokenListEntry finds that covenant id on the entry's genesis tx. Otherwise the row shows the truncated covenant id and raw base units. Amounts stay bigint until formatUnits. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ng (#357) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
f9fd462 to
f669357
Compare

Scope
KRON (KCC-20) Stage 0 — read-only DISPLAY (no transfers/mint/swap). Adds
@kronsdk/kron-sdk@0.18.2and alib/kcc20/module that fetches KRON covenant UTXOs, decodes the 112-byteKCC20State, matches ownership (isOwnedBy), and renders KRON in the dashboard token list.bigintend-to-end; only converted byformatUnitsfor display.verifyTokenListEntryresolves against the genesis tx via Kastle's own REST API; fallback renders truncatedcovenant_id+ raw base units.Gate
compile 0, build 0, e2e 176 passed (added
tests/kcc20-unit.spec.ts).Review
VERDICT: PASS — minor non-blocking nits (two unused exported URL constants; one
rows as {...}[]cast; a fetch error silently hides the KCC-20 section).Caveat (documented in code)
KRON's name/symbol/decimals are NOT on-chain — they come from KRON's registry, gated by
verifyTokenListEntry. A wrong registry could mislabel a real token; balances are unaffected (read from the node). Pinning KRON's published signing key is the future hardening.Scope class: in-scope (display only). Left open for Leo — new covenant-token surface.