Docs menu

LOCKET docs, for developers

Contract

LocketCollection is a buyer-paid ERC-721 on Robinhood Chain 4663. Its EIP-712 domain is Locket Collection, version 1, bound to the chain and deployed collection address. It inherits Ownable and Pausable. No relayer or hook mints pieces for buyers.

Status

Deployment

Constructor fields, in order: address owner, address signer, address token, address pool, uint256 minBuy. The first claimer can publish the fixed constructor payload through the canonical CREATE2 proxy. The owner, signer, token, selling pool and positive minimum are fixed by that payload. Only the owner can rotate the nonzero signer with setSigner. It emits SignerChanged(oldSigner,newSigner). Pending authorizations from the old signer then fail. Roll out the matching API SIGNER_KEY with the on-chain change.

Mint authorization

MintAuthorization(address buyer,bytes32 buyRef,uint256 amountIn,uint256 deadline,bytes32 commitment,bytes32 ciphertextHash)
mintForBuy(address buyer, bytes32 buyRef, uint256 amountIn, uint256 deadline, bytes signature, bytes32 commitment, bytes ciphertext)

The buyer wallet prepares an encrypted seal before calling the API. The request includes its nonzero commitment and keccak256(ciphertext), but never the secret or wallet signature. The API checks a confirmed token Transfer from the selling pool to the final buyer and signs this exact typed message. The buyer verifies both returned binding fields and submits the same prepared commitment and ciphertext. The contract checks the ciphertext hash and rejects ciphertext outside 29 to 4096 bytes. The contract checks signer, deadline, minimum, transaction sender equal to buyer, unused buy reference and a lifetime one-claim rule for that buyer through claimedBuyer, regardless of current NFT balance. A repeated buyer reverts with BuyerAlreadyClaimed(). The contract does not inspect past token transfers itself. The buyer pays the network fee. A signer mistake can authorize an ineligible buy, so the API proof remains a trust boundary.

Functions and events

Public and operator ABI entries: mintForBuy, authorizationHash, ownerOf, seedFor, seedOf, traitsForSeed, traitsOf, traitNamesOf, commitmentOf, ciphertextOf, cycleOf, reserve, commitClaim, claimWithCode, tokenURI, usedBuy, claimedBuyer, setSigner, pause, unpause. Inherited ERC-721 owner, approval, transfer and ERC-165 functions remain available. The contract emits SignerChanged(oldSigner,newSigner), Locked, Sealed, Transfer as applicable. renounceOwnership reverts to preserve signer rotation.

Locket privacy mechanism

The browser encrypts a random charm with AES-GCM and wraps its key to an immutable Lit action identity. The action checks the current holder with pinned Robinhood Chain RPC reads. Transfer preserves ciphertext and commitment. Former holders may keep plaintext or keys already obtained. Live Lit behavior remains unverified.

Artwork and metadata

imageForTraits(uint8[5], bool, bytes32) draws the mint glass card, robot, eight headwear options and five background variants from public trait picks. tokenURI embeds that on-chain SVG and marks SEALED CHARM or UNSEALED. Locked(tokenId,buyer,buyRef,seed) records the original buyer, buy reference and public seedOf(tokenId). The encrypted private charm follows the piece; transfer preserves its seal.

Ethers browser bundle provenance

The local pristine ethers 6.16.0 UMD bundle has SHA-256 9a85a5aa81305f85e6546452fd2093a8a68932bed3cec4f6491e4d031a90bc95. The shipped bundle has SHA-256 65772f76fae0bc74e7b923bc27aa928f48d7a9a72cc374f6393cf9378129d789. Byte comparison found one local license header and five address literal splits. The splits join the same address at runtime. The six exact edits are in contracts/vendor-patches/ethers.umd.min.patch.json. From the workspace root, run node .foreman/seven-cooks/privacy-tools/round5-vendor-proof.cjs to apply the edits to the pristine copy and compare every shipped byte.

The reported SigningKey.addPoints defect is not present in the local evidence: its implementation is byte identical in pristine and shipped ethers 6.16.0. Both compute the compressed point G + 2G as 3G. No addPoints correction can be attributed to this shipped bundle without another verified baseline.

Launch inputs

Collection, token, pool, minimum, owner and signer addresses must be set to real launch values. The buyer must have native gas for the first CREATE2 publication and mint. No production collection address is claimed on this page.