Class: ApplyAllowlistUpdates
Defined in: cct/evm/token-pool/operations/apply-allowlist-updates.ts:104
Applies allowlist removals and additions to an EVM token pool's allowlist in one
applyAllowListUpdates call: on the pool (v1.5.0–v1.6.1) or its bound AdvancedPoolHooks
(v2.0.0).
Extends
EVMOperation<ApplyAllowlistUpdatesParams,ParsedApplyAllowlistUpdatesParams>
Constructors
Constructor
new ApplyAllowlistUpdates():
ApplyAllowlistUpdates
Returns
ApplyAllowlistUpdates
Inherited from
EVMOperation< ApplyAllowlistUpdatesParams, ParsedApplyAllowlistUpdatesParams >.constructor
Properties
name
readonlyname:"applyAllowlistUpdates"='applyAllowlistUpdates'
Defined in: cct/evm/token-pool/operations/apply-allowlist-updates.ts:108
camelCase id; matches the token-manager facade method and error context.
Overrides
EVMOperation.name
Methods
buildUnsigned()
protectedbuildUnsigned(chain:EVMChain,params:ParsedApplyAllowlistUpdatesParams):Promise<UnsignedEVMTx>
Defined in: cct/evm/token-pool/operations/apply-allowlist-updates.ts:193
Resolves which contract holds the pool's allowlist (the pool, or its bound hooks on v2.0.0),
confirms sender owns that holder when it is known, then pre-flights the update against the
current allowlist so nothing that would revert or mine as a no-op is ever built.
Three state preconditions:
- the allowlist must be enabled —
applyAllowListUpdatesopens withif (!i_allowlistEnabled) revert AllowListNotEnabled(). The flag isimmutable, set toallowlist.length > 0in the constructor, so a holder deployed without one can never gain it. Permanent for a legacy pool; a v2.0.0 pool can be re-pointed at other hooks. - every
removesentry must currently be allowlisted —EnumerableSet.removereturns false for an absent address and the holder ignores it, so the tx mines having changed nothing. Mirrorsremove-remote-pool.ts. - no
addsentry may already be allowlisted — the symmetric case:EnumerableSet.addreturns false and the entry is silently skipped.
Parameters
| Parameter | Type |
|---|---|
chain | EVMChain |
params | ParsedApplyAllowlistUpdatesParams |
Returns
Promise<UnsignedEVMTx>
Remarks
The owner check is skipped entirely when sender is omitted — there is nothing to
compare against, and generateUnsignedApplyAllowlistUpdates is expected to be usable before
the eventual signer is known. execute always supplies one. The allowlist pre-flight,
by contrast, does not depend on the signer and always runs.
Throws
CCTOperationUnsupportedError if the pool is v2.0.0 with no hooks bound
Throws
CCTContractTypeInvalidError if the address is not a supported pool type
Throws
CCTContractVersionUnsupportedError if the pool reports an unknown version
Throws
CCTParamsInvalidError if sender is given and is not the holder's owner, if
the holder has no allowlist enabled, if a removes entry is not currently allowlisted, or if
an adds entry already is
Overrides
EVMOperation.buildUnsigned
execute()
execute(
chain:EVMChain,params:EVMExecuteParams<ApplyAllowlistUpdatesParams>):Promise<TransactionResult>
Defined in: cct/evm/operation.ts:150
generate, then sign and submit; returns the confirmed tx hash.
Parameters
| Parameter | Type |
|---|---|
chain | EVMChain |
params | EVMExecuteParams<ApplyAllowlistUpdatesParams> |
Returns
Promise<TransactionResult>
Inherited from
EVMOperation.execute
generate()
generate(
chain:EVMChain,params:ApplyAllowlistUpdatesParams):Promise<UnsignedEVMTx>
Defined in: cct/evm/operation.ts:110
Run prepare and buildUnsigned, applying optional sender; no signing.
Parameters
| Parameter | Type |
|---|---|
chain | EVMChain |
params | ApplyAllowlistUpdatesParams |
Returns
Promise<UnsignedEVMTx>
Remarks
Also pins every built transaction to chain.network.chainId (no RPC, known at
construction). This is the one point every CCT builder and both execute paths pass
through; unpinned, ethers would infer the chain from the eventual signer's provider.
Inherited from
EVMOperation.generate
parse()
protectedparse(__namedParameters:ApplyAllowlistUpdatesParams):ParsedApplyAllowlistUpdatesParams
Defined in: cct/evm/token-pool/operations/apply-allowlist-updates.ts:135
Validates the pool address and every allowlist entry before any RPC, keeping what each check produced (checksummed, duplicate-free arrays) so buildUnsigned and the encoder never re-derive it.
Four judgement calls, all rejections:
- both arrays empty — rejected: such a call encodes and mines while changing nothing, so
it can only be a caller bug; mirrors
lockbox/operations/update-authorized-callers.ts. - duplicates within an array — rejected, mirroring the Solana
configureAllowlist/removeFromAllowlistops. The EVM holder treats its allowlist as a set, so a duplicate is a silent no-op on-chain; catching it locally keeps the two families' contracts identical. - an address in BOTH
addsandremoves— rejected: removes apply first, so the address would end up allowlisted, and no caller can reasonably have meant both. - the zero address in either array — rejected: the holder
continues past it inaddsand so can never hold it, making it a silent no-op on either side.
Comparisons are on checksummed form, so the same address in two different casings still counts as a duplicate / an overlap. The remaining no-ops — removing an address that is not allowlisted, adding one that already is — need the holder's current allowlist and are caught in buildUnsigned.
Parameters
| Parameter | Type |
|---|---|
__namedParameters | ApplyAllowlistUpdatesParams |
Returns
ParsedApplyAllowlistUpdatesParams
Throws
CCTParamsInvalidError if poolAddress is invalid, either array is given but
is not an array or is sparse, both are empty or omitted, an entry is not a valid address or is the zero address
(reported as adds[i] / removes[i]), an array holds duplicates, or an address appears in
both arrays
Overrides
EVMOperation.parse
prepare()
protectedprepare(params:ApplyAllowlistUpdatesParams):ParsedApplyAllowlistUpdatesParams
Defined in: cct/operation.ts:48
validate then parse — the single pre-RPC step, before any chain access.
Parameters
| Parameter | Type |
|---|---|
params | ApplyAllowlistUpdatesParams |
Returns
ParsedApplyAllowlistUpdatesParams
Inherited from
EVMOperation.prepare
resolveWalletSender()
protectedresolveWalletSender(wallet:unknown,sender?:string):Promise<string>
Defined in: cct/evm/operation.ts:130
Resolves the address a signed submission is authorized against: the signing wallet's own.
The chain gates on msg.sender, and submit clears any builder-set tx.from before
populating the tx (so ethers' own from/signer guard never fires) — an explicit sender that
differs from the wallet would therefore let an op's pre-tx checks authorize one address while
a different one actually signs, passing every local guard and reverting on-chain. Ops that
gate on an on-chain role call this from execute; build with generateUnsigned* instead
when the eventual signer isn't known yet, where sender is trusted as given.
Parameters
| Parameter | Type |
|---|---|
wallet | unknown |
sender? | string |
Returns
Promise<string>
Throws
CCIPWalletInvalidError if wallet is not a valid signer
Throws
CCTParamsInvalidError if sender is given and is not the wallet's address
Inherited from
EVMOperation.resolveWalletSender
validate()
protectedvalidate(_params:ApplyAllowlistUpdatesParams):void
Defined in: cct/operation.ts:36
Reject invalid params before any chain RPC. No-op by default: an op that normalizes as it checks does that work in parse instead, and needs no empty stub here.
Parameters
| Parameter | Type |
|---|---|
_params | ApplyAllowlistUpdatesParams |
Returns
void
Inherited from
EVMOperation.validate