Skip to main content

token_unshield_extra_sighash_data

Function token_unshield_extra_sighash_data 

Source
pub fn token_unshield_extra_sighash_data(
    token_id: &[u8; 32],
    owner_id: &[u8; 32],
    recipient_id: &[u8; 32],
    amount: u64,
    platform_version: &PlatformVersion,
) -> Result<Vec<u8>, ProtocolError>
Expand description

Builds the transparent extra_data bound into a TokenUnshield’s platform sighash, with the byte layout token_id (32) || owner_id (32) || recipient_id (32) || amount (u64 LE).

A token unshield rides inside an identity-signed batch, but the note owner who authorizes the Orchard spend is not necessarily that identity. The spend-auth and binding signatures must therefore commit to the pool the notes leave (token_id), the identity paying the credits fee and submitting the batch (owner_id), the identity credited (recipient_id) and the gross amount, so a bundle observed in the mempool cannot be re-wrapped by another submitter to a different recipient or against another token’s pool (every token pool starts from the same empty-tree anchor).