Web3 & DApp Development Fundamentals · Lektion

Allowances

Delegierte Transfers

Lektion 3 von 413 Schritte

Allowances ist eine kostenlose Web3 & DApp Development Fundamentals-Lektion auf CoddyKit. Dies ist Lektion 3 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Web3 & DApp Development Fundamentals-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Web3 & DApp Development Fundamentals-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

Delegated Transfers

Allowances let a token owner authorize another account - the spender - to move tokens on their behalf. This is what enables decentralized exchanges and DeFi protocols to pull your tokens with permission.

The flow is: approve sets a limit, then transferFrom spends within it.

The Allowance Storage

Allowances live in a nested mapping: owner to spender to amount. It records how much each spender may move for each owner.

<code>mapping(address => mapping(address => uint256)) public allowance;</code>

Setting an Allowance

The owner calls approve to authorize a spender. This overwrites any previous allowance for that spender.

<code>function approve(address spender, uint256 amount) public returns (bool) {
    allowance[msg.sender][spender] = amount;
    emit Approval(msg.sender, spender, amount);
    return true;
}</code>

Reading an Allowance

Anyone can query the remaining allowance with the public mapping or the standard allowance(owner, spender) view function.

<code>// remaining = allowance[owner][spender];
function allowanceOf(address owner, address spender) public view returns (uint256) {
    return allowance[owner][spender];
}</code>

Implementing transferFrom

transferFrom lets an approved spender move tokens from the owner to a recipient. It must check both the owner's balance and the spender's allowance.

<code>function transferFrom(address from, address to, uint256 amount) public returns (bool) {
    require(balanceOf[from] >= amount, 'insufficient balance');
    require(allowance[from][msg.sender] >= amount, 'allowance exceeded');
    allowance[from][msg.sender] -= amount;
    balanceOf[from] -= amount;
    balanceOf[to] += amount;
    emit Transfer(from, to, amount);
    return true;
}</code>

Decrementing the Allowance

Notice that transferFrom reduces the allowance by the amount spent. This prevents a spender from reusing the same approval indefinitely.

<code>allowance[from][msg.sender] -= amount; // consumed</code>

Infinite Approval

Some protocols request the maximum uint256 allowance so users only approve once. Many implementations skip decrementing when the allowance is set to this max value, saving gas.

<code>uint256 constant MAX = type(uint256).max;
// if (allowance == MAX) skip decrement</code>

The Approve Race Condition

There is a known hazard: changing an allowance from one non-zero value to another can be front-run, letting a spender use both. The classic mitigation is to set the allowance to 0 first, then to the new value.

<code>// recommended pattern
token.approve(spender, 0);
token.approve(spender, newAmount);</code>

increaseAllowance and decreaseAllowance

To avoid the race condition, some tokens add helper functions that adjust the allowance relative to its current value rather than overwriting it.

<code>function increaseAllowance(address spender, uint256 added) public returns (bool) {
    allowance[msg.sender][spender] += added;
    emit Approval(msg.sender, spender, allowance[msg.sender][spender]);
    return true;
}</code>

Real-World Use: DEX

When you trade on a DEX you first approve the router contract. The router then calls transferFrom to pull your tokens into the swap. Without the allowance the trade cannot happen.

Security Reminder

An allowance is a standing permission. Granting an infinite allowance to a malicious or buggy contract can drain your tokens. Review and revoke unused approvals regularly.

<code>// revoke by approving zero
token.approve(spender, 0);</code>

Quick Check

Test your understanding of allowances.

Recap

You learned the allowance mechanism:

  • approve sets allowance[owner][spender]
  • transferFrom spends within the allowance and decrements it
  • The approve race condition is mitigated by setting to 0 first or using increase/decreaseAllowance
  • Allowances power DEXs and DeFi - revoke unused ones for safety
Kostenlos starten

Lerne Web3 & DApp Development Fundamentals mit einem KI-Tutor — kostenlos

Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.

Kurse
29
Lektionen
105

Häufig gestellte Fragen

Ist die Lektion „Allowances“ kostenlos?

Ja — der vollständige Text von „Allowances“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Web3 & DApp Development Fundamentals-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Web3 & DApp Development Fundamentals-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Allowances“?

Delegierte Transfers Du übst Web3 & DApp Development Fundamentals mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Web3 & DApp Development Fundamentals zu starten?

Keine Vorkenntnisse erforderlich. Web3 & DApp Development Fundamentals auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 3 von 4.

Wie lange dauert die Lektion „Allowances“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Web3 & DApp Development Fundamentals-Lektion Code schreiben und ausführen?

Ja. Jede Web3 & DApp Development Fundamentals-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Der ERC-20-Standard
  2. Einen Token implementieren
  3. Allowances
  4. Minting und Burning
← Zurück zu Web3 & DApp Development Fundamentals