Skip to content

js: Check metadata string limits in UTF-8 bytes - #862

Open
ara-stock wants to merge 1 commit into
solana-program:mainfrom
ara-stock:js-metadata-byte-length-checks
Open

ara-stock wants to merge 1 commit into
solana-program:mainfrom
ara-stock:js-metadata-byte-length-checks

Conversation

@ara-stock

Copy link
Copy Markdown
Contributor

Problem

updateTokenMetadataInstruction in clients/js checks the name, symbol and URI limits with tokenName.length > 32, tokenSymbol.length > 10 and tokenUri.length > 200. These count UTF-16 code units, but the Metaplex limits are in bytes (the CLI's is_valid_token_* already uses s.len()). So a non-ASCII value can pass the client check and then fail on chain. For example, 'あ'.repeat(11) is 11 characters but 33 bytes: the client builds the instruction, and the transaction fails with Metaplex custom program error: 0xb (NameTooLong). The same happens for a 12-byte symbol (0xc) and a 201-byte URI (0xd).

Summary of Changes

  • Encode the strings with TextEncoder before the checks (the encoded bytes were already used for the instruction data since js: Use UTF-8 byte length for metadata string prefixes #859) and compare the byte lengths against the limits. The error messages now say "bytes".
  • Add a js-legacy test that updateTokenMetadata rejects a name, symbol and URI that are within the character count but over the byte limit.

I used an AI assistant (Claude) while preparing this. I reproduced the issue and checked the fix and tests myself.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant