Skip to content

fix(isFromOwner): compare owner and sender addresses case-insensitively - #31

Open
devorun wants to merge 1 commit into
xmtp:mainfrom
devorun:fix/owner-address-case-insensitive
Open

devorun wants to merge 1 commit into
xmtp:mainfrom
devorun:fix/owner-address-case-insensitive

Conversation

@devorun

@devorun devorun commented Aug 11, 2026 •

Copy link
Copy Markdown

Problem

isFromOwner compares the sender address to XMTP_OWNER_ADDRESS with strict ===:

if (senderAddress === ownerAddress) {

Ethereum addresses are case-insensitive. XMTP_OWNER_ADDRESS is provided by the user (commonly copied from a wallet or block explorer as an EIP-55 checksummed, mixed-case string), while ctx.getSenderAddress() returns the address in whatever casing the SDK produces. When the two casings differ, the strict comparison fails and the owner's own messages are silently ignored — the middleware locks the owner out of their own agent.

Fix

Compare the addresses case-insensitively, keeping the check undefined-safe so a missing sender address still fails closed:

if (senderAddress?.toLowerCase() === ownerAddress.toLowerCase()) {

Verified with the project's npm test (tsc --noEmit).

Note

Fix isFromOwner middleware to compare Ethereum addresses case-insensitively

Ethereum addresses can appear in mixed case (e.g. EIP-55 checksum format), so a strict equality check can incorrectly reject valid owners. isFromOwner.ts now lowercases both senderAddress and ownerAddress before comparing, and uses optional chaining on senderAddress to avoid errors when it is undefined.

Macroscope summarized cad444d.

Ethereum addresses are case-insensitive. XMTP_OWNER_ADDRESS is user-provided
and may be checksummed, while getSenderAddress() may return a different casing,
so a strict === comparison can lock the owner out of their own agent.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant