# How to overwrite the function Approve?

**URL:** <https://forum.openzeppelin.com/t/how-to-overwrite-the-function-approve/14292>\
**Category:** Support\
**Tags:** erc20\
**Created:** [August 20, 2021, 10:21pm UTC](https://forum.openzeppelin.com/t/how-to-overwrite-the-function-approve/14292 "2021-08-20T22:21:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeissoni](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@jeissoni](https://forum.openzeppelin.com/u/jeissoni)\
**Post date:** [August 20, 2021, 10:21pm UTC](https://forum.openzeppelin.com/t/how-to-overwrite-the-function-approve/14292/1 "2021-08-20T22:21:53Z")

</div>

It seems that The approve function could be used in an attack that allows a spender to transfer more tokens than the owner of the tokens ever wanted to allow the spender to transfer.

It is advised to use safeapprove.

I import the library SafeERC20

I invoke it from the contract

> contract XVORTEX is ERC20, ERC20Detailed, ERC20Pausable{
> 
> ```
> using SafeERC20 for ERC20;
> 
> constructor(
> string memory _name,
> string memory _symbol,
> uint256 _initialSupply
> ) 
> 
> ERC20Detailed(_name,_symbol, 18) 
> public {
> _mint(msg.sender, _initialSupply);
> }
> 
> ```
> 
> }

But what I don't understand is how to write the approve function, or how to publish the safeapprove function.

Help!

---

<div class="post-metadata">

**Author:** ![STYJ](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@STYJ](https://forum.openzeppelin.com/u/STYJ)\
**Post date:** [August 22, 2021, 7:44am UTC](https://forum.openzeppelin.com/t/how-to-overwrite-the-function-approve/14292/2 "2021-08-22T07:44:45Z")

</div>

from [https://github.com/OpenZeppelin/openzeppelin-contracts/blob/master/contracts/token/ERC20/utils/SafeERC20.sol](https://github.com/OpenZeppelin/openzeppelin-contracts/blob/master/contracts/token/ERC20/utils/SafeERC20.sol)

```auto
/**
 * @title SafeERC20
 * @dev Wrappers around ERC20 operations that throw on failure (when the token
 * contract returns false). Tokens that return no value (and instead revert or
 * throw on failure) are also supported, non-reverting calls are assumed to be
 * successful.
 * To use this library you can add a `using SafeERC20 for IERC20;` statement to your contract,
 * which allows you to call the safe operations as `token.safeTransfer(...)`, etc.
 */

```

See the last line. Also, note that this is not supposed to be used inside your ERC20 token contract but a dapp like uniswap.

---

<div class="post-metadata">

**Author:** ![jeissoni](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@jeissoni](https://forum.openzeppelin.com/u/jeissoni)\
**Post date:** [August 22, 2021, 12:55pm UTC](https://forum.openzeppelin.com/t/how-to-overwrite-the-function-approve/14292/3 "2021-08-22T12:55:09Z")

</div>

Thanks for the reply.

So this library is used is a user interface? It is not necessary to expose these functions to the public in the contract?

---

<div class="post-metadata">

**Author:** ![STYJ](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@STYJ](https://forum.openzeppelin.com/u/STYJ)\
**Post date:** [August 23, 2021, 1:40am UTC](https://forum.openzeppelin.com/t/how-to-overwrite-the-function-approve/14292/4 "2021-08-23T01:40:08Z")

</div>

You don't have to expose it within your ERC20 token contract but for other contracts e.g. if you're making a DEX, you do.

Also just to add, the potential attack vector with approve isn't really fixed with safe approve... see [this](https://github.com/OpenZeppelin/openzeppelin-contracts/blob/master/contracts/token/ERC20/utils/SafeERC20.sol#L37-L43) for more info. If you're going to create an ERC20 token, add the increase / decrease allowance functions and use those instead. You will still want the approve function to be ERC20 compliant though.
