Skip to content

feat: expose Flamingo matching on wasm through uniffi - #554

Closed
Dzejkop wants to merge 3 commits into
codex/persistent-browser-demofrom
codex/flamingo-wasm-on-stack
Closed

Dzejkop wants to merge 3 commits into
codex/persistent-browser-demofrom
codex/flamingo-wasm-on-stack

Conversation

@Dzejkop

@Dzejkop Dzejkop commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Makes attested Flamingo matching callable from browsers through the UniFFI exports only: walletkit-core::flamingo now compiles on wasm32-unknown-unknown and is exported via this stack's ubrn pipeline (crates/walletkit -> web/walletkit npm package walletkit-web). The uniffi surface (FlamingoMatcher, FlamingoMatchRequest, FlamingoMatchOutcome, FlamingoMatchRejection, FlamingoError, VerifiedMatchToken) is unchanged and remains the API layer.

This supersedes #548's approach for the stack: the wasm-bindgen crate (crates/walletkit-web) and the standalone worker fixture (web/ client/worker + Playwright) were dropped deliberately. Exposing Flamingo through web/walletkit's hand-written TS client (protocol.ts / walletkit.worker.ts / index.ts) is a follow-up.

Changes

  • Browser-compatible dependency pins (exact revs):
  • wasm enablement: un-gated walletkit-core::flamingo for wasm32; #[cfg_attr(target_arch = "wasm32", async_trait(?Send))] on the internal MatchClient trait/impls; the uniffi-wasm export pattern on FlamingoMatcher::perform_match (matching authenticator); module unit tests gated native-only.
  • deny.toml: required-git-spec = "rev" plus allow-git entries for the flamingo/pontifex sources (sources check stays green).
  • CI: --locked added to the existing WASM check/test commands to protect the git pins. No new jobs or web-package steps.

Validation (local, rust 1.98.1)

  • cargo deny check advisories ✅ (previously the only failing job, run 35728811406)
  • cargo deny check bans licenses sources ✅
  • cargo metadata --locked ✅
  • cargo check -p walletkit-core --no-default-features --locked ✅
  • cargo check -p walletkit-core --no-default-features --features uniffi-wasm --locked --target wasm32-unknown-unknown ✅
  • cargo check -p walletkit --features embed-zkeys --locked --target wasm32-unknown-unknown ✅
  • cargo check -p walletkit --no-default-features --features embed-zkeys --locked --target wasm32-unknown-unknown ✅
  • cargo fmt --all -- --check ✅

Follow-ups / risks


Note

Medium Risk
Introduces browser-callable attested matching and pins security-sensitive verifier code to git SHAs until upstream browser fixes ship on crates.io.

Overview
Enables walletkit-core::flamingo on wasm32 so attested Flamingo matching can be exported through the existing UniFFI stack (same uniffi-wasm vs tokio export split as authenticator). The module is no longer gated off on wasm; MatchClient uses async_trait(?Send) on wasm, and Flamingo unit tests run only on native targets.

Replaces crates.io flamingo-verifier-* and pontifex with git rev pins that avoid browser panics from std::time::SystemTime::now() in published pontifex 2.0.0. walletkit-core now pulls the verifier crates (and async-trait) for all targets, not only native. Cargo.lock reflects the new sources; deny.toml requires rev on git deps and allowlists the Worldcoin flamingo/pontifex repos.

CI adds --locked to the existing WASM cargo check / cargo test steps so those pins cannot drift in CI.

Reviewed by Cursor Bugbot for commit 775c67c. Bugbot is set up for automated code reviews on this repo. Configure here.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate findings remain in worker failure handling and decoder compatibility coverage.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds browser WASM support for Flamingo matching through new bindings, a dedicated worker fixture, browser tests, pinned dependencies, and Rust 1.98.1 tooling.

Changes:

  • Adds walletkit-web wasm-bindgen APIs and worker-based RPC.
  • Enables WASM Flamingo support with Chromium/WebKit coverage.
  • Updates dependency pins, MSRV, CI, and release tooling.
File Summary
web/​worker.js Serialized worker RPC and lifecycle; P1 critical, 1 vote: bound verifier requests with deadlines and typed timeout handling.
web/​tests/​server.mjs Browser fixture server.
web/​tests/​client.spec.js Browser integration tests.
web/​README.md Fixture and RPC documentation.
web/​playwright.config.js Chromium/WebKit configuration.
web/​package.json Browser test dependencies.
web/​package-lock.json Locked npm dependencies.
web/​client.js Page-side worker client; two P2 moderate findings, 1 vote each: normalize construction failures and correctly classify post-initialization worker errors.
web/​build.sh WASM build pipeline.
web/​.gitignore Generated artifact exclusions.
rust-toolchain.toml Rust 1.98.1 toolchain.
README.md Browser binding documentation.
flake.lock Updated Rust overlay.
deny.toml Allowed pinned git sources.
crates/​walletkit-web/​src/​lib.rs wasm-bindgen Flamingo API.
crates/​walletkit-web/​Cargo.toml New web crate metadata.
crates/​walletkit-core/​src/​v3/​world_id.rs Assertion update.
crates/​walletkit-core/​src/​storage/​cache/​activity.rs Activity ID decoding; P2 moderate, 1 vote: add a frozen-byte compatibility assertion.
crates/​walletkit-core/​src/​lib.rs Enables Flamingo on WASM.
crates/​walletkit-core/​src/​flamingo.rs WASM async and export support.
crates/​walletkit-core/​Cargo.toml Cross-target Flamingo dependencies.
Cargo.toml Workspace crate, MSRV, and git pins.
Cargo.lock Locked dependency graph.
.github/​workflows/​release.yml Release toolchain pin.
.github/​workflows/​release-swift-kotlin.yml Updated release toolchain.
.github/​workflows/​ci.yml WASM and browser CI coverage.
Files not reviewed (1)
  • web/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread web/worker.js Outdated
Comment on lines +15 to +16
/** Serialized handling keeps dispose() from freeing a client with an in-flight call. */
let queue = Promise.resolve();
crates.io flamingo-verifier-* 0.4.0 and pontifex 2.0.0 are not browser-safe:
pontifex 2.0.0 calls std::time::SystemTime::now(), which panics in browsers.
Pin the browser-compatible 0.4 line (worldcoin/flamingo#116) and the pontifex
rev it pins (worldcoin/pontifex#47), and enforce rev-pinned git sources in
cargo-deny. Move to merged revs/tags once worldcoin/flamingo#116 lands.
Make walletkit-core::flamingo compile on wasm32-unknown-unknown so attested
Flamingo matching is callable from browsers through the generated UniFFI
bindings:

- move flamingo-verifier-* and async-trait to shared dependencies and un-gate
  the module for wasm32
- use async_trait(?Send) on wasm and the uniffi-wasm export pattern on
  FlamingoMatcher
- keep the module's unit tests native-only
- add --locked to the WASM CI checks to protect the git pins
@Dzejkop
Dzejkop force-pushed the codex/persistent-browser-demo branch from bc85fd2 to 627eabe Compare September 22, 2026 13:46
@Dzejkop
Dzejkop requested review from a team and wld-walletkit-bot as code owners September 22, 2026 13:46
@Dzejkop
Dzejkop force-pushed the codex/flamingo-wasm-on-stack branch from eb042f4 to c86167e Compare September 22, 2026 13:46
Copilot AI review requested due to automatic review settings September 22, 2026 13:46
@Dzejkop Dzejkop changed the title feat: support Flamingo matching in browser WASM (port of #548) feat: expose Flamingo matching on wasm through uniffi Sep 22, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Add browser runtime coverage for the exported Flamingo async API; it is currently only compile-checked.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)

}

#[cfg(test)]
#[cfg(all(test, not(target_arch = "wasm32")))]
Re-pin the flamingo-verifier-* crates to worldcoin/flamingo#116's branch
head and pontifex to worldcoin/pontifex#47's merged rev.
Copilot AI review requested due to automatic review settings September 22, 2026 15:13

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

HTTPS enforcement and focused WASM/browser runtime coverage are unresolved; the unused Pontifex workspace entry also needs cleanup.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity · 1 Medium severity

Open (3)

Comment on lines +57 to +58
#[cfg_attr(feature = "uniffi-wasm", uniffi::export)]
#[cfg_attr(not(feature = "uniffi-wasm"), uniffi::export(async_runtime = "tokio"))]
@Dzejkop

Dzejkop commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

closing for now - WASM/Browser env will need a very different setup for authorizing operations

@Dzejkop Dzejkop closed this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants