Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical and moderate findings remain in worker failure handling and decoder compatibility coverage.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds browser WASM support for Flamingo matching through new bindings, a dedicated worker fixture, browser tests, pinned dependencies, and Rust 1.98.1 tooling.
Changes:
- Adds
walletkit-webwasm-bindgen APIs and worker-based RPC. - Enables WASM Flamingo support with Chromium/WebKit coverage.
- Updates dependency pins, MSRV, CI, and release tooling.
| File | Summary |
|---|---|
web/worker.js |
Serialized worker RPC and lifecycle; P1 critical, 1 vote: bound verifier requests with deadlines and typed timeout handling. |
web/tests/server.mjs |
Browser fixture server. |
web/tests/client.spec.js |
Browser integration tests. |
web/README.md |
Fixture and RPC documentation. |
web/playwright.config.js |
Chromium/WebKit configuration. |
web/package.json |
Browser test dependencies. |
web/package-lock.json |
Locked npm dependencies. |
web/client.js |
Page-side worker client; two P2 moderate findings, 1 vote each: normalize construction failures and correctly classify post-initialization worker errors. |
web/build.sh |
WASM build pipeline. |
web/.gitignore |
Generated artifact exclusions. |
rust-toolchain.toml |
Rust 1.98.1 toolchain. |
README.md |
Browser binding documentation. |
flake.lock |
Updated Rust overlay. |
deny.toml |
Allowed pinned git sources. |
crates/walletkit-web/src/lib.rs |
wasm-bindgen Flamingo API. |
crates/walletkit-web/Cargo.toml |
New web crate metadata. |
crates/walletkit-core/src/v3/world_id.rs |
Assertion update. |
crates/walletkit-core/src/storage/cache/activity.rs |
Activity ID decoding; P2 moderate, 1 vote: add a frozen-byte compatibility assertion. |
crates/walletkit-core/src/lib.rs |
Enables Flamingo on WASM. |
crates/walletkit-core/src/flamingo.rs |
WASM async and export support. |
crates/walletkit-core/Cargo.toml |
Cross-target Flamingo dependencies. |
Cargo.toml |
Workspace crate, MSRV, and git pins. |
Cargo.lock |
Locked dependency graph. |
.github/workflows/release.yml |
Release toolchain pin. |
.github/workflows/release-swift-kotlin.yml |
Updated release toolchain. |
.github/workflows/ci.yml |
WASM and browser CI coverage. |
Files not reviewed (1)
- web/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| /** Serialized handling keeps dispose() from freeing a client with an in-flight call. */ | ||
| let queue = Promise.resolve(); |
crates.io flamingo-verifier-* 0.4.0 and pontifex 2.0.0 are not browser-safe: pontifex 2.0.0 calls std::time::SystemTime::now(), which panics in browsers. Pin the browser-compatible 0.4 line (worldcoin/flamingo#116) and the pontifex rev it pins (worldcoin/pontifex#47), and enforce rev-pinned git sources in cargo-deny. Move to merged revs/tags once worldcoin/flamingo#116 lands.
Make walletkit-core::flamingo compile on wasm32-unknown-unknown so attested Flamingo matching is callable from browsers through the generated UniFFI bindings: - move flamingo-verifier-* and async-trait to shared dependencies and un-gate the module for wasm32 - use async_trait(?Send) on wasm and the uniffi-wasm export pattern on FlamingoMatcher - keep the module's unit tests native-only - add --locked to the WASM CI checks to protect the git pins
bc85fd2 to
627eabe
Compare
eb042f4 to
c86167e
Compare
| } | ||
|
|
||
| #[cfg(test)] | ||
| #[cfg(all(test, not(target_arch = "wasm32")))] |
Re-pin the flamingo-verifier-* crates to worldcoin/flamingo#116's branch head and pontifex to worldcoin/pontifex#47's merged rev.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
HTTPS enforcement and focused WASM/browser runtime coverage are unresolved; the unused Pontifex workspace entry also needs cleanup.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
| #[cfg_attr(feature = "uniffi-wasm", uniffi::export)] | ||
| #[cfg_attr(not(feature = "uniffi-wasm"), uniffi::export(async_runtime = "tokio"))] |
|
closing for now - WASM/Browser env will need a very different setup for authorizing operations |


Summary
Makes attested Flamingo matching callable from browsers through the UniFFI exports only:
walletkit-core::flamingonow compiles onwasm32-unknown-unknownand is exported via this stack's ubrn pipeline (crates/walletkit -> web/walletkit npm packagewalletkit-web). The uniffi surface (FlamingoMatcher,FlamingoMatchRequest,FlamingoMatchOutcome,FlamingoMatchRejection,FlamingoError,VerifiedMatchToken) is unchanged and remains the API layer.This supersedes #548's approach for the stack: the
wasm-bindgencrate (crates/walletkit-web) and the standalone worker fixture (web/client/worker + Playwright) were dropped deliberately. Exposing Flamingo through web/walletkit's hand-written TS client (protocol.ts/walletkit.worker.ts/index.ts) is a follow-up.Changes
flamingo-verifier-{api-types,client,protocol,sealed-types}->git = "https://github.com/worldcoin/flamingo", rev = "00bdb03bad1229a875ebc6772baff1f18e5b6629"(head of feat: support the attested verifier client in browser WASM flamingo#116, the browser-compat 0.4.0 line)pontifex->rev = "51d3b1171d8f9d6c915ce1a6ff537058e3292072"(fix: support attestation and channels in browser WASM pontifex#47's merged browser fix; the rev flamingo#116 pins itself)flamingo-verifier-* 0.4.0/pontifex 2.0.0are not browser-safe at runtime: pontifex 2.0.0 callsstd::time::SystemTime::now(), which panics in browsers.walletkit-core::flamingofor wasm32;#[cfg_attr(target_arch = "wasm32", async_trait(?Send))]on the internalMatchClienttrait/impls; theuniffi-wasmexport pattern onFlamingoMatcher::perform_match(matchingauthenticator); module unit tests gated native-only.required-git-spec = "rev"plusallow-gitentries for the flamingo/pontifex sources (sources check stays green).--lockedadded to the existing WASM check/test commands to protect the git pins. No new jobs or web-package steps.Validation (local, rust 1.98.1)
cargo deny check advisories✅ (previously the only failing job, run 35728811406)cargo deny check bans licenses sources✅cargo metadata --locked✅cargo check -p walletkit-core --no-default-features --locked✅cargo check -p walletkit-core --no-default-features --features uniffi-wasm --locked --target wasm32-unknown-unknown✅cargo check -p walletkit --features embed-zkeys --locked --target wasm32-unknown-unknown✅cargo check -p walletkit --no-default-features --features embed-zkeys --locked --target wasm32-unknown-unknown✅cargo fmt --all -- --check✅Follow-ups / risks
00bdb03); move to a merged rev/tag once chore: bump uniffi to 0.30 #116 lands.embed-zkeys/tests requirenargo; covered by CI rather than this validation run.Note
Medium Risk
Introduces browser-callable attested matching and pins security-sensitive verifier code to git SHAs until upstream browser fixes ship on crates.io.
Overview
Enables
walletkit-core::flamingoonwasm32so attested Flamingo matching can be exported through the existing UniFFI stack (sameuniffi-wasmvstokioexport split asauthenticator). The module is no longer gated off on wasm;MatchClientusesasync_trait(?Send)on wasm, and Flamingo unit tests run only on native targets.Replaces crates.io
flamingo-verifier-*andpontifexwith git rev pins that avoid browser panics fromstd::time::SystemTime::now()in publishedpontifex2.0.0.walletkit-corenow pulls the verifier crates (andasync-trait) for all targets, not only native.Cargo.lockreflects the new sources;deny.tomlrequiresrevon git deps and allowlists the Worldcoin flamingo/pontifex repos.CI adds
--lockedto the existing WASMcargo check/cargo teststeps so those pins cannot drift in CI.Reviewed by Cursor Bugbot for commit 775c67c. Bugbot is set up for automated code reviews on this repo. Configure here.