diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 72ec3483..60876757 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -112,7 +112,7 @@ jobs: llvm-ar-18 --version | head -n1 - name: Run WASM compile check - run: cargo check -p walletkit --features embed-zkeys --target wasm32-unknown-unknown + run: cargo check -p walletkit --features embed-zkeys --locked --target wasm32-unknown-unknown # Keep this version aligned with the wasm-bindgen version in Cargo.lock. - name: Install WASM browser test runner @@ -121,7 +121,7 @@ jobs: - name: Test walletkit-sqlite in a browser runner run: | CHROMEDRIVER="$CHROMEWEBDRIVER/chromedriver" \ - cargo test -p walletkit-sqlite --target wasm32-unknown-unknown + cargo test -p walletkit-sqlite --locked --target wasm32-unknown-unknown swift-build: name: Build Swift diff --git a/Cargo.lock b/Cargo.lock index 78d07532..558faef5 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -3275,8 +3275,7 @@ checksum = "b7ac824320a75a52197e8f2d787f6a38b6718bb6897a35142d749af3c0e8f4fe" [[package]] name = "flamingo-verifier-api-types" version = "0.4.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "753c3bb33c6957e7d83ad9f7bffb36f72e75fd65005fd54813ea085dd439b092" +source = "git+https://github.com/worldcoin/flamingo?rev=00bdb03bad1229a875ebc6772baff1f18e5b6629#00bdb03bad1229a875ebc6772baff1f18e5b6629" dependencies = [ "serde", ] @@ -3284,13 +3283,14 @@ dependencies = [ [[package]] name = "flamingo-verifier-client" version = "0.4.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "eb4a5c25a10e733f19a507ced5270b7fcab66f6d7a2b47e6391bd4472ad17066" +source = "git+https://github.com/worldcoin/flamingo?rev=00bdb03bad1229a875ebc6772baff1f18e5b6629#00bdb03bad1229a875ebc6772baff1f18e5b6629" dependencies = [ "base64 0.22.1", "flamingo-verifier-api-types", "flamingo-verifier-protocol", "flamingo-verifier-sealed-types", + "futures-util", + "getrandom 0.2.17", "hex", "pontifex", "reqwest 0.12.28", @@ -3303,8 +3303,7 @@ dependencies = [ [[package]] name = "flamingo-verifier-protocol" version = "0.4.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b39b0c2d481a09ce3047a0adda53bfda3372422510bdb4f2a4c11fb0738aa5b9" +source = "git+https://github.com/worldcoin/flamingo?rev=00bdb03bad1229a875ebc6772baff1f18e5b6629#00bdb03bad1229a875ebc6772baff1f18e5b6629" dependencies = [ "ark-ff 0.5.0", "coset", @@ -3318,8 +3317,7 @@ dependencies = [ [[package]] name = "flamingo-verifier-sealed-types" version = "0.4.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5f9a69d2013a4be260d5abb9c619b064fa7bd349e250d3127f22213f8b72d8fd" +source = "git+https://github.com/worldcoin/flamingo?rev=00bdb03bad1229a875ebc6772baff1f18e5b6629#00bdb03bad1229a875ebc6772baff1f18e5b6629" dependencies = [ "ciborium", "flamingo-verifier-api-types", @@ -5519,12 +5517,12 @@ dependencies = [ [[package]] name = "pontifex" version = "2.0.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1f05f626f4b534d7891a41b0a0ffc47e8e7eafa40c63f4dbacfa9b2828527195" +source = "git+https://github.com/worldcoin/pontifex?rev=51d3b1171d8f9d6c915ce1a6ff537058e3292072#51d3b1171d8f9d6c915ce1a6ff537058e3292072" dependencies = [ "ciborium", "const-fnv1a-hash", "coset", + "getrandom 0.2.17", "p384", "quantum-box", "serde", @@ -5533,6 +5531,7 @@ dependencies = [ "thiserror 2.0.18", "tokio", "tracing", + "web-time", "webpki", "x509-cert", "zeroize", diff --git a/Cargo.toml b/Cargo.toml index 0c6eaad2..47fa917f 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -41,10 +41,17 @@ clap = "4" ctor = "0.2" dirs = "6" dotenvy = "0.15.7" -flamingo-verifier-api-types = "0.4.0" -flamingo-verifier-client = "0.4.0" -flamingo-verifier-protocol = "0.4.0" -flamingo-verifier-sealed-types = "0.4.0" +# crates.io `flamingo-verifier-*` 0.4.0 and `pontifex` 2.0.0 are not browser-safe: +# pontifex 2.0.0 calls `std::time::SystemTime::now()`, which panics in browsers. +# Pin the browser-compatible 0.4 line at worldcoin/flamingo#116's branch head and +# the merged browser-compat `pontifex` rev (worldcoin/pontifex#47), both in lockstep +# with flamingo's own manifests. Move to a merged rev/tag once flamingo#116 lands. +flamingo-verifier-api-types = { version = "0.4.0", git = "https://github.com/worldcoin/flamingo", rev = "00bdb03bad1229a875ebc6772baff1f18e5b6629" } +flamingo-verifier-client = { version = "0.4.0", git = "https://github.com/worldcoin/flamingo", rev = "00bdb03bad1229a875ebc6772baff1f18e5b6629" } +flamingo-verifier-protocol = { version = "0.4.0", git = "https://github.com/worldcoin/flamingo", rev = "00bdb03bad1229a875ebc6772baff1f18e5b6629" } +flamingo-verifier-sealed-types = { version = "0.4.0", git = "https://github.com/worldcoin/flamingo", rev = "00bdb03bad1229a875ebc6772baff1f18e5b6629" } +# Merged browser-compat rev (worldcoin/pontifex#47), pinned in lockstep with flamingo's own manifests. +pontifex = { version = "2.0.0", git = "https://github.com/worldcoin/pontifex", rev = "51d3b1171d8f9d6c915ce1a6ff537058e3292072" } eyre = "0.6" getrandom = "0.3" hex = "0.4" diff --git a/crates/walletkit-core/Cargo.toml b/crates/walletkit-core/Cargo.toml index 952d8418..4153d5df 100644 --- a/crates/walletkit-core/Cargo.toml +++ b/crates/walletkit-core/Cargo.toml @@ -22,9 +22,14 @@ name = "walletkit_core" [dependencies] alloy-core = { workspace = true } +async-trait = { workspace = true } backon = { workspace = true } base64 = { workspace = true } ciborium = { workspace = true } +flamingo-verifier-api-types = { workspace = true } +flamingo-verifier-client = { workspace = true } +flamingo-verifier-protocol = { workspace = true } +flamingo-verifier-sealed-types = { workspace = true } hex = { workspace = true } hkdf = { workspace = true } log = { workspace = true } @@ -57,12 +62,7 @@ getrandom = { workspace = true, features = ["wasm_js"] } # Native-only dependencies (not available on wasm32) [target.'cfg(not(target_arch = "wasm32"))'.dependencies] -async-trait = { workspace = true } ctor = { workspace = true } -flamingo-verifier-api-types = { workspace = true } -flamingo-verifier-client = { workspace = true } -flamingo-verifier-protocol = { workspace = true } -flamingo-verifier-sealed-types = { workspace = true } reqwest = { workspace = true, features = ["brotli", "rustls-tls"] } rustls = { workspace = true, features = ["ring"] } diff --git a/crates/walletkit-core/src/flamingo/mod.rs b/crates/walletkit-core/src/flamingo/mod.rs index e3ec701f..5239f9f2 100644 --- a/crates/walletkit-core/src/flamingo/mod.rs +++ b/crates/walletkit-core/src/flamingo/mod.rs @@ -40,7 +40,8 @@ pub struct FlamingoMatcher { client: OnceCell, } -#[async_trait] +#[cfg_attr(target_arch = "wasm32", async_trait(?Send))] +#[cfg_attr(not(target_arch = "wasm32"), async_trait)] trait MatchClient: Sync { type Assignment: Send + Sync; @@ -53,7 +54,8 @@ trait MatchClient: Sync { ) -> Result; } -#[uniffi::export(async_runtime = "tokio")] +#[cfg_attr(feature = "uniffi-wasm", uniffi::export)] +#[cfg_attr(not(feature = "uniffi-wasm"), uniffi::export(async_runtime = "tokio"))] impl FlamingoMatcher { /// Creates an instance with default values, use `with_measurements` and `with_headers` for customization. /// @@ -154,7 +156,8 @@ impl FlamingoMatcher { } } -#[async_trait] +#[cfg_attr(target_arch = "wasm32", async_trait(?Send))] +#[cfg_attr(not(target_arch = "wasm32"), async_trait)] impl MatchClient for FlamingoVerifierClient { type Assignment = VerifiedAssignment; @@ -258,7 +261,7 @@ fn verifier_error(error: &ClientError) -> FlamingoError { FlamingoError::Verifier(error.to_string()) } -#[cfg(test)] +#[cfg(all(test, not(target_arch = "wasm32")))] mod tests { use std::{ collections::{HashMap, VecDeque}, diff --git a/crates/walletkit-core/src/flamingo/types.rs b/crates/walletkit-core/src/flamingo/types.rs index b9a171ac..f5649ad1 100644 --- a/crates/walletkit-core/src/flamingo/types.rs +++ b/crates/walletkit-core/src/flamingo/types.rs @@ -243,7 +243,7 @@ impl From for VerifiedMatchToken { } } -#[cfg(test)] +#[cfg(all(test, not(target_arch = "wasm32")))] mod tests { use super::{FlamingoLiveCapture, FlamingoMatchRequest, MatchInputs}; diff --git a/crates/walletkit-core/src/lib.rs b/crates/walletkit-core/src/lib.rs index ea9d3998..40adf05c 100644 --- a/crates/walletkit-core/src/lib.rs +++ b/crates/walletkit-core/src/lib.rs @@ -103,7 +103,6 @@ pub enum Region { } /// Attested Flamingo matching in preparation for zero-knowledge proof generation. -#[cfg(not(target_arch = "wasm32"))] pub mod flamingo; /// Contains error outputs from `WalletKit` diff --git a/deny.toml b/deny.toml index a5a02e7b..2afdac8a 100644 --- a/deny.toml +++ b/deny.toml @@ -4,6 +4,12 @@ all-features = true [sources] unknown-registry = "deny" +# Git dependencies must pin an exact commit. +required-git-spec = "rev" +allow-git = [ + "https://github.com/worldcoin/flamingo", + "https://github.com/worldcoin/pontifex", +] [bans] deny = [