Skip to content

feat(internet-identity): SSO sign-in and the SSO domain status on auth 11 - #415

Open
sea-snake wants to merge 13 commits into
mainfrom
docs/internet-identity-sso
Open

sea-snake wants to merge 13 commits into
mainfrom
docs/internet-identity-sso

Conversation

@sea-snake

Copy link
Copy Markdown
Contributor

Brings the internet-identity skill in line with the Internet Identity guides in the developer docs and with @icp-sdk/auth 11.

  • Organization SSO: constructor-only ssoDomain (mutually exclusive with openIdProvider), the domain check as client state (getSsoStatus() with subscribe(), refreshSsoStatus() to retry, dispose() for a replaced client), signIn() rejecting only for an invalid domain, and sso: scoped keys. New pitfalls: no browser-side domain check, no awaiting the check before signIn(), and options being constructor-only.
  • Corrections: verified_email is present when an OpenID provider marked the address verified or the user verified it with Internet Identity, and never under sso:; mo:identity-attributes reads SSO email from sso:<domain>:email.
  • Less duplication: the shared-sessions walkthrough, the full app-metadata rules, the organization's SSO setup, the Rust attributes backend and the older-API notes are replaced by links to the developer-docs guides and the @icp-sdk/auth upgrade guides. SKILL.md goes from 768 to 391 lines.
  • Versions: pins @icp-sdk/auth@^11 with @icp-sdk/core@^6.

Describes dfinity/developer-docs#340, dfinity/icp-js-auth#203 and dfinity/internet-identity#4421.

Evals: three SSO cases added and the changed cases re-run with and without the skill (SSO check while typing 6/6 vs 1/6, awaiting the check 3/3 vs 2/3, verified_email under sso: 4/4 vs 2/4, local II without agentOptions 5/5 vs 3/5, version pairing 4/4 vs 3/4); trigger evals 9/9 and 6/6. node scripts/check-project.js passes.

🤖 Generated with Claude Code

sea-snake and others added 3 commits October 7, 2026 11:38
…h 11

Adds organization SSO: constructor-only `ssoDomain`, the domain check as
client state (`getSsoStatus()` with `subscribe()`, `refreshSsoStatus()` to
retry), `signIn()` rejecting only for an invalid domain, and `sso:` scoped
keys. Corrects `verified_email` (an OpenID provider's verification or one the
user completed with II, never under `sso:`) and the `mo:identity-attributes`
mapping for SSO sources.

SKILL.md moves under the 500-line limit: the shared-sessions walkthrough, the
app-metadata rules, the Rust attributes backend, the older-API notes, and the
organization's SSO setup move to `references/`. Pins `@icp-sdk/auth@^11` with
`@icp-sdk/core@^6`; evals updated and three SSO cases added.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… asks

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The shared-sessions walkthrough, app-metadata rules, organization SSO setup,
Rust attributes backend and older-API notes live in the developer docs and
the @icp-sdk/auth upgrade guides; the skill links to them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sea-snake
sea-snake requested a balanced review from Copilot October 7, 2026 09:49
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Skill Validation Report

Validating skill: /home/runner/work/icskills/icskills/skills/internet-identity

Structure

  • Pass: SKILL.md found
  • Pass: all files in references/ are referenced

Frontmatter

  • Pass: name: "internet-identity" (valid)
  • Pass: description: (609 chars)
  • Pass: license: "Apache-2.0"
  • Pass: compatibility: (45 chars)
  • Pass: metadata: (2 entries)

Tokens

  • Warning: SKILL.md body is 6090 tokens (spec recommends < 5000)

Markdown

  • Pass: no unclosed code fences found

Tokens

File Tokens
SKILL.md body 6,090
references/app-metadata.md 1,030
references/enterprise-sso.md 1,218
references/older-api.md 753
references/rust-identity-attributes.md 884
references/shared-sessions.md 1,204
Total 11,179

Content Analysis

Metric Value
Word count 3,331
Code block ratio 0.22
Imperative ratio 0.07
Information density 0.14
Instruction specificity 0.88
Sections 15
List items 40
Code blocks 14

References Content Analysis

Metric Value
Word count 3,005
Code block ratio 0.11
Imperative ratio 0.01
Information density 0.06
Instruction specificity 0.89
Sections 19
List items 38
Code blocks 13

Contamination Analysis

Metric Value
Contamination level low
Contamination score 0.11
Primary language category javascript
Scope breadth 3
  • Warning: Language mismatch: config (1 category differ from primary)

References Contamination Analysis

Metric Value
Contamination level high
Contamination score 0.60
Primary language category config
Scope breadth 5
  • Warning: Language mismatch: javascript, shell, systems (3 categories differ from primary)
  • Multi-interface tool detected: aws

Result: 1 warning

Project Checks


✓ Project checks passed for 1 skills (0 warnings)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several examples can produce unhandled rejections or fail locally, and related evaluation expectations need correction.

Review effort: Balanced
Findings: 5 Medium severity

Open (5)
What changed in this PR

Updates the Internet Identity skill for @icp-sdk/auth 11, including organization SSO and revised identity-attribute guidance.

Changes:

  • Documents SSO domain checking, lifecycle, and sign-in behavior.
  • Updates versions, attribute semantics, and related evaluations.
  • Replaces duplicated walkthroughs with developer-guide links.
File Description
skills/​internet-identity/​SKILL.md Updates and condenses Internet Identity guidance.
evaluations/​internet-identity.json Adds SSO cases and updates version expectations.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread evaluations/internet-identity.json Outdated
Comment thread skills/internet-identity/SKILL.md Outdated
Comment thread skills/internet-identity/SKILL.md Outdated
Comment thread skills/internet-identity/SKILL.md Outdated
Comment thread skills/internet-identity/SKILL.md Outdated
… key

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It contains outdated Vite guidance, contradictory local-II documentation, and uncovered SSO behaviors.

Review effort: Balanced
Findings: None

Resolved since last review (5)
Previously missed (3)

In code that hasn't changed since last review

Medium severity Add eval coverage for constructor-only SSO domain changes

skills/​internet-identity/​SKILL.md:93

This newly added constructor-only pitfall has no output eval, although the other two new SSO pitfalls do. Add a focused case that rejects attempts to change ssoDomain or pass it to signIn(), and requires disposing and replacing the client; otherwise this explicit regression target is unprotected.

This issue also appears on line 224 of the same file.

Low severity Update outdated Vite target default claim

skills/​internet-identity/​SKILL.md:47

This Vite default is outdated: skills/wallet-integration/SKILL.md:430 records that only Vite 5 and earlier defaulted to es2020, while Vite 6+ uses baseline-widely-available and allows top-level await. Keep the portable init() recommendation, but version the claim so current users are not given an incorrect explanation.

This issue also appears on line 157 of the same file.

Low severity Remove unnecessary second local principal instruction

skills/​internet-identity/​SKILL.md:350

This instruction contradicts lines 39 and 108, which state that the local II uses the same well-known backend principal. For the ii: true setup documented here, adding another local principal is unnecessary and implies readers need to discover a second ID.

…tProfile, and cover constructor-only ssoDomain

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sea-snake

Copy link
Copy Markdown
Contributor Author

On the three items Copilot lists under "previously missed", all fixed in a4fcab4:

  • Constructor-only ssoDomain had no output eval: added "Adversarial: switching an existing client to another SSO domain".
  • The Vite default: the skill now says Vite 6 and earlier reject top-level await by default and Vite 7 allows it, and keeps the init() recommendation.
  • The local II principal: the trusted_attribute_signers comment now says a local II (ii: true) has the same principal.

The same commit also makes the Motoko getProfile example read caller from the call instead of taking a principal argument.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation and evaluations are consistent, focused, and syntactically valid.

Review effort: Balanced
Findings: None

sea-snake and others added 8 commits October 7, 2026 13:42
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Restores the reference files and brings them to the current state: the
Rust backend from the developer docs (bounded nonces, ic-cdk-management-canister),
one client per page in shared sessions, a domain without a port, and no
asset canister setup.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…st backend, and keep the profile lookup public

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sea-snake
sea-snake marked this pull request as ready for review October 7, 2026 13:59
@sea-snake
sea-snake requested review from a team and JoshDFN as code owners October 7, 2026 13:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants