You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(internet-identity): SSO sign-in and the SSO domain status on auth 11 - #415
Brings the internet-identity skill in line with the Internet Identity guides in the developer docs and with @icp-sdk/auth 11.
Organization SSO: constructor-only ssoDomain (mutually exclusive with openIdProvider), the domain check as client state (getSsoStatus() with subscribe(), refreshSsoStatus() to retry, dispose() for a replaced client), signIn() rejecting only for an invalid domain, and sso: scoped keys. New pitfalls: no browser-side domain check, no awaiting the check before signIn(), and options being constructor-only.
Corrections: verified_email is present when an OpenID provider marked the address verified or the user verified it with Internet Identity, and never under sso:; mo:identity-attributes reads SSO email from sso:<domain>:email.
Less duplication: the shared-sessions walkthrough, the full app-metadata rules, the organization's SSO setup, the Rust attributes backend and the older-API notes are replaced by links to the developer-docs guides and the @icp-sdk/auth upgrade guides. SKILL.md goes from 768 to 391 lines.
Versions: pins @icp-sdk/auth@^11 with @icp-sdk/core@^6.
Evals: three SSO cases added and the changed cases re-run with and without the skill (SSO check while typing 6/6 vs 1/6, awaiting the check 3/3 vs 2/3, verified_email under sso: 4/4 vs 2/4, local II without agentOptions 5/5 vs 3/5, version pairing 4/4 vs 3/4); trigger evals 9/9 and 6/6. node scripts/check-project.js passes.
…h 11
Adds organization SSO: constructor-only `ssoDomain`, the domain check as
client state (`getSsoStatus()` with `subscribe()`, `refreshSsoStatus()` to
retry), `signIn()` rejecting only for an invalid domain, and `sso:` scoped
keys. Corrects `verified_email` (an OpenID provider's verification or one the
user completed with II, never under `sso:`) and the `mo:identity-attributes`
mapping for SSO sources.
SKILL.md moves under the 500-line limit: the shared-sessions walkthrough, the
app-metadata rules, the Rust attributes backend, the older-API notes, and the
organization's SSO setup move to `references/`. Pins `@icp-sdk/auth@^11` with
`@icp-sdk/core@^6`; evals updated and three SSO cases added.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The shared-sessions walkthrough, app-metadata rules, organization SSO setup,
Rust attributes backend and older-API notes live in the developer docs and
the @icp-sdk/auth upgrade guides; the skill links to them.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Add eval coverage for constructor-only SSO domain changes
skills/internet-identity/SKILL.md:93
This newly added constructor-only pitfall has no output eval, although the other two new SSO pitfalls do. Add a focused case that rejects attempts to change ssoDomain or pass it to signIn(), and requires disposing and replacing the client; otherwise this explicit regression target is unprotected.
This issue also appears on line 224 of the same file.
Update outdated Vite target default claim
skills/internet-identity/SKILL.md:47
This Vite default is outdated: skills/wallet-integration/SKILL.md:430 records that only Vite 5 and earlier defaulted to es2020, while Vite 6+ uses baseline-widely-available and allows top-level await. Keep the portable init() recommendation, but version the claim so current users are not given an incorrect explanation.
This issue also appears on line 157 of the same file.
Remove unnecessary second local principal instruction
skills/internet-identity/SKILL.md:350
This instruction contradicts lines 39 and 108, which state that the local II uses the same well-known backend principal. For the ii: true setup documented here, adding another local principal is unnecessary and implies readers need to discover a second ID.
Restores the reference files and brings them to the current state: the
Rust backend from the developer docs (bounded nonces, ic-cdk-management-canister),
one client per page in shared sessions, a domain without a port, and no
asset canister setup.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings the
internet-identityskill in line with the Internet Identity guides in the developer docs and with@icp-sdk/auth11.ssoDomain(mutually exclusive withopenIdProvider), the domain check as client state (getSsoStatus()withsubscribe(),refreshSsoStatus()to retry,dispose()for a replaced client),signIn()rejecting only for aninvaliddomain, andsso:scoped keys. New pitfalls: no browser-side domain check, no awaiting the check beforesignIn(), and options being constructor-only.verified_emailis present when an OpenID provider marked the address verified or the user verified it with Internet Identity, and never undersso:;mo:identity-attributesreads SSO email fromsso:<domain>:email.@icp-sdk/authupgrade guides.SKILL.mdgoes from 768 to 391 lines.@icp-sdk/auth@^11with@icp-sdk/core@^6.Describes dfinity/developer-docs#340, dfinity/icp-js-auth#203 and dfinity/internet-identity#4421.
Evals: three SSO cases added and the changed cases re-run with and without the skill (SSO check while typing 6/6 vs 1/6, awaiting the check 3/3 vs 2/3,
verified_emailundersso:4/4 vs 2/4, local II withoutagentOptions5/5 vs 3/5, version pairing 4/4 vs 3/4); trigger evals 9/9 and 6/6.node scripts/check-project.jspasses.🤖 Generated with Claude Code