docs: Internet Identity spec reference#91
Conversation
Review: Internet Identity SpecificationMust fix
Suggestions
Verified
|
- Fix canister signature description: store empty blob at path ["sig", SHA-256(seed), SHA-256(payload)], not store SHA-256(payload) at a path encoding the seed (per IC interface spec line 418) - Fix verification step: clarify witness tree checks the path ["sig", SHA-256(seed), SHA-256(payload)] with matching hash - Replace "hostname" with "frontend origin (scheme + host + port)" in client auth protocol section — full origin is the derivation input - Use "OpenID Connect (OIDC)" consistently in heading and body - Soften Ed25519 hardware key claim: most FIDO2 keys use ECDSA P-256 - Add initialization comment to alternative origins code snippet
|
<!-- feedback-addressed --> Feedback addressed: PR #91 — Internet Identity SpecificationChanges appliedMust fix (both addressed):
Suggestions (all applied):
Items skippedNone — all feedback items were factually correct and improve the page. Build statusThe |
Summary
Sync recommendation
informed by dfinity/portal — docs/building-apps/authentication/internet-identity/; dfinity/icskills — skills/internet-identity/SKILL.md