Skip to content

docs(world-id): fix audit findings across IDKit, credentials, sandbox, and technical reference - #197

Open
soamdesai-tfh wants to merge 8 commits into
mainfrom
docs-audit/world-id-content-fixes
Open

soamdesai-tfh wants to merge 8 commits into
mainfrom
docs-audit/world-id-content-fixes

Conversation

@soamdesai-tfh

@soamdesai-tfh soamdesai-tfh commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Fix World ID docs.

  • idkit/integrate.mdx: note Kotlin's GitHub Packages requirement; document the sandbox environment and .constraints() (JS/React; passport and MNC combine with any, never all).
  • idkit/error-codes.mdx: add the missing feature_unavailable code; scope the cross-SDK parity claim.
  • idkit/javascript.mdx: document .constraints() and all 3 environment values; include the required allow_legacy_proofs flag and keep Passport/MNC as alternatives.
  • idkit/session-proofs.mdx, idkit/credentials.mdx, idkit/mini-apps.mdx, and world-id/SKILL.md: use constraints for session requests and update React session guidance. These pre-existing session-example defects are addressed in a separate commit.
  • sandbox/sandbox-access.mdx: fix the Sandbox Support email domain.
  • from-idkit-standalone.mdx: reframe legacy presets as a compatibility step, not the end state; keep all document users with any(proof_of_human, passport, mnc).
  • credentials/9303.mdx: correct — My Number Card has its own schema (9310) but still counts as the user's one NFC credential, so request it as an alternative to passport/eID.
  • reference/contracts.mdx: fix the wrong @ethers/utils import, the copy-pasted nullifierHash description, the Testnet column, and the "only groupId 1" claim.
  • reference/authenticator.mdx: fix the requests→proof_requests wire key, add missing oprf_key_id/expires_at_min fields, fix malformed example signatures.
  • reference/poh-issuer.mdx: correct the claim commitment count (15, not 16); rename associated_data_hash→associated_data_commitment; add issuer_version.
  • idkit/credentials.mdx: document the missing mnc preset and which presets override allow_legacy_proofs.
  • idkit/react.mdx: add missing hook fields (isOpen, isInWorldApp); document constraints.
  • sandbox/testing-selfie-check.mdx: remove a reference to a "Warm" flow that doesn't exist.
  • credentials/1.mdx: rename associated_data_hash→associated_data_commitment.
  • idkit/signatures.mdx: document computeRpSignatureMessage and getSessionCommitment.
  • 4-0-migration.mdx: fix 2 mislabeled Solidity code fences.

Skipped 3 findings that point at live remote OpenAPI content or facts not in evidence.

…box, and technical reference

- world-id/idkit/integrate.mdx: note Kotlin's GitHub Packages install requirement, sandbox environment value, sandbox testing cross-link, and advanced constraints() finalizer
- world-id/idkit/error-codes.mdx: add missing feature_unavailable code, scope the JS/Kotlin/Swift parity claim to its two real exceptions
- world-id/idkit/javascript.mdx: document constraints()/CredentialRequest/any/all as an alternative to preset(), and the sandbox environment value
- world-id/sandbox/sandbox-access.mdx: fix Sandbox Support email domain (.org -> .com)
- world-id/from-idkit-standalone.mdx: frame legacy presets as compatibility-only and point migrators to v4-native proofOfHuman/passport presets
- world-id/credentials/9303.mdx: correct MNC to be its own credential (schema id 9310), not "the same credential" as the NFC/passport credential (9303)
- world-id/reference/contracts.mdx: clarify additional on-chain groups are not RP-facing, fix ethers.js import path, fix nullifierHash row (was copy-pasted from root), reconcile Supported Chains testnet column with onchain-verification.mdx
- world-id/reference/authenticator.mdx: rename requests -> proof_requests wire key, add required oprf_key_id and expires_at_min fields, replace placeholder signature with a valid r||s||v hex format
- world-id/reference/poh-issuer.mdx: fix claims cap (15, not 16) and rename associated_data_hash -> associated_data_commitment, add issuer_version field
- world-id/idkit/credentials.mdx: document the mnc preset alongside proofOfHuman/passport
- world-id/idkit/react.mdx: document isOpen/isInWorldApp hook result fields and constraints as a preset alternative
- world-id/idkit/signatures.mdx: document computeRpSignatureMessage and getSessionCommitment exports
- world-id/credentials/1.mdx: rename associated_data_hash -> associated_data_commitment to match the real Credential struct
- world-id/sandbox/testing-selfie-check.mdx: stop citing verification-flows.mdx for a "Warm" flow it doesn't define
- world-id/4-0-migration.mdx: fix Solidity code fences mislabeled as jsx/ts
@mintlify

mintlify Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
world 🟢 Ready View Preview Sep 23, 2026, 10:06 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@soamdesai-tfh

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T04:12:36.148566Z a5903d0 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a5903d0b65

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread world-id/from-idkit-standalone.mdx Outdated
Style pass on the earlier audit commit: cut redundant clauses,
self-explanatory asides, and repeated phrasing across the World ID
docs it touched, tightening sentences to the surrounding terse
Mintlify style without changing any technical content.
@soamdesai-tfh

Copy link
Copy Markdown
Contributor Author

Style pass on the 9 prose-heavy files from the audit commit: tightened sentences to match the surrounding docs' terse Mintlify style (cut redundant clauses, repeated phrasing, and self-explanatory asides). No technical content, values, or warnings changed — cspell spot-check on all touched files passes clean.

# Conflicts:
#	world-id/idkit/credentials.mdx
Addresses a Codex review comment on PR #197: the note only listed
proofOfHuman/passport as the v4 migration target, which would leave
standalone document-level (MNC) users without a documented preset to
migrate to, even though v4 exposes mnc as its own preset distinct from
passport.
- integrate: constraints example is Proof of Human AND (Passport OR MNC),
  scoped to JS/React; passport and MNC are alternatives (any, never all)
- error-codes: feature_unavailable is JS/React only until the next Kotlin
  and Swift releases; fix its remedy
- 9303: MNC has its own schema (9310) but counts as the user's one NFC
  credential; drop my-number-card; name the IDKit credential types
- from-idkit-standalone: keep all document users with
  any(proof_of_human, passport, mnc); note v4 presets always keep 3.0
  fallback, so dropping 3.0 needs constraints + allow_legacy_proofs: false
- contracts: only groupId 1 is supported for RPs; IDKit 4.x v3 responses
  use nullifier
- authenticator: examples parse with world-id-primitives 0.14.1 (numeric
  timestamps, 0x-hex signals, canonical proof/nullifiers, session_id)
- javascript/react/poh-issuer: add mnc and session entry points, missing
  invite-code hook fields, uint8, claims slot wording
- integrate/javascript: sandbox build of World ID; Maven Central comment
- credentials: proofOfHuman, passport, mnc and identityCheck always accept
  World ID 3.0 fallback and selfieCheck never does, whatever
  allow_legacy_proofs says (idkit preset.rs allow_legacy_proofs_override),
  so the options table matches the migration note

This branch was successfully deployed

1 active deployment
staging — 9bcc7fb3 Deployed Sep 23, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant