Vendored on purpose (~60 lines) instead of pulled as a dependency: this function decides the
exact bytes that get signed, so it must be trivially auditable. It must produce the same output
as serde_jcs on the Rust side — the conformance vectors (engines#591) are the guard.
RFC 8785 in short: object keys sorted by UTF-16 code units, no whitespace, strings escaped as
ECMAScript JSON.stringify, numbers serialized as ECMAScript (shortest round-trip form).
JSON.stringify already implements the string/number rules; what it does not do is sort keys.
JSON Canonicalization Scheme (RFC 8785) serializer.
Vendored on purpose (~60 lines) instead of pulled as a dependency: this function decides the exact bytes that get signed, so it must be trivially auditable. It must produce the same output as
serde_jcson the Rust side — the conformance vectors (engines#591) are the guard.RFC 8785 in short: object keys sorted by UTF-16 code units, no whitespace, strings escaped as ECMAScript
JSON.stringify, numbers serialized as ECMAScript (shortest round-trip form).JSON.stringifyalready implements the string/number rules; what it does not do is sort keys.