@hongminhee It's still an assumption that actor URL is a prefix of the key ID, but it works with the systems I'm seeing.
I haven't found any clear requirement about this in the AP specs.
I'm a little unhappy about parsing the message content before verifying the signature b/c it messes up the logical order of things, and because I'm not sure if it entails any security risk. (But I'm skeptical about the HTTPsig approach as a whole so it adds little extra doubt.)