Skip to main content

Module identity

Module identity 

Source
Expand description

atproto identity resolution: handle → DID → DID document → PDS.

The security property that matters here is bidirectional verification. The atproto spec makes it mandatory: “If starting with a handle, it is critical (mandatory) to bidirectionally verify the handle by checking that the DID document claims the handle.” A handle is a DNS name someone else controls; without the back-check, whoever controls victim.example can point it at any DID they like.

The comparison is deliberately narrow — equality against the first at:// entry in alsoKnownAs, not membership in the array. A “is the handle anywhere in the list” check reintroduces the attack, because an attacker’s own DID document can list the victim’s handle as a secondary entry.

Functions§

declared_handle
The handle a DID document claims, normalized.
did_document_url
Where a DID’s document lives.
did_from_txt_records
Extract the DID from a handle’s _atproto TXT records.
did_from_well_known
Extract the DID from a /.well-known/atproto-did body: first line, trimmed.
is_atproto_did
Whether did is a DID this client can resolve: did:plc: or did:web:.
join_txt_chunks
Join one TXT record’s character-strings into its value.
normalize_handle
Normalize and validate a handle: lowercase, then check it against the handle grammar and the reserved-TLD list.
pds_endpoint
The PDS endpoint from a DID document.
validate_did_document
Validate a DID document against the DID that was requested.
verify_handle_claim
Bidirectional verification: does this DID document claim handle?