Expand description
atproto identity resolution: handle → DID → DID document → PDS.
The security property that matters here is bidirectional verification.
The atproto spec makes it mandatory: “If starting with a handle, it is
critical (mandatory) to bidirectionally verify the handle by checking that
the DID document claims the handle.” A handle is a DNS name someone else
controls; without the back-check, whoever controls victim.example can point
it at any DID they like.
The comparison is deliberately narrow — equality against the first
at:// entry in alsoKnownAs, not membership in the array. A “is the handle
anywhere in the list” check reintroduces the attack, because an attacker’s
own DID document can list the victim’s handle as a secondary entry.
Functions§
- declared_
handle - The handle a DID document claims, normalized.
- did_
document_ url - Where a DID’s document lives.
- did_
from_ txt_ records - Extract the DID from a handle’s
_atprotoTXT records. - did_
from_ well_ known - Extract the DID from a
/.well-known/atproto-didbody: first line, trimmed. - is_
atproto_ did - Whether
didis a DID this client can resolve:did:plc:ordid:web:. - join_
txt_ chunks - Join one TXT record’s character-strings into its value.
- normalize_
handle - Normalize and validate a handle: lowercase, then check it against the handle grammar and the reserved-TLD list.
- pds_
endpoint - The PDS endpoint from a DID document.
- validate_
did_ document - Validate a DID document against the DID that was requested.
- verify_
handle_ claim - Bidirectional verification: does this DID document claim
handle?