From 587ebbba9e54a76ba323dfe594df80dff8635c7f Mon Sep 17 00:00:00 2001 From: Guido Jansen Date: Fri, 25 Sep 2026 14:23:12 +0200 Subject: [PATCH] fix(auth): resolve handles via the public AppView, not the entryway The bsky.social entryway keeps a stale handle -> DID mapping for months after a handle moves to another account. anders.sorby.xyz still resolved to its previous account there, so the OAuth client's bi-directional handle check rejected the sign-in (issue #5). public.api.bsky.app resolves it correctly and matches the entryway for all current members. --- src/lib/oauth.ts | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/lib/oauth.ts b/src/lib/oauth.ts index c8e729c..72d3eb3 100644 --- a/src/lib/oauth.ts +++ b/src/lib/oauth.ts @@ -4,7 +4,10 @@ import { BrowserOAuthClient } from '@atproto/oauth-client-browser'; import { OAUTH_SCOPE } from './oauth-scope'; -const HANDLE_RESOLVER = 'https://bsky.social'; +// The public AppView, not the bsky.social entryway: the entryway caches handle -> DID for months +// after a handle moves to another account (seen 2026-09-25: anders.sorby.xyz still resolved to its +// previous account there), and the OAuth client's bi-directional check then rejects the sign-in. +const HANDLE_RESOLVER = 'https://public.api.bsky.app'; export async function createOAuthClient(): Promise { const origin = window.location.origin; -- 2.51.2