A community based topic aggregation platform built on atproto

feat(middleware): integrate DPoP verification into auth middleware master

Enhance AtProtoAuthMiddleware with DPoP token binding support: - Add Stop() method to prevent goroutine leaks on shutdown - Require DPoP proof when token has cnf.jkt claim - Treat DPoP-bound tokens without proof as unauthenticated in OptionalAuth - Honor X-Forwarded-Proto header for URI verification behind proxies Security model: - DPoP is ADDITIONAL security, never a fallback for failed verification - Token signature must be verified BEFORE checking DPoP binding - Missing DPoP proof for bound tokens results in rejection Tests added for: - Middleware Stop() cleanup - OptionalAuth with DPoP-bound tokens - X-Forwarded-Proto handling - DPoP replay protection integration 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>


+564 -6
2 changed files