From cc6c8349eb7eb4b3773382fac637dc8bf8de1894 Mon Sep 17 00:00:00 2001 From: JP Hastings-Spital Date: Sun, 31 May 2026 12:32:16 +0200 Subject: [PATCH] Rename lexicon NSID to me.byjp.deepsky.identity Reverse-DNS of the new deepsky.byjp.me domain. Changes the Collection constant (used for the record $type, repo reads, Jetstream filter and lightrail backfill) plus the doc/README references. The badge.blue signature $type is unrelated and unchanged. --- README.md | 4 ++-- identity_cmd.go | 2 +- internal/identity/fingerprint.go | 4 ++-- internal/identity/index/backfill.go | 2 +- internal/identity/index/ingest.go | 2 +- internal/identity/index/jetstream.go | 2 +- internal/identity/index/store.go | 2 +- internal/identity/record.go | 2 +- internal/identity/sign.go | 2 +- internal/render/render.go | 2 +- main.go | 2 +- 11 files changed, 13 insertions(+), 13 deletions(-) diff --git a/README.md b/README.md index 305af4e..7eb9c9e 100644 --- a/README.md +++ b/README.md @@ -119,8 +119,8 @@ client at `gemini://localhost/p/bsky.app`. Gemini authenticates clients with TLS **client certificates** — a stable but anonymous key. DeepSky can recognise the Bluesky account behind a certificate -via a custom lexicon, [`space.deepsky.identity`](internal/identity). A record at -`at:///space.deepsky.identity/` is a +via a custom lexicon, [`me.byjp.deepsky.identity`](internal/identity). A record at +`at:///me.byjp.deepsky.identity/` is a [badge.blue](https://badge.blue)-style signed statement that the holder of the certificate's private key is that account. diff --git a/identity_cmd.go b/identity_cmd.go index c65c43a..c4b2956 100644 --- a/identity_cmd.go +++ b/identity_cmd.go @@ -16,7 +16,7 @@ import ( "tangled.org/byjp.me/deepsky/internal/tlsx" ) -// runIdentity mints (and optionally publishes) a space.deepsky.identity record +// runIdentity mints (and optionally publishes) a me.byjp.deepsky.identity record // binding a Gemini client certificate to an atproto account. func runIdentity(args []string) { fs := flag.NewFlagSet("identity", flag.ExitOnError) diff --git a/internal/identity/fingerprint.go b/internal/identity/fingerprint.go index bb67072..0ccd61b 100644 --- a/internal/identity/fingerprint.go +++ b/internal/identity/fingerprint.go @@ -1,6 +1,6 @@ // Package identity binds a Gemini client TLS certificate to an atproto account. // -// A space.deepsky.identity record published in an account's repo is a signed +// A me.byjp.deepsky.identity record published in an account's repo is a signed // claim of the form "the holder of the private key whose certificate // fingerprint is is this account". The record key is the fingerprint, and // the record carries a badge.blue-style signature made by the certificate's @@ -23,7 +23,7 @@ import ( ) // Collection is the NSID of the binding record's lexicon. -const Collection = "space.deepsky.identity" +const Collection = "me.byjp.deepsky.identity" // b32 is RFC 4648 base32 without padding; we lowercase its output so the // fingerprint sits within the atproto record-key charset (a-z, 2-7). diff --git a/internal/identity/index/backfill.go b/internal/identity/index/backfill.go index 3bf7754..bb9166c 100644 --- a/internal/identity/index/backfill.go +++ b/internal/identity/index/backfill.go @@ -17,7 +17,7 @@ import ( // DefaultLightrail is microcosm's hosted backfill-by-collection service. const DefaultLightrail = "https://lightrail.microcosm.blue" -// Backfiller enumerates space.deepsky.identity records that already exist on the +// Backfiller enumerates me.byjp.deepsky.identity records that already exist on the // network, calling emit for each. emit performs verification + indexing. type Backfiller interface { Records(ctx context.Context, emit func(did, rkey string, value json.RawMessage)) error diff --git a/internal/identity/index/ingest.go b/internal/identity/index/ingest.go index de7762f..175b48e 100644 --- a/internal/identity/index/ingest.go +++ b/internal/identity/index/ingest.go @@ -12,7 +12,7 @@ import ( // the record is signed with — the binding is malformed and must be rejected. var ErrFingerprintMismatch = errors.New("index: record key is not the signing key's fingerprint") -// Ingest verifies a space.deepsky.identity record read from did's repo at record +// Ingest verifies a me.byjp.deepsky.identity record read from did's repo at record // key rkey, and on success records the fingerprint→did binding. recordValue is // the raw record JSON (the value, not the wrapper). It is safe to call for // records from untrusted sources: anything that fails verification is rejected. diff --git a/internal/identity/index/jetstream.go b/internal/identity/index/jetstream.go index fa17310..14bb1d8 100644 --- a/internal/identity/index/jetstream.go +++ b/internal/identity/index/jetstream.go @@ -16,7 +16,7 @@ import ( // DefaultJetstream is a public Jetstream instance. const DefaultJetstream = "wss://jetstream2.us-east.bsky.network/subscribe" -// Consumer tails a Jetstream instance for space.deepsky.identity records and +// Consumer tails a Jetstream instance for me.byjp.deepsky.identity records and // keeps the Store up to date. It reconnects with backoff and resumes from the // Store's saved cursor. type Consumer struct { diff --git a/internal/identity/index/store.go b/internal/identity/index/store.go index 68cf066..b5dd3f9 100644 --- a/internal/identity/index/store.go +++ b/internal/identity/index/store.go @@ -1,5 +1,5 @@ // Package index maintains a persistent, verified map from certificate -// fingerprints to atproto DIDs, populated from space.deepsky.identity records +// fingerprints to atproto DIDs, populated from me.byjp.deepsky.identity records // seen on the network (a one-time backfill plus a live Jetstream tail). // // Every record is cryptographically verified before it enters the store, so a diff --git a/internal/identity/record.go b/internal/identity/record.go index 58d8b71..f0eee5d 100644 --- a/internal/identity/record.go +++ b/internal/identity/record.go @@ -10,7 +10,7 @@ package identity // only thing that depends on getting this exactly right. const SignatureType = "community.lexicon.attestation.signature" -// Record is a space.deepsky.identity record: a signed binding from a +// Record is a me.byjp.deepsky.identity record: a signed binding from a // certificate fingerprint (the record key) to the repository's account. type Record struct { Type string `json:"$type"` diff --git a/internal/identity/sign.go b/internal/identity/sign.go index 72da6a7..3418a63 100644 --- a/internal/identity/sign.go +++ b/internal/identity/sign.go @@ -29,7 +29,7 @@ func payloadCID(content, meta map[string]any) (raw []byte, str string, err error return raw, str, nil } -// Sign builds a signed space.deepsky.identity record binding priv's certificate +// Sign builds a signed me.byjp.deepsky.identity record binding priv's certificate // public key to did. createdAt is an RFC 3339 timestamp used for both the // record and the attestation. func Sign(priv *ecdsa.PrivateKey, did, createdAt string) (*Record, error) { diff --git a/internal/render/render.go b/internal/render/render.go index d020017..9e04f23 100644 --- a/internal/render/render.go +++ b/internal/render/render.go @@ -63,7 +63,7 @@ func Me(w io.Writer, v *Viewer, fp string) { case fp != "": fmt.Fprintf(w, "Your client certificate is recognised but not yet linked to an "+ "atproto account.\n\nFingerprint:\n%s\n\n", fp) - fmt.Fprint(w, "To link it, publish a signed space.deepsky.identity record from your "+ + fmt.Fprint(w, "To link it, publish a signed me.byjp.deepsky.identity record from your "+ "account with this fingerprint as its record key:\n\n"+ " deepsky identity -handle -cert -key -app-password \n") default: diff --git a/main.go b/main.go index 3dbd9dd..16937c8 100644 --- a/main.go +++ b/main.go @@ -10,7 +10,7 @@ // It has two subcommands: // // deepsky serve run the Gemini server (default if none given) -// deepsky identity mint a space.deepsky.identity record binding a Gemini +// deepsky identity mint a me.byjp.deepsky.identity record binding a Gemini // client certificate to your atproto account package main -- 2.51.2