Identities for entities did.bot
agent llm did

feat(oauth)!: check the DPoP proof on a pushed authorization request master

The atproto profile has a client begin DPoP at PAR. A push with no proof is refused as invalid_dpop_proof, and one whose proof carries no current nonce gets the use_dpop_nonce challenge, both before the client's document is fetched. Nothing is stored from the proof, and its jti is not spent. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Change-Id: I69648641752ac73e407fd5de1e2ad6f318e4de23


+211 -61
6 changed files