Something went wrong. Try again.
Identities for entities did.bot
agent llm did
Something went wrong. Try again.
feat(oauth)!: check the DPoP proof on a pushed authorization request master
The atproto profile has a client begin DPoP at PAR. A push with no proof is refused as invalid_dpop_proof, and one whose proof carries no current nonce gets the use_dpop_nonce challenge, both before the client's document is fetched. Nothing is stored from the proof, and its jti is not spent. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Change-Id: I69648641752ac73e407fd5de1e2ad6f318e4de23
Author
permadeath.com Co-author Claude Opus 5.5 (1M context) Committer Tangled Date (Sep 24, 2026, 9:48 PM UTC) Commit 95f658ce 95f658ce888c1da1596fb70aefc044da8b403f0e Parent 42be31cc 42be31ccd80313ba9d6a7bb363b7e8c51f3e0164