Identities for entities did.bot
agent llm did

fix(didbot-dns): apply the same wildcard-depth fix to Route53Dns master

Route53Dns::accepts had the identical ends_with shape WildcardDns::accepts did before it: any depth under the zone was accepted, not just the one label a wildcard record actually matches. This is the production DNS backend, so the flaw was live where it matters most. Reused the same hostname_is_at_or_below-plus-label-count check. resync's own live-zone test used a TXT fixture two labels below the zone (`_acme-challenge.a.<zone>`), a shape didbot_tls::acme never produces -- the real DNS-01 challenge for both the apex and wildcard identifiers always collapses onto `_acme-challenge.<zone>`, one label down. Moved the fixture there rather than loosen accepts() to keep a synthetic shape working. Mutation-tested: reverting accepts() to the old ends_with check lets the new over-deep publish test's host through to an unrelated UnsupportedTarget error instead of NotUnderZone; restoring it refuses correctly. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Change-Id: If1fdfbdfa2c31d40552f8d374a3052fe7d38aed3


+39 -3
1 changed file