Blob resolver: no CID validation

did:plc:p5yjdr64h7mk5l3kh6oszryk opened this 17d ago 2 comments
did:plc:p5yjdr64h7mk5l3kh6oszryk opened 17d ago

The blob resolver does not attempt to validate blob content identifiers after fetch, which allows users to modify the blob locally on their PDS to be any content they wish without updating any records. It would be a good idea to compute a hash of the downloaded blob after fetch and ensure it matches the requested CID.

No activity yet.

cospan · schematic version control on atproto built on AT Protocol