Blob resolver: no CID validation
did:plc:p5yjdr64h7mk5l3kh6oszryk opened this 17d ago 2 comments
did:plc:p5yjdr64h7mk5l3kh6oszryk opened 17d ago
The blob resolver does not attempt to validate blob content identifiers after fetch, which allows users to modify the blob locally on their PDS to be any content they wish without updating any records. It would be a good idea to compute a hash of the downloaded blob after fetch and ensure it matches the requested CID.
No activity yet.