Skip to content

WebID link ownership check #2263

Description

@bourgeoa

Environment

  • Server version: 7.2.0

Description

LinkWebIdHandler decide whether to require the registration-token (ownership) flow by asking the
deployment's StorageLocationStrategy where the WebID lives.

const baseUrl = await this.storageStrategy.getStorageIdentifier({ path: webId });
const pod = await this.podStore.findByBaseUrl(baseUrl.path);
isCreator = accountId === pod?.accountId;

That lookup answers "which storage contains this identifier?", which is not the same question as
"is this document inside a pod the account created?". It gives a false negative in:

  • configs wiring css:config/storage/location/root.json (RootStorageLocationStrategy): the lookup
    returns the server root, which is never a named pod's baseUrl → an account linking
    <base>/alice/profile/card#me is sent to the ownership-token flow for its own pod;
  • suffix identifiers with a card directly under the base (root-level pod):
    SuffixIdentifierGenerator.extractPod('<base>/profile/card#me') resolves to <base>/profile/,
    which is not a pod either.

Deployments with location/pod.json and named pods are unaffected — suffix vs subdomain is not the
deciding factor.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions