Environment
Description
LinkWebIdHandler decide whether to require the registration-token (ownership) flow by asking the
deployment's StorageLocationStrategy where the WebID lives.
const baseUrl = await this.storageStrategy.getStorageIdentifier({ path: webId });
const pod = await this.podStore.findByBaseUrl(baseUrl.path);
isCreator = accountId === pod?.accountId;
That lookup answers "which storage contains this identifier?", which is not the same question as
"is this document inside a pod the account created?". It gives a false negative in:
- configs wiring
css:config/storage/location/root.json (RootStorageLocationStrategy): the lookup
returns the server root, which is never a named pod's baseUrl → an account linking
<base>/alice/profile/card#me is sent to the ownership-token flow for its own pod;
- suffix identifiers with a card directly under the base (root-level pod):
SuffixIdentifierGenerator.extractPod('<base>/profile/card#me') resolves to <base>/profile/,
which is not a pod either.
Deployments with location/pod.json and named pods are unaffected — suffix vs subdomain is not the
deciding factor.
Environment
Description
LinkWebIdHandlerdecide whether to require the registration-token (ownership) flow by asking thedeployment's
StorageLocationStrategywhere the WebID lives.That lookup answers "which storage contains this identifier?", which is not the same question as
"is this document inside a pod the account created?". It gives a false negative in:
css:config/storage/location/root.json(RootStorageLocationStrategy): the lookupreturns the server root, which is never a named pod's
baseUrl→ an account linking<base>/alice/profile/card#meis sent to the ownership-token flow for its own pod;SuffixIdentifierGenerator.extractPod('<base>/profile/card#me')resolves to<base>/profile/,which is not a pod either.
Deployments with
location/pod.jsonand named pods are unaffected — suffix vs subdomain is not thedeciding factor.