Summary
The GitlawbNameRegistry/DID-registry calls used by gl name register and gl name register-did (crates/gl/src/name.rs:238-285, :352-397; ABI at :27-50) take register(string name, string did) / register(string did, string document) from the caller's wallet alone, with no signature from the DID subject being claimed. Consumers of gl name resolve / resolve-did get the mapping presented as authoritative. The constants also pin Base Sepolia testnet (name.rs:21-23) while output text says "Base L2".
Impact
Any wallet can bind a name to a DID it does not control, or anchor an attacker-authored DID document (service endpoints, metadata) for another peer's DID observable on the network. Agents deciding where to clone from via gl name resolve consume attacker-chosen identity data. Testnet today; this is a protocol-design gap to fix before any mainnet use.
Remediation
- Require the DID subject's signature over the registration (or a DID-document proof) in the contract flow.
- Correct the network labelling in output.
Proposed labels: kind:bug, crate:gl, subsystem:identity.
Summary
The
GitlawbNameRegistry/DID-registry calls used bygl name registerandgl name register-did(crates/gl/src/name.rs:238-285,:352-397; ABI at:27-50) takeregister(string name, string did)/register(string did, string document)from the caller's wallet alone, with no signature from the DID subject being claimed. Consumers ofgl name resolve/resolve-didget the mapping presented as authoritative. The constants also pin Base Sepolia testnet (name.rs:21-23) while output text says "Base L2".Impact
Any wallet can bind a name to a DID it does not control, or anchor an attacker-authored DID document (service endpoints, metadata) for another peer's DID observable on the network. Agents deciding where to clone from via
gl name resolveconsume attacker-chosen identity data. Testnet today; this is a protocol-design gap to fix before any mainnet use.Remediation
Proposed labels: kind:bug, crate:gl, subsystem:identity.