Skip to content

gl(name): on-chain name and DID registries accept registrations without proving control of the DID #492

Description

@euxaristia

Summary

The GitlawbNameRegistry/DID-registry calls used by gl name register and gl name register-did (crates/gl/src/name.rs:238-285, :352-397; ABI at :27-50) take register(string name, string did) / register(string did, string document) from the caller's wallet alone, with no signature from the DID subject being claimed. Consumers of gl name resolve / resolve-did get the mapping presented as authoritative. The constants also pin Base Sepolia testnet (name.rs:21-23) while output text says "Base L2".

Impact

Any wallet can bind a name to a DID it does not control, or anchor an attacker-authored DID document (service endpoints, metadata) for another peer's DID observable on the network. Agents deciding where to clone from via gl name resolve consume attacker-chosen identity data. Testnet today; this is a protocol-design gap to fix before any mainnet use.

Remediation

  1. Require the DID subject's signature over the registration (or a DID-document proof) in the contract flow.
  2. Correct the network labelling in output.

Proposed labels: kind:bug, crate:gl, subsystem:identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:glgl — the contributor CLIkind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions