requireAttribution property

bool requireAttribution
final

Refuse a document with neither a transport-authenticated sender nor a proof, with proofRequired. Defaults to true.

Without it, an unauthenticated POST claiming "issuer": "did:web:victim.example" reaches the handler with that string as the resolved issuer, and nothing downstream can tell it from a genuine request. ยง5: "this binding does not permit proof to be omitted". Turn it off only for local development.

Implementation

final bool requireAttribution;