requireAttribution property
Refuse a document with neither a transport-authenticated sender
nor a proof, with proofRequired. Defaults to true.
Without it, an unauthenticated POST claiming
"issuer": "did:web:victim.example" reaches the handler with that string
as the resolved issuer, and nothing downstream can tell it from a genuine
request. ยง5: "this binding does not permit proof to be omitted". Turn it
off only for local development.
Implementation
final bool requireAttribution;