{"record":{"id":"829a5b49f87625c5","repo":"affaan-m/ECC","slug":"invalid-did-did-r-must-start-with-did","errorCode":null,"errorMessage":"invalid DID: {did!r} (must start with 'did:')","messagePattern":"invalid DID: (.+?) \\(must start with 'did:'\\)","errorType":"exception","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"integrations/aura/adapter.py","lineNumber":159,"sourceCode":"def aura_verdict(\n    did: str,\n    *,\n    base_url: str = DEFAULT_BASE_URL,\n    timeout: float = DEFAULT_TIMEOUT,\n    _fetch: Callable[[str, float], dict[str, Any]] = _http_get_json,\n) -> AuraVerdict:\n    \"\"\"\n    Look up the trust verdict for a counterparty DID. Never raises on a\n    network/parse failure — returns an `unknown` verdict instead, leaving the\n    proceed/abort decision to the caller's policy (see before_settle).\n\n        v = aura_verdict(\"did:aura:z6Mk...\")\n        print(v.verdict, v.reason, v.score)\n\n    `_fetch` is an injection seam for tests; production callers ignore it.\n    \"\"\"\n    if not did or not str(did).startswith(\"did:\"):\n        raise ValueError(f\"invalid DID: {did!r} (must start with 'did:')\")\n\n    url = f\"{base_url.rstrip('/')}/check?\" + urllib.parse.urlencode({\"did\": did})\n    try:\n        body = _fetch(url, timeout)\n    except urllib.error.HTTPError as e:\n        return AuraVerdict.invalid_response(did, f\"AURA returned HTTP {e.code}: {e.reason}\")\n    except (urllib.error.URLError, TimeoutError, OSError) as e:\n        return AuraVerdict.unreachable(did, f\"AURA unreachable: {e}\")\n    except (json.JSONDecodeError, ValueError) as e:\n        return AuraVerdict.invalid_response(did, f\"AURA returned non-JSON: {e}\")\n\n    if not isinstance(body, dict):\n        return AuraVerdict.invalid_response(did, \"AURA returned an unexpected shape\")\n    return AuraVerdict.from_payload(did, body)\n\n\ndef before_settle(\n    did: str,","sourceCodeStart":141,"sourceCodeEnd":177,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/integrations/aura/adapter.py#L141-L177","documentation":"aura_verdict validates that its `did` argument is a non-empty string starting with 'did:' before building the AURA check URL. If the DID is empty, None, or malformed, it raises ValueError(\"invalid DID: ... (must start with 'did:')\") immediately — fail-fast input validation for the decentralized identifier format.","triggerScenarios":"Calling aura_verdict(None), aura_verdict(''), aura_verdict('z6Mk...') (raw key without did: prefix), or a non-string object; also via before_settle or the listed tests that pass an invalid DID.","commonSituations":"Agent identity not yet provisioned so the DID variable is None/empty; storing only the aura key (did:aura:z6Mk...) and stripping the scheme somewhere upstream; config loading returning the wrong field; tests passing placeholder values.","solutions":["Ensure the DID is loaded/provisioned before calling — check the agent identity config or keychain entry exists","Prefix raw keys with the scheme, e.g. 'z6Mk...' -> 'did:aura:z6Mk...'","Trim whitespace/quotes around the configured DID value","Validate the DID at config-load time so bad values fail before any settlement call"],"exampleFix":"# before\nverdict = aura_verdict(agent_key)          # 'z6Mk...'\n\n# after\nverdict = aura_verdict(f\"did:aura:{agent_key}\") if not agent_key.startswith(\"did:\") else aura_verdict(agent_key)","handlingStrategy":"validation","validationCode":"def is_valid_did(did) -> bool:\n    return bool(did) and str(did).startswith(\"did:\")","typeGuard":"def require_did(did: str) -> str:\n    if not isinstance(did, str) or not did.startswith(\"did:\"):\n        raise ValueError(f\"invalid DID: {did!r}\")\n    return did","tryCatchPattern":"try:\n    v = aura_verdict(did)\nexcept ValueError as e:\n    logger.error(\"bad DID configured: %s\", e)  # fail the workflow before settlement\n    raise","preventionTips":["Load and validate the DID at config/identity startup, not at call time","Store DIDs with their did: scheme included; never strip it for storage","Add a unit test asserting the identity module never returns an unprefixed key"],"tags":["python","validation","did","aura"],"backgroundTag":"invalid-identifier-format","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}