Skip to content

Latest commit

 

History

History
47 lines (27 loc) · 4.64 KB

File metadata and controls

47 lines (27 loc) · 4.64 KB

Contributing to Abblix OIDC Server

Thank you for your interest in Abblix OIDC Server. Bug reports, specification gaps and real integration scenarios from the people who build on this library go straight into what we fix and what we build next.

This note explains how the project is developed, so your effort goes where it counts.

How the codebase is maintained

Abblix OIDC Server is a source-available commercial product, developed in-house by the Abblix team. We do not accept external pull requests, and outside code is not merged into the codebase. This lets us keep full ownership of the architecture, apply one consistent standard for security and specification conformance, and keep the provenance of every line clear under our license.

That is not a judgement on the quality of outside work. It is how we keep a security-critical identity library coherent and accountable.

Packages under an open-source license

Part of this repository is distributed under the Apache License 2.0. Each package names its license in its manifest, and every source file repeats it in an SPDX identifier, so you never have to guess: read the header of the file in front of you.

An open license answers what you may do with the code. It does not change how the project is developed, and the two are separate questions. We do not merge external pull requests into the Apache-2.0 packages either, for the reason above and for one more: remaining the sole author is what lets us release future versions under the license we choose. Accepting outside code would end that quietly, and it is not a decision that should happen as a side effect of a merge.

You are free to fork an Apache-2.0 package and change it in your own copy. That is what the license grants, and we are not asking you to refrain. What we will not do is take the change back into this repository. If you found a defect there, an issue with a reproduction is worth more to us than a patch, because it lets us fix it for everyone.

How you can help

These are the contributions we value most:

  • Report a bug. Open a GitHub issue with the library version, your .NET version, your configuration, the request sequence, and what you expected versus what happened. A clear reproduction is the fastest path to a fix.
  • Suggest a feature or improvement. Open an issue, or post in Ideas describing the use case. That is where we ask what to build next, and we read it when planning. We cannot build everything, and we say so when we decide against something.
  • Point out a specification gap. If something diverges from an RFC or an OpenID Connect specification, tell us which clause, and where our behavior departs from it. Abblix OIDC Server is certified by the OpenID Foundation, and the standards it implements are listed in the documentation: a divergence from a clause is a defect, and we treat it as one.
  • Ask a question. Q&A is the place for integration questions and design conversations.

Security issues

Anything that lets someone obtain a token, a session or a claim they should not have, or that weakens a check this library is meant to perform, goes to support@abblix.com or through private reporting on GitHub. Never to a public issue or discussion. The process is in SECURITY.md.

If you are unsure which kind you are holding, treat it as a security issue. We would far rather receive an ordinary bug privately than read a live vulnerability in a public thread, and we will tell you when it is fine to move it into the open.

Ideas you post here

Anything you post in issues or discussions we may implement freely and without obligation, and we claim nothing over what you keep to yourself. Please do not post code you want to retain rights in, or anything confidential to your employer: we will not merge it, and these are public forums.

Contact

We triage new issues weekly and reply to every bug report. Thank you for the time you take to help us make Abblix OIDC Server better.