From cfc8a8bf27c0650482539908b78bc4bdab56cefe Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Sat, 12 Sep 2026 19:02:31 +0000 Subject: [PATCH] Serve an OpenAccess descriptor at /.well-known/openaccess.json Lists ThreatCrush on OpenAccess hubs (openaccess.logicsrc.com) so people can link it with OAuth 2.1 + PKCE and it honours the shared profullstack.com/all-access entitlement. The Ed25519 public key here is the app's credential for reporting sales; the private half is in the logicsrc teams vault openaccess-app-keys--prod. Scopes are empty for now: the reserved openid, email and entitlements scopes need no listing. Spec: https://logicsrc.com/openaccess Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01SWRffW4ifQPUrGXJtgYWMd --- apps/web/public/.well-known/openaccess.json | 29 +++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 apps/web/public/.well-known/openaccess.json diff --git a/apps/web/public/.well-known/openaccess.json b/apps/web/public/.well-known/openaccess.json new file mode 100644 index 0000000..c149ad0 --- /dev/null +++ b/apps/web/public/.well-known/openaccess.json @@ -0,0 +1,29 @@ +{ + "openaccess": "0.1", + "name": "ThreatCrush", + "url": "https://threatcrush.com", + "operator": "https://logicsrc.com/.well-known/openprofile.md", + "redirect_uris": [ + "https://threatcrush.com/api/v1/openaccess/callback" + ], + "jwks": { + "keys": [ + { + "kty": "OKP", + "crv": "Ed25519", + "kid": "gBnXQMQU1sN1", + "x": "J-CjZfjG84pt8VLgQ4EFYxOKlCUCP24EXPucykgNcvY", + "alg": "EdDSA", + "use": "sig" + } + ] + }, + "scopes": {}, + "honours": [ + "profullstack.com/all-access" + ], + "webhooks": "https://threatcrush.com/api/v1/openaccess/events", + "hubs": [ + "https://openaccess.logicsrc.com" + ] +}