OAI / OAI/sig-security

Security SIG Meeting - October 8th, 2021

Open
#4 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

meetings
Dominant language
No language data
Stars
6
Forks
3
Avg merge
1h 54m
Merged PRs (30d)
1

Description

Here are my notes from today's security SIG, providing some overview of what occurred during the recurring discussion:

  • Jeremy's Proposal - Everyone should review. Phillippe did.
  • Who are the targets of changes?
    • Producer?
    • Consumer?
    • Security?
    • Auditor? Compliance? Regulatory?
  • Why are we doing this?
    • What is require?
    • Where it goes?
  • What are we focusing on?
    • FAPI
    • OAuth
    • JWT
    • SAML
  • Industries

We seem to come out of it with a focus on taking Jeremy's spec and applying to FAPI to think through all of this end to end.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Begin with the meeting notes in issue #4 and review the linked SAML bindings errata alongside the references to FAPI, OAuth, JWT, and SAML. Done is not defined in the issue; a contributor would need a maintainer to specify whether these notes should be expanded, corrected, or turned into a concrete documentation task.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.