LogicSRC standards surface
++ One file a merchant serves about the commission it pays, and four calls that let a + person or an agent earn it. No network in the money. +
+
+ Affiliate marketing runs through networks, and the networks are the problem. A merchant
+ pays a third of every commission for a pixel and a payout file. An affiliate applies to
+ each program by hand, waits weeks, and ends up with ten dashboards that disagree. Terms
+ live in a PDF signed once. A conversion is reversed with no reason. A payout arrives sixty
+ days later, minus a fee. And none of it is readable by a machine, so an agent that could
+ earn by recommending the right product cannot find out what the commission is. The
+ merchant already knows what it pays and what each sale was worth. OpenAffiliate is that,
+ written down, at /.well-known/openaffiliate.json.
+
+ Status: 0.1. The reference implementation is{" "} + crawlproof.com, which runs its own + program, joins other merchants' programs from the same dashboard, and pays in USDC on + Polygon. The smallest valid file is a merchant with a name and a program with a title + and one thing it pays. +
++ A commission fetched from the merchant's own origin is the commission the merchant + says it pays, today, in words it cannot say it never agreed to. +
+{DESCRIPTOR}
+
+ pays is one entry per event. window{" "}
+ is the attribution window in days and attribution whether a
+ later click replaces an earlier one. hold_days is the refund
+ window a conversion waits out as pending. payout.methods are{" "}
+ asset/chain pairs or a named rail. self{" "}
+ says whether the affiliate's own purchase pays. Unknown keys are kept.
+
| + {what} + | +{how} | +
{JOIN}
+ | event | +what happened | +how it pays | +
|---|---|---|
+ {event}
+ |
+ {what} | +{how} | +
| on a network | +with OpenAffiliate | +
|---|---|
| {before} | +{after} | +
| + {what} + | +{why} | +
LogicSRC standards surface
++ One file a security tool serves about what it found in the open. A directory reads the + reporter instead of a vendor feed, and the reporter decides what it discloses. +
+
+ Every security tool finds things, and every one keeps what it found behind its own login.
+ A scanner that runs on a thousand public repositories knows which rules fire and where,
+ and says nothing, because saying it would mean a feed, a schema, an API key and a sales
+ call. The threat feeds that exist are products with terms that forbid redistribution.
+ OpenThreat is the small file a tool can serve in an afternoon at{" "}
+ /.well-known/openthreat.json, with a rule for what may go in
+ it.
+
+ Status: 0.1. The first reporter is{" "} + threatcrush.com/discovery, built from the + scans its GitHub App ran on public repositories; the first directory is{" "} + nichedb.dev/c/threats. +
+
+ Only reporter.name and a threat's{" "}
+ title are required. Everything at{" "}
+ /.well-known/ is TLP:CLEAR by definition.
+
{DESCRIPTOR}
+
+ rule is the same string a SARIF ruleId carries;{" "}
+ subject is what the threat is about and is public by
+ definition; status is open, fixed, mitigated, blocked or
+ withdrawn, and a withdrawn threat stays in the file a while so directories retract it.
+ The second threat above is a secret: no location, no message, by rule.
+
| kind | +what it is | +
|---|---|
+ {kind}
+ |
+ {what} | +
Every other rule degrades. These two are the reason the file can exist at all.
+| + {what} + | +{why} | +
+ A subject that was scanned did not ask to be listed. Announcing is on by default, because
+ a finding in a public repository is public already, and opting out is one switch in the
+ tool's own settings. A subject that opts out leaves the file on the next build, and
+ is served once more as withdrawn so directories retract it.
+
| + {what} + | +{why} | +