init
This commit is contained in:
@@ -0,0 +1,9 @@
|
||||
# Commercial boundary
|
||||
|
||||
The declaration renderer and standard remain usable without a commercial entitlement. Licensed capabilities are enabled only by tokens issued through the separately operated Universal License Platform.
|
||||
|
||||
Official binaries embed a public trust store at build time. Customers can configure only a signed `LICENSE_TOKEN` and optional runtime verification settings. They cannot replace the trusted issuer or lease keys through environment variables.
|
||||
|
||||
The AI Disclosure Standard repository does not contain private keys, key generation, license issuance, administration, revocation storage or lease signing. Those responsibilities belong to the standalone platform.
|
||||
|
||||
A technically capable user can still modify open source and compile an unofficial binary. Legal licence terms, trademark protection, official signed releases, support, updates and centrally verified services remain the enforceable commercial boundary.
|
||||
@@ -0,0 +1,40 @@
|
||||
# Runtime license client
|
||||
|
||||
The application uses the client protocol from Universal License Platform v1.0.0.
|
||||
|
||||
Imports:
|
||||
|
||||
```go
|
||||
import (
|
||||
"github.com/b1tsblog/license-platform/pkg/licensekit"
|
||||
"github.com/b1tsblog/license-platform/sdk/go/licenseclient"
|
||||
)
|
||||
```
|
||||
|
||||
Initialization is performed in `internal/app/server.go`. The product ID and embedded trust store are not customer-configurable.
|
||||
|
||||
```go
|
||||
licenses := licenseclient.New(ctx, licenseclient.Config{
|
||||
Product: "ai-disclosure-standard",
|
||||
ClientVersion: "1.6.1",
|
||||
Token: cfg.LicenseToken,
|
||||
TrustStore: trustStore,
|
||||
BaseURL: cfg.BaseURL,
|
||||
InstanceID: cfg.LicenseInstanceID,
|
||||
Mode: cfg.LicenseMode,
|
||||
ServerURL: cfg.LicenseServerURL,
|
||||
CacheFile: cfg.LicenseCacheFile,
|
||||
RefreshEvery: cfg.LicenseRefreshEvery,
|
||||
RequestTimeout: cfg.LicenseTimeout,
|
||||
})
|
||||
```
|
||||
|
||||
Feature checks remain server-side:
|
||||
|
||||
```go
|
||||
if licenses.Has("custom_badge") {
|
||||
// accept custom badge presentation
|
||||
}
|
||||
```
|
||||
|
||||
The runtime client contains no license-signing or private-key functionality. See [`LICENSE-INTEGRATION.md`](LICENSE-INTEGRATION.md) for deployment details.
|
||||
@@ -0,0 +1,172 @@
|
||||
# Integration mit der Universal License Platform
|
||||
|
||||
## Verantwortungsgrenze
|
||||
|
||||
Die AI-Disclosure-Anwendung ist ausschließlich ein Lizenz-Client. Die Universal License Platform ist die einzige Autorität für:
|
||||
|
||||
- Schlüsselverwaltung;
|
||||
- Produkterfassung;
|
||||
- Lizenzausstellung;
|
||||
- Token-Registry;
|
||||
- Widerruf und Reaktivierung;
|
||||
- Onlineprüfung;
|
||||
- Signierung kurzlebiger Leases;
|
||||
- Audit- und Benutzerverwaltung.
|
||||
|
||||
Das Hauptprojekt enthält keine dieser Funktionen.
|
||||
|
||||
## Produkt in der Plattform anlegen
|
||||
|
||||
Verwende als unveränderliche Produkt-ID:
|
||||
|
||||
```text
|
||||
ai-disclosure-standard
|
||||
```
|
||||
|
||||
Die aktuell ausgewerteten Feature-IDs sind:
|
||||
|
||||
| Feature | Wirkung |
|
||||
|---|---|
|
||||
| `custom_text` | eigener Titel und eigener Erklärungstext |
|
||||
| `custom_badge` | eigene Badge-Beschriftungen und Farben |
|
||||
| `white_label` | reserviert für markenneutrale Ausgaben |
|
||||
|
||||
Unbekannte Features werden vom Produkt ignoriert und können für andere Produkte weiterverwendet werden.
|
||||
|
||||
## Trust Store installieren
|
||||
|
||||
Die Plattform liefert unter folgendem Endpunkt ausschließlich öffentliche Schlüssel:
|
||||
|
||||
```text
|
||||
GET /api/v1/trust-store
|
||||
```
|
||||
|
||||
Die Antwort muss vor dem Produkt-Build als folgende Datei gespeichert werden:
|
||||
|
||||
```text
|
||||
internal/app/trusted_keys.json
|
||||
```
|
||||
|
||||
Erwartetes Format:
|
||||
|
||||
```json
|
||||
{
|
||||
"licenseKeys": {
|
||||
"issuer-2026": "PUBLIC_KEY_BASE64URL"
|
||||
},
|
||||
"leaseKeys": {
|
||||
"lease-2026": "PUBLIC_KEY_BASE64URL"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
Anschließend muss das Produkt neu kompiliert beziehungsweise das Container-Image neu gebaut werden. Der Trust Store ist absichtlich nicht per Umgebungsvariable konfigurierbar.
|
||||
|
||||
## Runtime-Konfiguration
|
||||
|
||||
Minimal für Offline-Lizenzen:
|
||||
|
||||
```env
|
||||
LICENSE_TOKEN=...
|
||||
LICENSE_MODE=offline
|
||||
```
|
||||
|
||||
Hybrid:
|
||||
|
||||
```env
|
||||
LICENSE_TOKEN=...
|
||||
LICENSE_MODE=hybrid
|
||||
LICENSE_CACHE_FILE=/data/license-lease.json
|
||||
LICENSE_REFRESH_INTERVAL=15m
|
||||
LICENSE_REQUEST_TIMEOUT=5s
|
||||
```
|
||||
|
||||
Online:
|
||||
|
||||
```env
|
||||
LICENSE_TOKEN=...
|
||||
LICENSE_MODE=online
|
||||
LICENSE_REQUEST_TIMEOUT=5s
|
||||
```
|
||||
|
||||
Optional:
|
||||
|
||||
```env
|
||||
LICENSE_SERVER_URL=https://licenses.example.org
|
||||
LICENSE_INSTANCE_ID=production-eu-1
|
||||
```
|
||||
|
||||
Die in der Lizenz signierte `verification.serverUrl` wird automatisch erkannt. Die Auflösungsreihenfolge ist:
|
||||
|
||||
1. `licenseclient.Config.ServerURL` beziehungsweise `LICENSE_SERVER_URL`;
|
||||
2. signierte `verification.serverUrl` aus dem Lizenz-Token;
|
||||
3. `/.well-known/license-server` auf der Produkt-Basis-URL.
|
||||
|
||||
## Onlineprotokoll
|
||||
|
||||
Der Client sendet an:
|
||||
|
||||
```text
|
||||
POST /api/v1/licenses/validate
|
||||
```
|
||||
|
||||
Anfrage:
|
||||
|
||||
```json
|
||||
{
|
||||
"token": "...",
|
||||
"product": "ai-disclosure-standard",
|
||||
"baseUrl": "https://ai.example.org",
|
||||
"host": "ai.example.org",
|
||||
"instanceId": "production-eu-1",
|
||||
"clientVersion": "1.6.1"
|
||||
}
|
||||
```
|
||||
|
||||
Erwartete Antwort:
|
||||
|
||||
```json
|
||||
{
|
||||
"valid": true,
|
||||
"leaseToken": "..."
|
||||
}
|
||||
```
|
||||
|
||||
Der Lease-Token wird erneut lokal gegen die eingebetteten Lease-Public-Keys geprüft. Eine bloße positive JSON-Antwort ohne gültige Signatur schaltet keine Funktionen frei.
|
||||
|
||||
## Domain- und Instanzbindung
|
||||
|
||||
Die Plattform kann Lizenzen binden an:
|
||||
|
||||
```text
|
||||
example.org
|
||||
*.example.org
|
||||
*
|
||||
```
|
||||
|
||||
`*` erlaubt alle Domains. `*.example.org` erlaubt nur echte Subdomains und nicht automatisch `example.org` selbst.
|
||||
|
||||
Instanz-IDs funktionieren entsprechend. Ist eine Lizenz an Instanzen gebunden, muss `LICENSE_INSTANCE_ID` gesetzt sein.
|
||||
|
||||
## Schlüsselrotation
|
||||
|
||||
1. In der Universal License Platform einen neuen Issuer- oder Lease-Key aktivieren.
|
||||
2. Einen Trust Store herunterladen, der alten und neuen Public Key enthält.
|
||||
3. Das Produkt mit beiden Schlüsseln neu bauen und ausrollen.
|
||||
4. Neue Lizenzen beziehungsweise Leases mit dem neuen Key ausstellen.
|
||||
5. Den alten Public Key erst entfernen, wenn alle damit signierten Tokens abgelaufen oder ersetzt sind.
|
||||
|
||||
## Client-Snapshot
|
||||
|
||||
Unter `third_party/license-platform-client` liegt eine client-only, protokollkompatible Momentaufnahme des Go-SDK aus Universal License Platform v1.0.0. Sie enthält nur:
|
||||
|
||||
- öffentliche Protokolltypen;
|
||||
- Trust-Store-Parsing;
|
||||
- Ed25519-Verifikation;
|
||||
- Kontext-, Domain- und Instanzprüfung;
|
||||
- Offline-/Hybrid-/Online-Client;
|
||||
- signierten Lease-Cache.
|
||||
|
||||
Private-Key-Handling, Signierfunktionen, Admin-Server und Persistenz wurden bewusst nicht übernommen.
|
||||
|
||||
Sobald das eigenständige Modul über einen stabilen Go-Modul-Tag erreichbar ist, kann in `go.mod` der lokale `replace`-Eintrag entfernt und direkt die veröffentlichte SDK-Version verwendet werden.
|
||||
@@ -0,0 +1,35 @@
|
||||
# Marketing page
|
||||
|
||||
The product page is served by the same Go binary as the badge and declaration API.
|
||||
|
||||
## Routes
|
||||
|
||||
- `/product` — complete product, feature, pricing and installation page
|
||||
- `/pricing` — redirects to `/product#pricing`
|
||||
- `/install` — redirects to `/product#install`
|
||||
|
||||
All routes support `?lang=de|en|fr|es|it|nl|pt|pl` and `Accept-Language` negotiation.
|
||||
|
||||
## Runtime configuration
|
||||
|
||||
```text
|
||||
SALES_URL=https://example.org/contact
|
||||
PRICE_COMMUNITY=0 €
|
||||
PRICE_PRO=19 €
|
||||
PRICE_PUBLISHER=79 €
|
||||
PRICE_AGENCY=199 €
|
||||
```
|
||||
|
||||
`SALES_URL` is used by paid-plan calls to action. When it is empty, the service falls back to `CONTACT_URL`.
|
||||
|
||||
The page deliberately markets only capabilities that exist in the current build. Domain counts, support levels and commercial terms are offer definitions; adjust them before publication.
|
||||
|
||||
## Editing content
|
||||
|
||||
- Page structure: `web/templates/marketing.html`
|
||||
- Styling: `web/static/style.css`
|
||||
- Copy controls and language switch: `web/static/marketing.js`
|
||||
- Localised product copy: `internal/marketing/content.go`
|
||||
- Generator navigation label: `internal/i18n/marketing.go`
|
||||
|
||||
No external fonts, scripts, images, analytics or cookies are required.
|
||||
@@ -0,0 +1,40 @@
|
||||
# Migration von 1.5 auf 1.6
|
||||
|
||||
## Entfernte Bestandteile
|
||||
|
||||
Aus dem AI-Disclosure-Projekt wurden vollständig entfernt:
|
||||
|
||||
- lokale Schlüsselgenerierung und Token-Signierung;
|
||||
- Lizenz-Webinterface;
|
||||
- eingebauter Lizenz- und Widerrufsserver;
|
||||
- Admin-API und lokale Lizenz-Registry;
|
||||
- Lease-Signierung;
|
||||
- zugehörige Docker-, Kubernetes-, OpenAPI- und Schema-Dateien.
|
||||
|
||||
Diese Aufgaben übernimmt ausschließlich die eigenständige Universal License Platform.
|
||||
|
||||
## Umstellung
|
||||
|
||||
1. Universal License Platform v1.0.0 separat starten.
|
||||
2. Vorhandene Issuer- und Lease-Schlüssel entsprechend deren Migrationsanleitung importieren.
|
||||
3. In der Plattform das Produkt `ai-disclosure-standard` und die benötigten Features verwenden.
|
||||
4. Den öffentlichen Trust Store aus `GET /api/v1/trust-store` herunterladen.
|
||||
5. Die Datei als `internal/app/trusted_keys.json` in dieses Projekt kopieren.
|
||||
6. Produkt-Binary oder Container neu bauen.
|
||||
7. Beim Produkt nur noch `LICENSE_TOKEN` und gegebenenfalls Client-Einstellungen setzen.
|
||||
|
||||
## Nicht mehr unterstützte Konfiguration
|
||||
|
||||
Folgende Werte gehören nicht mehr zum Produktprojekt:
|
||||
|
||||
```text
|
||||
LICENSE_PUBLIC_KEY
|
||||
LICENSE_PRIVATE_KEY
|
||||
LEASE_SIGNING_PRIVATE_KEY
|
||||
LEASE_SIGNING_KEY_ID
|
||||
LICENSE_SERVER_ADMIN_TOKEN
|
||||
LICENSE_SERVER_DATA
|
||||
LICENSE_TRUST_STORE_FILE
|
||||
```
|
||||
|
||||
Eine vom alten eingebauten Server verwendete `LICENSE_SERVER_URL` muss auf die neue Universal License Platform zeigen. Neue Hybrid-/Online-Lizenzen können deren öffentliche URL bereits signiert im Token enthalten.
|
||||
@@ -0,0 +1,10 @@
|
||||
# Product and installation page
|
||||
|
||||
The public `/product` page documents features and installation paths without prices or upgrade advertising.
|
||||
|
||||
Routes:
|
||||
|
||||
- `/product` — feature and installation overview;
|
||||
- `/install` — redirects to `/product#install`.
|
||||
|
||||
The public page does not expose license administration. Runtime capabilities are available through `/v1/capabilities`; all license creation and management is handled by the separately deployed Universal License Platform.
|
||||
Reference in New Issue
Block a user