aboutsummaryrefslogtreecommitdiff
path: root/internal/web/server.go
diff options
context:
space:
mode:
authorLukasz Kasprzak <lukas@labunix.xyz>2026-07-28 14:02:54 +0200
committerLukasz Kasprzak <lukas@labunix.xyz>2026-07-28 14:02:54 +0200
commit0586599fc6020df996c4278230eeea99b9d070cb (patch)
treea03b615039243f84fa2d69430b769676d1da9135 /internal/web/server.go
parent44472bbe31475a3c672ae003d928d7caffb4b50a (diff)
downloadlectio-0586599fc6020df996c4278230eeea99b9d070cb.tar.gz
lectio-0586599fc6020df996c4278230eeea99b9d070cb.zip
licence: relicense MIT -> AGPL-3.0-or-later
lectio was MIT, which let anyone take it closed. The concern is not people selling it -- no licence stops that, and the AGPL does not try to -- but someone building a proprietary product on it and giving nothing back. Plain GPL would leave the obvious hole open: lectio-web is a network service, and hosting is not distribution, so a modified lectio-web could be run as a paid subscription API without ever publishing a line. AGPL section 13 closes exactly that. LICENSE is the verbatim FSF text. README carries the standard notice. Section 13 requires a modified network-reachable version to PROMINENTLY offer its source to the users interacting with it, so the offer ships with the code rather than living only in a file nobody fetches: - GET /source plain text, no template or config dependency, so it answers even when something else is broken - page footers every full page (fragments render inside one) - JSON envelope "source" / "license" - iCal header X-LECTIO-SOURCE / X-LECTIO-LICENSE The feed fields are not redundant: an /api/calendar.json consumer or an .ics subscriber never loads a page, so the footer alone would miss them. config.SourceURL is the single source of truth, and says in its comment that a fork running as a service must repoint it -- an offer that leads to someone else's code is not an offer. Tests pin all of it. This is a licence obligation, not a feature, so it should fail loudly if a later change drops it.
Diffstat (limited to 'internal/web/server.go')
-rw-r--r--internal/web/server.go27
1 files changed, 27 insertions, 0 deletions
diff --git a/internal/web/server.go b/internal/web/server.go
index 6e76d3f..92cb758 100644
--- a/internal/web/server.go
+++ b/internal/web/server.go
@@ -74,6 +74,7 @@ func NewServer(cfg config.Config) http.Handler {
mux.HandleFunc("GET /calendar.ics", func(w http.ResponseWriter, r *http.Request) { calendarICSHandler(s.get())(w, r) })
mux.HandleFunc("GET /reader", func(w http.ResponseWriter, r *http.Request) { readerHandler(s.get(), s.table())(w, r) })
mux.HandleFunc("GET /theme.css", func(w http.ResponseWriter, r *http.Request) { themeCSSHandler(s.get())(w, r) })
+ mux.HandleFunc("GET /source", sourceHandler)
mux.HandleFunc("GET /settings", settingsGet(s))
mux.HandleFunc("POST /settings", settingsPost(s))
mux.HandleFunc("POST /reader/bookmark", addBookmark(s))
@@ -691,6 +692,32 @@ func themeCSSHandler(cfg config.Config) http.HandlerFunc {
}
}
+// sourceHandler serves the AGPL-3.0 §13 source offer: where to obtain the
+// code this server is running. Every page footer links here, so a user
+// interacting with lectio-web over a network is never more than one click
+// from the corresponding source.
+//
+// Deliberately dependency-free (no template, no config read): it must answer
+// even when config is broken or a template failed to parse, because a §13
+// offer that only works on healthy days is not an offer. Plain text keeps it
+// readable by both a browser and curl.
+func sourceHandler(w http.ResponseWriter, r *http.Request) {
+ w.Header().Set("Content-Type", "text/plain; charset=utf-8")
+ w.Header().Set("X-Content-Type-Options", "nosniff")
+ fmt.Fprintf(w, `lectio %s
+Licence: %s (GNU Affero General Public License, version 3 or later)
+Source: %s
+
+lectio is free software. You may use, study, share and modify it under the
+terms of the AGPL. The full licence text ships with the source as LICENSE.
+
+Because this is the Affero GPL, section 13 applies to this server: if the
+code running here has been MODIFIED, whoever operates it must offer you the
+modified source. If this address does not lead to the version you are
+talking to, that is the operator's obligation to fix, not lectio's.
+`, config.Version, config.License, config.SourceURL)
+}
+
// settingsData drives templates/settings.html.
type settingsData struct {
Cfg config.Config