From 0586599fc6020df996c4278230eeea99b9d070cb Mon Sep 17 00:00:00 2001 From: Lukasz Kasprzak Date: Tue, 28 Jul 2026 14:02:54 +0200 Subject: licence: relicense MIT -> AGPL-3.0-or-later lectio was MIT, which let anyone take it closed. The concern is not people selling it -- no licence stops that, and the AGPL does not try to -- but someone building a proprietary product on it and giving nothing back. Plain GPL would leave the obvious hole open: lectio-web is a network service, and hosting is not distribution, so a modified lectio-web could be run as a paid subscription API without ever publishing a line. AGPL section 13 closes exactly that. LICENSE is the verbatim FSF text. README carries the standard notice. Section 13 requires a modified network-reachable version to PROMINENTLY offer its source to the users interacting with it, so the offer ships with the code rather than living only in a file nobody fetches: - GET /source plain text, no template or config dependency, so it answers even when something else is broken - page footers every full page (fragments render inside one) - JSON envelope "source" / "license" - iCal header X-LECTIO-SOURCE / X-LECTIO-LICENSE The feed fields are not redundant: an /api/calendar.json consumer or an .ics subscriber never loads a page, so the footer alone would miss them. config.SourceURL is the single source of truth, and says in its comment that a fork running as a service must repoint it -- an offer that leads to someone else's code is not an offer. Tests pin all of it. This is a licence obligation, not a feature, so it should fail loudly if a later change drops it. --- internal/web/server.go | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) (limited to 'internal/web/server.go') diff --git a/internal/web/server.go b/internal/web/server.go index 6e76d3f..92cb758 100644 --- a/internal/web/server.go +++ b/internal/web/server.go @@ -74,6 +74,7 @@ func NewServer(cfg config.Config) http.Handler { mux.HandleFunc("GET /calendar.ics", func(w http.ResponseWriter, r *http.Request) { calendarICSHandler(s.get())(w, r) }) mux.HandleFunc("GET /reader", func(w http.ResponseWriter, r *http.Request) { readerHandler(s.get(), s.table())(w, r) }) mux.HandleFunc("GET /theme.css", func(w http.ResponseWriter, r *http.Request) { themeCSSHandler(s.get())(w, r) }) + mux.HandleFunc("GET /source", sourceHandler) mux.HandleFunc("GET /settings", settingsGet(s)) mux.HandleFunc("POST /settings", settingsPost(s)) mux.HandleFunc("POST /reader/bookmark", addBookmark(s)) @@ -691,6 +692,32 @@ func themeCSSHandler(cfg config.Config) http.HandlerFunc { } } +// sourceHandler serves the AGPL-3.0 §13 source offer: where to obtain the +// code this server is running. Every page footer links here, so a user +// interacting with lectio-web over a network is never more than one click +// from the corresponding source. +// +// Deliberately dependency-free (no template, no config read): it must answer +// even when config is broken or a template failed to parse, because a §13 +// offer that only works on healthy days is not an offer. Plain text keeps it +// readable by both a browser and curl. +func sourceHandler(w http.ResponseWriter, r *http.Request) { + w.Header().Set("Content-Type", "text/plain; charset=utf-8") + w.Header().Set("X-Content-Type-Options", "nosniff") + fmt.Fprintf(w, `lectio %s +Licence: %s (GNU Affero General Public License, version 3 or later) +Source: %s + +lectio is free software. You may use, study, share and modify it under the +terms of the AGPL. The full licence text ships with the source as LICENSE. + +Because this is the Affero GPL, section 13 applies to this server: if the +code running here has been MODIFIED, whoever operates it must offer you the +modified source. If this address does not lead to the version you are +talking to, that is the operator's obligation to fix, not lectio's. +`, config.Version, config.License, config.SourceURL) +} + // settingsData drives templates/settings.html. type settingsData struct { Cfg config.Config -- cgit v1.3