Three things a licence audit turned up. None of them is a conflict -- every one of the 182 installed packages is permissive, and the relicence was within the copyright holder's gift -- but all three are ways the AGPL fails to stick. The offer was hard-coded to this repository. Section 13 asks whoever runs a modified version to offer *that* version's source, so every deployment with a patch in it was pointing at the wrong tree, and would have gone on doing so unless its operator noticed and edited the About page. SOURCE_URL now sets it, alongside APP_NAME, and both the sign-in page and About read it. The offer was also only visible after signing in. Whoever is looking at the sign-in form is interacting with the program over a network too, so the footer carries it now. And the two workspace packages declared no licence at all. Private, so npm never minded, but anything reading the tree saw a blank where the rest of the project says AGPL-3.0-or-later. Checked both ways round: with SOURCE_URL set to a fork, the sign-in page and About both point at the fork; with it unset, both fall back to this repository.
9 lines
379 B
TypeScript
9 lines
379 B
TypeScript
/**
|
|
* Where to point someone who wants this instance's source.
|
|
*
|
|
* The AGPL asks whoever runs a modified version to offer *that* version's
|
|
* source. The server says where its own lives, via SOURCE_URL; this is only the
|
|
* fallback for when it has not been asked yet, or has nothing to say.
|
|
*/
|
|
export const DEFAULT_SOURCE_URL = "https://github.com/LINUXexpert-org/ihasmail";
|