feat(licence): contributed manifests are CC0 1.0
Contributed manifests were in no declared condition at all, which left §9a replication with no grant flowing through it: peers mirror each other's catalogues wholesale, and every hop of that was unlicensed. CC0 rather than a share-alike licence, because a share-alike works by asserting a right in the data and then conditioning its use. The position in docs/legal-posture.md §3 is that presence timings are facts rather than protectable expression — asserting copyright in them in order to license them would contradict that argument in the same repository, and that contradiction is worth more to an opponent than the licence is worth to us. CC0 also waives the sui generis database right by name, closing the EU-specific residual exposure from the contributor's side. The grant is taken at token issuance, and that is not incidental. There are no accounts, so there is no sign-up to attach terms to, and a manifest arrives over POST /manifests with no channel to negotiate over. Acquiring the contribute capability is the only moment a grant can be made, so POST /tokens now returns the licence and its terms alongside the token — a licence the server publishes but never delivers is one no contributor agreed to. The test pins the scope limit as well as the identifier. Bounding the grant to the manifest is the half that can fail silently: a reworded term reading onto the underlying work would purport to grant what no contributor can. Also records the settled code-licence position across all four repositories in the legal posture, correcting an earlier claim there that the plugin and extraction repos declared nothing. Both already carried LICENSE files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> TRACES: UR-019 | PR-006
This commit is contained in:
+28
-2
@@ -209,9 +209,26 @@ pub async fn post_bundle(
|
||||
Ok(with_quota_headers(resp, quota))
|
||||
}
|
||||
|
||||
/// SPDX identifier of the licence a contributed manifest is placed under (§5b).
|
||||
pub const CONTRIBUTION_LICENSE: &str = "CC0-1.0";
|
||||
|
||||
/// The grant a contributor makes, in the words §5b specifies.
|
||||
///
|
||||
/// Scope is the operative part: it covers *the manifest*, and cannot purport to
|
||||
/// license the underlying work, which is not the contributor's to license and
|
||||
/// which this server does not hold.
|
||||
pub const CONTRIBUTION_TERMS: &str = "Contributing a manifest places its content \
|
||||
— timings, identifiers and audio signature — under CC0 1.0 Universal. This \
|
||||
covers the manifest only. It does not, and cannot, license the underlying \
|
||||
work, which the contributor does not own and this server does not hold.";
|
||||
|
||||
#[derive(Debug, Serialize)]
|
||||
pub struct TokenIssued {
|
||||
pub token: String,
|
||||
/// Delivered with the capability, not merely published: a licence the server
|
||||
/// declares unilaterally is not one any contributor granted (§5b).
|
||||
pub contribution_license: &'static str,
|
||||
pub contribution_terms: &'static str,
|
||||
}
|
||||
|
||||
/// Issues an anonymous bearer capability (§5a).
|
||||
@@ -220,7 +237,12 @@ pub struct TokenIssued {
|
||||
/// only as a hash, so the server cannot enumerate who holds tokens. Discarding a
|
||||
/// token and requesting another is trivially easy — and that is fine, because the
|
||||
/// token is not the defence; the content checks are.
|
||||
/// TRACES: UR-005 | SR-004
|
||||
///
|
||||
/// The response carries the §5b contribution licence. This is the only moment
|
||||
/// the server can obtain a grant: there are no accounts, so there is no sign-up
|
||||
/// to attach terms to, and a manifest arrives with no channel to negotiate over.
|
||||
/// Acquiring the capability is therefore where the grant has to be made.
|
||||
/// TRACES: UR-005, UR-019 | SR-004 | PR-006
|
||||
pub async fn post_token(
|
||||
State(state): State<AppState>,
|
||||
peer: crate::state::PeerIp,
|
||||
@@ -240,5 +262,9 @@ pub async fn post_token(
|
||||
.await
|
||||
.map_err(ApiError::Internal)?;
|
||||
|
||||
Ok(Json(TokenIssued { token }))
|
||||
Ok(Json(TokenIssued {
|
||||
token,
|
||||
contribution_license: CONTRIBUTION_LICENSE,
|
||||
contribution_terms: CONTRIBUTION_TERMS,
|
||||
}))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user