Private release previewNo live purchasesRelease details ↗

EN · ORIGINAL REPOSITORY DOCUMENT

Licensing system overview

Original English text. Commands and evidence apply to the revision and environment stated in the document.

product/licensing/README.md

On this page

Original licensing component: bounded private candidate

This directory contains an original Go entitlement backend (Go JSON persistence), a PHP public-key verification client and explicit update/download helpers. It does not modify the WordPress cache core or grant rights to upstream Object Cache Pro. No license calls run on cache reads/writes. No upstream package, payment provider, production keys or live deployment is configured.

Go is the runnable backend; service.py is retained only as a historical reference/test fixture. Read the Go operation guide, the standalone WordPress admin binding, the server contract and the PHP client contract for configuration and operation. Site origins require operator approval; each activation is bound to an installation secret. Counts are transactional. The client receives public verification keys only. Signed denials clear premium update access; outages retain the existing signed validity/grace deadlines. Local status uses no network. Cache functionality is independent.

The server’s /updates and /download endpoints serve an explicitly configured original ZIP. They recheck activation ownership, expiry and revocation when delivering bytes. The PHP helper verifies SHA-256 and never extracts or installs packages. Revocation/deactivation blocks previously issued download tokens immediately at the server. Offline clients learn new revocations only on refresh and cannot extend their signed grace deadlines.

Targeted checks

Build and test the actual backend with Go 1.24 or newer (tested with Go 1.26.1):

cd product/licensing/go
go build -buildvcs=false .
go test -race ./...
go vet ./...
# Optional real Go HTTP / PHP parity using an existing PHP Docker image:
LICENSING_PHP_DOCKER_IMAGE=<existing-php-image> go test -race -v ./...
cd ../../..
docker run --rm --network none -v "$PWD:/opt/project:ro" -w /opt/project php:8.3-apache-bookworm php product/licensing/client-test.php
docker run --rm --network none -v "$PWD:/opt/project:ro" -w /opt/project php:8.3-apache-bookworm php product/licensing/transport-test.php

The old integration_client.py runner tests the historical Python reference only; it is not the Go deployment or parity runner. It requires the official Python and PHP images locally. One labelled Python container has networking disabled; temporary PHP containers share its loopback namespace. It generates ephemeral RSA keys, synthetic licenses and an original text-only fixture ZIP, with no published ports. It tests actual HTTP ownership, signatures, package delivery, service outage/grace, revocation and denial reload, then removes its own container, keys, database and package. Reports are written to ignored build/.

Remaining commercial operation gates

Complete authenticated customer/operator administration and installation/key recovery, automated domain-ownership proof, payment/renewal/refund lifecycle, deployment TLS, private-key custody/rotation, backup/recovery and capacity before external operation. Manual origin approval represents separately obtained operator evidence. The earlier prototype database is rejected rather than inventing ownership migration.

PHP/files are controlled by their operator; the client is not uncrackable. Server-side package authorization is the commercial boundary. PHP 7.2 syntax is retained, but only PHP 8.3 runtime tests passed here. Owner-confirmed upstream reuse authorization is recorded in ../../PROVENANCE.md; this original protocol grants no upstream rights.