EN · ÖZGÜN DEPO BELGESİ
Sunucu API sözleşmesi
Özgün İngilizce metin. Komutlar ve kanıtlar, belgede belirtilen revizyona ve ortama aittir.
product/licensing/README.server.md
Bu sayfada
Owned installation and original package server prototype
The Go backend implements the runnable local server; service.py
is retained as a historical Python reference/test fixture. The Go backend has mandatory operator-approved origins,
installation ownership, RSA-SHA256 signed entitlements and protected delivery of
an explicitly configured original ZIP. It does not grant distribution rights
to upstream Object Cache Pro software. Test packages contain synthetic original
text only. There is no configured package by default, no upstream download, no
payment provider and no deployment. The cache core has no dependency on this service.
Contract
Every POST takes exactly license_key, site and installation_key as JSON.
Both bearer keys must have 32..256 characters. Sites normalize to HTTPS origins,
without path, credentials, query or fragment. The operator first approves an
origin per license using independently obtained ownership evidence. The server
never fetches user-supplied URLs. Automating domain proof is a remaining gate.
/activate creates ownership binding using SHA-256 digests of both keys. A flock-serialized Go JSON snapshot
serializes activation counts. The same installation can reactivate idempotently;
a different installation cannot check, deactivate, request entitlements or
updates for the owned origin. /deactivate frees a slot while retaining ownership.
Installation replacement/recovery requires a future authenticated operator flow.
/check returns live activation state, rejecting expired/revoked licenses.
/entitlement returns HTTP 200 with {payload, sig, kid:"fixture-v1"}. Payload
and signature are Base64URL without padding; RSA-SHA256 signs decoded raw JSON
bytes, not the encoded string. The client receives only the public verification
key. Claims are:
aud: "original-product-entitlement", normalizedsite, SHA-256licenseandinstallation, andstatus: "active"|"revoked"|"inactive"|"expired".- Integer
issued_at,refresh_after,expires_at,grace_until. - Active refresh is at most 300 seconds, validity at most 3600 seconds and grace at most another 3600 seconds. All are capped by the underlying license expiry.
- Signed denial for an already bound identity has all timestamps equal to now. A verified denial can invalidate a cached entitlement immediately. Wrong owner, unapproved origin or unknown license gets unsigned HTTP 403; signer outage gets unsigned HTTP 503. Neither is authority to extend cached grace.
/updates requires a live active owned installation and returns configured
version, immutable ZIP sha256 and download_token. Tokens last at most five
minutes and never outlive the underlying license. GET /download accepts the token
in Authorization: Bearer .... It verifies its server-only HMAC, audience, site,
installation, expiry, live activation, revocation and configured package digest,
then returns the ZIP snapshot read at startup. Revocation/deactivation blocks
previously issued tokens at the server immediately. No external download URL or
upstream artifact can be requested. The ZIP owner must establish its own rights.
Local operation
Build and configure the Go backend; it runs without Python, SQLite or an OpenSSL executable. Supply server-only HMAC material through the operator environment and an RSA private PEM through an explicit local path. Use a fresh Go JSON state file: Python SQLite ownership is not silently migrated. The Go guide includes build, issue, origin approval, revoke and serve commands. It also documents whole-state locking, capacity bounds and local-filesystem limits.
The listener binds 127.0.0.1 only. Issuance/revocation/origin approval are local
operator actions, not public HTTP endpoints or payment verification. Private-key
custody, authenticated administration and key rotation remain deployment gates.
Focused Go race tests cover the server contracts; a real Go HTTP/PHP fixture covers signature verification, fixed outage/grace limits and package bytes. A separate actual WordPress admin/Go fixture covers explicit administrative operations and persisted signed denial. The retained Python tests and runner serve only as historical reference evidence.
Before external operation, complete payment renewal/refund/webhook idempotency, authenticated ownership verification and recovery, TLS delivery, operator audit, backup/recovery and capacity constraints. PHP can be modified by its operator; protect package delivery on the server and do not claim an uncrackable client.