Commit Graph
3 Commits
Author SHA1 Message Date
Divarion_D bd54afa16b feat(integrity): lock panel UI when AGPL attribution is removed
Adds a disclosed, reversible attribution-integrity check (AGPL-3.0 §7(b)).
The "Vateron Media · AGPL-3.0" credit now has a single source
(AdminHelpers::getAttribution(), reused by getFooter). AttributionGuard
verifies its markers; AttributionVerificationStage runs the check on the
Admin (UI) boot profile only — admin/reseller/player panels — and calls
generateError('ATTRIBUTION_REMOVED') when the notice is gone.

Scope is deliberately UI-only: streaming is NOT gated, so removing a UI
footer cannot cut off a reseller's end-viewers (that is the licence
layer's concern). The lock is non-destructive and auto-reverses — the CLI
stays usable and restoring the notice unlocks the panel on the next
request. Enforcement is documented in README (License Enforcement).

This is a readable-PHP deterrent (a determined actor can remove the check
with the notice); tamper-resistant enforcement belongs in the compiled
xcvm_core extension (planned).

Tests: attribution markers, hasMarkers tamper detection, CLI self-skip,
UI-only wiring, error-code registration. Full suite + gates + CRAP green.
2026-09-18 15:10:43 +03:00
Divarion_D 4ea916ab89 fix(bootstrap): address Sourcery review — WebApi profile guard, falsy http code, getBool
Three fixes from the automated PR review:

- ErrorResponder::respondError() used `$httpCode === null` where the legacy
  generateError() used `!$rCode`; a caller passing 0 now falls through to the 404
  page again instead of emitting http_response_code(0). (+ test)
- StageProfiles::for(BootContext::WebApi) now throws instead of silently building
  a wrong stage list from the common prefix/suffix — WebApi boots via
  WebApiBootstrap, never the kernel. (+ test)
- LegacyCoreStage reads enable_cache via SettingsManager::getBool() (the typed
  getter the Web API path used), rather than the raw get(). Behaviour is
  equivalent (`!` already coerces) but the intent is clearer.
2026-09-16 18:57:54 +03:00
Divarion_D 6a39902fbf refactor(bootstrap): add ConstantsInitializer + ErrorResponder PSR-4 classes
Introduce the source-of-truth classes for the bootstrap testability refactor.
Purely additive — nothing is wired to them yet.

- ConstantsInitializer: pure value maps (paths/appConfig/binaries/statuses)
  plus the single define() site (init/initStatus). The maps evaluate with
  different MAIN_HOME/BIN_PATH in one process, which the one-shot define()
  constants they feed cannot — this is what makes them testable.
- ErrorResponder: the generateError()/generate404() logic extracted into pure
  codes()/renderDebug()/render404()/respond*() plus a single side-effecting
  emit(). A test-mode toggle throws ErrorResponseException instead of exit().
- ErrorResponseException: value carrier for a resolved error response.

OPENSSL_EXTRA is now sourced per-install via ConfigReader with a mandatory
fallback to the historical literal, so existing installs (whose persisted data
derives from it) keep decrypting; generation-at-install is left to the installer.

Verified byte-for-byte against the legacy prelude before wiring: 53/53 constants,
debug/404 HTML frozen as sha256 goldens, 65 error codes.
2026-09-16 16:34:02 +03:00