Part of #334.
Decision
Relicense the whole ecosystem from AGPL-3.0-only to Apache-2.0: the API, the SDKs, types, CLI, templates, messaging, admin dashboard and docs.
The SDKs are the main reason. @seamless-auth/react, client, core, express, fastify and types are all AGPL-3.0-only today and get bundled or linked into the adopter's own application, which most company and government legal reviews will block. Apache-2.0 over MIT for the explicit patent grant, which those same reviewers look for.
Before changing any file
External contributors hold copyright in their contributions and have to agree to the change (or those contributions are rewritten). From git log:
| Repo |
Contributors other than the maintainer |
| seamless-auth-react |
Peter (12 commits), nightcityblade (1), kcorbettsr (1) |
| seamless-cli |
Bharat Bhojwani (1) |
| seamless-auth-docs |
Peter (11 commits) |
Per repo
For each of seamless-auth-api, seamless-auth-server, seamless-auth-react, seamless-auth-types, seamless-cli, seamless-templates, seamless-auth-messaging, seamless-auth-admin-dashboard, seamless-auth-docs:
Known leftovers to clean up on the way: seamless-auth-react/LICENSE.md still has template boilerplate, and seamless-auth-server/packages/fastify/LICENSE.md calls itself the Express package.
Outside the repos
Part of #334.
Decision
Relicense the whole ecosystem from AGPL-3.0-only to Apache-2.0: the API, the SDKs, types, CLI, templates, messaging, admin dashboard and docs.
The SDKs are the main reason.
@seamless-auth/react,client,core,express,fastifyandtypesare allAGPL-3.0-onlytoday and get bundled or linked into the adopter's own application, which most company and government legal reviews will block. Apache-2.0 over MIT for the explicit patent grant, which those same reviewers look for.Before changing any file
External contributors hold copyright in their contributions and have to agree to the change (or those contributions are rewritten). From
git log:Per repo
For each of
seamless-auth-api,seamless-auth-server,seamless-auth-react,seamless-auth-types,seamless-cli,seamless-templates,seamless-auth-messaging,seamless-auth-admin-dashboard,seamless-auth-docs:LICENSE/LICENSE.mdwith the Apache-2.0 text (and remove duplicates; several repos have both)licensefield in everypackage.json, including workspace packages (some are missing it entirely)Known leftovers to clean up on the way:
seamless-auth-react/LICENSE.mdstill has template boilerplate, andseamless-auth-server/packages/fastify/LICENSE.mdcalls itself the Express package.Outside the repos