Remove sponsor token gating
Some checks failed
CodeQL / Analyze (go) (push) Failing after 1m16s
CodeQL / Analyze (actions) (push) Failing after 4s
CodeQL / Analyze (javascript-typescript) (push) Failing after 7s
Default / Clean (push) Has been cancelled
Default / Build (push) Has been cancelled
Default / Test (push) Has been cancelled
Default / Lint (push) Has been cancelled
Default / UI (push) Has been cancelled
Default / Integration (push) Has been cancelled
Default / Warm fork cache (Go) (push) Has been cancelled
Default / Warm fork cache (UI) (push) Has been cancelled

Unlock all locally gated features without a sponsor token. The change sits
in util/sponsor/auth.go instead of the ~68 device constructors:

- Subject defaults to a non-empty value, so RedactedStatus reports an active
  sponsorship and the frontend unlocks isSponsor
- IsAuthorized always returns true, opening every caller including the
  modbus proxy and the optimizer gate
- ConfigureSponsorship still validates a configured token but never fails,
  so an expired token no longer aborts startup

Drops TestAlpitronicSponsorGate and TestSigenergyEVDCSponsorGate, which
asserted exactly the gate that is removed here.

Cloud-backed services (optimizer API, remote access, cloud vehicles,
telemetry) still require a real token - those are checked server side.

See FORK.md.
This commit is contained in:
Stefan 2026-08-30 10:41:18 +02:00
parent d379b7802e
commit 13215c74c2
4 changed files with 86 additions and 31 deletions

View file

@ -35,10 +35,15 @@ import (
"google.golang.org/grpc/status"
)
// unlocked is the sponsorship subject used by this fork. Sponsor gating is
// removed here, so Subject is never empty and IsAuthorized always holds.
const unlocked = "unlocked"
var (
mu sync.RWMutex
Subject, Token string
ExpiresAt time.Time
mu sync.RWMutex
Subject = unlocked
Token string
ExpiresAt time.Time
)
func machineID() string {
@ -51,9 +56,8 @@ const unavailable = "sponsorship unavailable"
const startupTimeout = 30 * time.Second
func IsAuthorized() bool {
mu.RLock()
defer mu.RUnlock()
return len(Subject) > 0
// sponsorship gating removed in this fork
return true
}
func IsAuthorizedForApi() bool {
@ -62,8 +66,29 @@ func IsAuthorizedForApi() bool {
return IsAuthorized() && Subject != unavailable && Token != ""
}
// check and set sponsorship token
// ConfigureSponsorship validates a sponsor token when one is configured, but
// never fails: sponsorship is not required in this fork. A valid token is
// still picked up so cloud-backed services keep working for real sponsors.
func ConfigureSponsorship(token string) error {
err := configureSponsorship(token)
mu.Lock()
defer mu.Unlock()
if err != nil {
// stay unlocked, but do not offer a rejected token to cloud services
Token = ""
}
if Subject == "" {
Subject = unlocked
}
return nil
}
// check and set sponsorship token
func configureSponsorship(token string) error {
mu.Lock()
defer mu.Unlock()