evcc-io/FORK.md
Stefan 13215c74c2
Some checks failed
CodeQL / Analyze (go) (push) Failing after 1m16s
CodeQL / Analyze (actions) (push) Failing after 4s
CodeQL / Analyze (javascript-typescript) (push) Failing after 7s
Default / Clean (push) Has been cancelled
Default / Build (push) Has been cancelled
Default / Test (push) Has been cancelled
Default / Lint (push) Has been cancelled
Default / UI (push) Has been cancelled
Default / Integration (push) Has been cancelled
Default / Warm fork cache (Go) (push) Has been cancelled
Default / Warm fork cache (UI) (push) Has been cancelled
Remove sponsor token gating
Unlock all locally gated features without a sponsor token. The change sits
in util/sponsor/auth.go instead of the ~68 device constructors:

- Subject defaults to a non-empty value, so RedactedStatus reports an active
  sponsorship and the frontend unlocks isSponsor
- IsAuthorized always returns true, opening every caller including the
  modbus proxy and the optimizer gate
- ConfigureSponsorship still validates a configured token but never fails,
  so an expired token no longer aborts startup

Drops TestAlpitronicSponsorGate and TestSigenergyEVDCSponsorGate, which
asserted exactly the gate that is removed here.

Cloud-backed services (optimizer API, remote access, cloud vehicles,
telemetry) still require a real token - those are checked server side.

See FORK.md.
2026-08-30 10:41:18 +02:00

54 lines
2.1 KiB
Markdown

# Fork-Hinweise
Fork von [evcc-io/evcc](https://github.com/evcc-io/evcc).
## Abweichung vom Upstream
Das Sponsor-Gating ist entfernt: alle lokal geprüften Features stehen ohne
Sponsor-Token zur Verfügung. Der Eingriff sitzt an einer einzigen Stelle in
`util/sponsor/auth.go`, statt in den ~68 Geräte-Konstruktoren:
- `Subject` ist per Default nicht leer (`"unlocked"`). Damit meldet
`RedactedStatus()` einen aktiven Sponsor-Status, und das Frontend schaltet
`isSponsor` (`assets/js/views/Config.vue`) frei — Geräte-Dialoge zeigen kein
„Sponsor-Token erforderlich" mehr.
- `IsAuthorized()` liefert immer `true`. Das öffnet alle Aufrufer, u. a. die
Charger-/Vehicle-Konstruktoren, `server/modbus/proxy.go` und den
Optimizer-Gate in `core/site_optimizer.go`.
- `ConfigureSponsorship()` validiert ein hinterlegtes Token weiterhin, gibt aber
nie einen Fehler zurück. Ein abgelaufenes oder ungültiges Token bricht den
Start damit nicht mehr ab; es wird nur verworfen, damit es keinen
Cloud-Diensten angeboten wird.
Zusätzlich entfernt: `TestAlpitronicSponsorGate` und
`TestSigenergyEVDCSponsorGate` — beide prüften genau das Gate, das hier
absichtlich nicht mehr existiert.
## Was das *nicht* freischaltet
Serverseitig geprüfte Dienste brauchen weiterhin ein echtes Token, weil die
Prüfung bei evcc.io stattfindet und nicht im Client:
- Optimizer-API (`core/site_optimizer.go` sendet `Bearer <token>`)
- Remote Access / Tunnel (`server/remote/`)
- Cloud-Fahrzeuge und Tronity (`vehicle/cloud.go`, `vehicle/tronity.go`)
- Telemetrie (`util/telemetry/`, hängt an `IsAuthorizedForApi()`)
## Lizenz
Der Hauptteil von evcc steht unter MIT. `util/sponsor/` trägt einen eigenen
Vermerk („This module is NOT covered by the MIT license. All rights reserved.").
Diese Änderung betrifft genau dieses Modul.
evcc finanziert sich über Sponsoring: <https://sponsor.evcc.io>
## Upstream-Sync
```
git remote add upstream https://github.com/evcc-io/evcc.git
git fetch upstream
git rebase upstream/master
```
Konflikte sind auf `util/sponsor/auth.go` beschränkt; `FORK.md` liegt bewusst
außerhalb der Upstream-Dateien.