1.6 KiB
1.6 KiB
Application License Removal Audit
Date: 2026-07-02
Decision
The application-level offline license gate has been removed. The system now relies on login sessions, role checks, audit logging, deployment network controls, and operation-level guards. LandSAR vendor license configuration is not part of this removal and remains required for LandSAR production runtimes.
Removed Scope
- Global FastAPI license dependency and
/api/license/*routes. - Backend LIC2 verification service and bundled license issuer tools.
- Frontend license status store fields, license overlay, login-page license warning, and header license chip.
- Deployment example variable
LICENSE_PATH. - Audit-log display labels for removed license upload/refresh actions.
Preserved Scope
- User authentication and session cookie flow.
- Admin versus read-only write protection.
- High-risk write audit logging.
- LandSAR runtime license settings such as
LANDSAR_LICENSE_MODE,LANDSAR_LICENSE_HOST, andLANDSAR_LICENSE_PORT.
Operational Result
Startup and API availability no longer depend on a local .lic file or issuer-generated public/private key material. Removing the gate also removes a misleading security boundary: application access control must be handled by account roles, network exposure, and deployment policy rather than a local offline license file.
Follow-up Checks
- Keep
.envand initial admin credentials out of deployable artifacts. - Keep LandSAR license server settings documented as vendor runtime requirements, not application authorization.
- Continue using the operations maintenance panel for failed task cleanup and audit review.