LICENSE became AGPL-3.0-only in 037eb24, but both READMEs still told readers
the project was MIT — the one place a user actually looks before deciding what
they may do with it. The two "license notes" underneath were MIT-shaped as
well: attribution and a disclaimer, with no mention of copyleft at all.
They now say what AGPL actually requires, including section 13, which is the
clause that matters most here: Felis is a hosting platform reached over a
network, so a modified deployment owes its source to the people using it even
if no binary is ever distributed. Leaving that unsaid was the part that could
mislead someone into a violation they never intended.
The documented one-liner fetches bootstrap.sh from raw.githubusercontent.com
unauthenticated, which 404s for as long as this repository stays private -- so
the single command the README exists to provide did not work for anyone.
The authenticated form goes through the contents API with the raw media type,
matching what github_api already does, and hands the token to curl over stdin
via --config rather than -H. argv is world-readable through /proc, and a token
on the command line would leak to any local user during the install; bootstrap
avoids that in its own fetches for the same reason and the README should not
teach the opposite.
sudo -E, because the installer needs that same token to resolve and download the
release. Without it sudo drops the variable and the run fails later, at the
release lookup, for a reason the operator has no way to connect to this command.
The public one-liner stays first: it is what this becomes once the repository is
public, and the note is scoped to the current state.
Also records that re-running the installer is how felis-api moves to a newer
release, that it now keeps the installed root domain, and that it does not keep
the channel.