I didn't get paid, so I open-sourced my client’s project
github.com
github.com
That voids Bank of America's security guarantee.[1] If you provide info for an ACH transfer, and the other party abuses that info, it's reversible. If you provide login info and the other party abuses that info, it's not.
[1] https://www.bankofamerica.com/online-banking/online-banking-...
I don’t like it either, but I’m not sure how you could get archaic banks and low-tech consumers to adopt something better.
It won't take much in terms of negative outcomes generated by increased attack surface to make bank/financial regulations even more strict.
This practice is a clear violation of just about every bank I've seen's security policy. Normal practice would be to negotlate a data sharing of some sort, but that happening would be dependent on your company's ability to generate increased visibility for, or traffic to the bank.
Anyway, tread carefully
Your business with the bank entitles you, and only you; barring certain exceptions at their discretion, access to that data.
They do this to minimize risk and culpability in the face of a large number of adversaries that could extract value from possession of data on your personal habits.
It isn't sexy, but that is just the way it works. I've banged my head against the financial industry looking for ways to improve it, but at the end of the day, a lot of the rules and restrictions they put in place actually do make a frustratingly good deal of sense.
Think about this.
Suppose you and 1000000 other people hand login credentials for financial service X to company Y.
Company Y is basically a shell company wrapping a money laundering operation. Your combined set of login credentials becomes an ideal way to wash money into the financial system until everyone else in the financial network catches on. Then that company disappears, and sets up under a different name.
This stuff happens; and even if only some people don't notice, that's all it takes.
Laws that require banks to provide APIs so that any other service, including other banks, can consume the user's banking data.
I'm working with a fintech company in Germany at the moment that asks users for their internet banking credentials. Apparently it's quite common in Germany.
We're taking about end-users utilizing a third party service to get some kind of visualisation for their Bank accounts.
While German banks have a standardized API (FinTS), the normal authentication details are still necessary in order to use it, so basically all third party services demand them for that.
The only place where oauth2 is used is for single sign on between services of the same company and maybe - very rarely - you also get social auth from Facebook or similar.
No bank I've ever seen ever provided a public oauth API with which you could fetch data.
The instructions asked me to provide account, card number and OTP login code... then it’s just a matter of scraping all my past 10 years transactions and keep the session alive to snoop on exactly how many condoms I buy...
Criminals
I've sometimes used giropay, though, which does the same, only directly through your bank's online banking interface. So you're interacting with your bank, not a third party; but that third party gets confirmation about the transfer. Still more of a hassle than direct withdrawal ...
- using a service like PayU or Przelewy24 that have accounts in every major bank (in-bank transfers are immediate), use bank API to initiate the transfer and provide a confirmation to the merchant when the money arrives on their account (they often allow manual or post-office transfer as a fallback, and Blik too)
- using a service like Blik, which is directly integrated with the bank
- using bank APIs directly
The first option is basically as wide-spread as credit card support; direct withdrawals pretty much don't exist there. A service that would ask for your banking login data and OTPs is unthinkable for me.
No way anyone's ever getting my bank credentials, even though anything important is approved by phone. It's like giving someone the keys to your home and cash safe, and telling them to be careful with it please :)
There is no defensible need for anything else
I remeber that banks were very much opposed to that service when they started out, warning people off (against the banks ToS, grounds for sccount termination etc.) and trying to block Sofort from their servers. I honestly don't know how the banks were placated in the end.
because after many years into sofort, they still couldn't provide a modern authentiation flow for external services. like openid.
Dutch banks are behind in many things, but this is not one.
Luckily for the German merchant, they also provided an IBAN I could copy-paste into the transfer form.
So it would seem obvious that they want customers to give out their passwords so they become victims of fraud, only to then learn that the bank has excellent fraud protection (contrary to let's say cryptocurrencies).
That is pure speculation of course. Hanlon's Razor would suggest "banks are too stupid to implement good auth", which, having worked both outside and inside the banking industry, I would strongly agree with.
Playing fast and loose with security because the bank will be on the hook (at financial cost to the bank) does not seem like a moral or ethical thing to do, and banks would be likely to pull transaction reversion from anyone who tried to use it as a feature.
Banks won't cover you for fraud that ends up happening because of you handing your online banking password to someone and rightly so.
When they do cover you, it'll be because they have a professional relationship with Plaid and/or they rely on other auth methods such as EMV CAP.
Edit: if anyone is interested it looks like it’s an EU directive https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
When I created this product [1], it required the end user's bank credentials. (I am using the past tense because I don't know if it does that anymore -- I'm not working there nowadays.)
I was sure that was an insane idea, as nobody was going to give us their user and password and let us log on to their banks as the clients. (To be honest, we were using an Intuit API which might have prevented us from creating transactions, but I could still have saved them and used them outside the API.)
When I left (for unrelated reasons), they had a few thousand clients.
[0]: https://docs.youneedabudget.com/article/142-troubleshooting
Banks need to provide APIs, IMO.
And to be clear, the app itself never has access to your credentials. This all happens in an iframe that tokenizes your credentials.
My bank considers transactions done using login credentials to be final. There is no recourse if someone steals your money.
Last year an iOS mail application called "Spark" (otherwise a great app) decided to quietly upload my login and password to their cloud servers so that their servers can access my mail for me. I dropped the app immediately (https://jan.rychter.com/enblog/spark-email-app-why-i-dont-us...).
This should not be considered acceptable. If you want to let users authorize external access to account data, use Oauth2.
Sandboxes are already available under reasonable terms for many banks in for example Ireland.
*edit, first word
(disclaimer: I work here)
I found this unacceptable, so I can't use Spark, which I regret. I also lost trust for Readdle, so now, even though they make great apps, I am extra careful with handing them any sensitive information.
AFAIK Spark’s push notification service relies on checking for mail server-side (so that they don’t drain your battery with constant background refreshes, I suppose?), so I wouldn’t consider it sneaky.
An my accounts do that by default (France), except for pre-approved recipients.
I don't know why it isn't well-advertised, I wouldn't use it otherwise.
2) The Cash app only has my routing number and account number.
3) PayPal only has my routing number and account number.
4) My credit card only has my bank’s routing and account number.
Despite these restrictions, the world keeps on spinning round and round.
That's way too much enthusiasm for the new and shiny app, way too little awareness that in this world people are out to get what's yours, way too little concern for questionable security at every single layer of computing, way too much trust in the banking system, way too careless about the information about you that you give to strangers.
Not something that people I know who are good with money would do.
It's also security lunacy to allow apps unfettered access to your accounts, acting as you.
This is why in Europe we have stuff like PSD2 in the works...
Assuming that your contract leaves you with copyright until you’re paid you could always have dmca’d them when they deployed. But that’s the vindictive side of me :D
Why would this matter? If he's not paid, what validity does the contract have?
What does this mean? The contract is valid absent payment.
A contract has to have consideration for both parties to be a valid contract, but a promise of payment is a perfectly valid consideration and would make the contract valid.
The promise of payment is the consideration. A contract is literally an exchange of promises. When you go into a car dealership and buy a car, they are exchanging a promise (you get a car!) for your promise to pay them.
The refusal to pay is a failure to live up to the promise - that is what makes it a breach of contract. If not paying meant consideration didn’t exist, then nobody would be able to sue for breach of contract for non-payment. If breach meant the contract was invalid, you wouldn’t be able to enforce the contract.
The promise of payment itself is consideration. The refusal to honor that promise is the breach of the contract. The contract itself doesn't become invalid because one party breaches the contract. Again, such an interpretation would fully the entire purpose of contract law.
The question is really whether it is IP transfer on final payment or not. If the contract specifies IP is transferred only on final payment, then the developer keeps all IP until that point.
Now, something like building a website, it doesn't really make a whole lot of sense why this matters. If the person doesn't pay, they may not get the source code you've written, and they may not have the technical chops to deploy or use it. But think about a design agency instead.
Client hires a design agency to come up with a brand identity, logo etc. Client agrees to their standard terms - 50% upfront, remaining 50% on completion. They start work and come up with a few ideas. Client asks for a few changes, but they soon broadly settle on a design style. Before the agency gets to the point of completing all the deliverables, the client cuts off contact and does not pay. They're now in breach.
But, they think, we've got the logo, we don't need all the other stuff the agency were going to do. We're fine with the logo, and we're not going to pay. They can go to court, and the court might say "well, you paid 50%, you are entitled to the part performance before the breach". They might look at the design agency and conclude "they're not going to sue us, they're tiny and lawyers are expensive" and decide the risk of the breach makes it worthwhile.
There's also completely innocent scenarios you could imagine that lead to the breach: perhaps the working relationship breaks down. Perhaps the design agency don't answer the client's emails for a week and they refuse to pay.
But if the agency had 50% upfront AND IP transfer only on final payment, then if the company decide to reuse the work, they can't try and argue "well, part payment entitles us to part performance", plus you have a viable cause of action against them for breach of copyright violation in addition to breach of contract.
IP transfer on completion makes it clear what happens in the case of breach (which reduces legal uncertainty), and it increases the cost to the client of breaching, which hopefully has something of a deterrent effect.
In the monteiro talk he says that a lot of companies have default contracts for contractors, and say things to the effect of "it's just our standard contract there's nothing to worry about", IIRC he gives examples of contemporary contracts that require delivery on floppy disks. But also they try to have terms that essentially say all the work belongs to them, and you will be paid on completion.
e.g. if you don't finish the work - or they claim you did not (by applying feature creep offensively, etc). Then because you didn't finish they don't owe you money.
The other approach is that they fail to pay, you can't use (for example) the DMCA to pull down their site, or bring copyright violation suit against them because the IP already belongs to them. All you can do is sue for owed money but you don't have the leverage of stopping them using your IP, because it's not your IP anymore.
That is my understanding from his talk anyway - IANAL, and also I haven't done contract work myself (that's what my wife used to do, and she had a default contract produced by her own lawyer)
To be clear, this is a strong second endorsement.
> you could always have dmca’d them when they deployed
Or do like I did and end up working full-time for a client that does pay well. That brought my non-payment rate down to 0%.
It heavily depends on the kind work and the clients you target and accept.
Some tips:
* always demand partial payment up front (usually 20-50%, depending on contract size and length)
* set milestones with additional payment required upon completion (for bigger jobs)
* have a contract that only transfers usage rights and copyright upon final payment
You can always get screwed over or have bad luck (client goes bankrupt, ...), but some prudence in selecting work goes a long way.
When starting, I learned to stay away from anything gambling and real estate related.
You can mitigate this risk in the following ways:
* Focus on taking in referrals; you're less likely to get hosed if you know a way back to them.
* Fixed contract + payment plan. As much as you can, negotiate one and have everyone sign it.
* Get clients in your geographic proximity. Spend a lot (say, 3 hours) of unbilled time with them in advance of closing a deal. This gives each party a chance to suss out the other. As with the first bullet point, you're less likely to get scammed because you probably know where they work.
Whose idea was it to use react-native-web?
a) So would any competitor to the client.
b) The client can use the AGPLv3 version gratis too, even if they modify it, as it will be on their own server anyway.
The AGPL covers using code in servers. They would have to provide code for any server side changes.
It just wouldn't be free software anymore.
Here's more info: https://choosealicense.com/licenses/agpl-3.0/
def validate(_vin, vin_arr) when length(vin_arr) != 6, do: {:error, "VIN has incorrect length."}
def validate(vin, [_, "ma3", _, "0", "0", _] = _vin_arr) do
case String.length(vin) do
17 ->
{:error, "You must include the full VIN. Including the last two extra digits. It may not be included in your RC book. You may need to get it from your chassis."}
19 ->
{:ok, :valid}
_ ->
{:error, "VIN has incorrect length."}
end
Normally, the whole app I develop usually will sit inside my Google Cloud account and the handover is done only when payment is made. The types of clients I work with normally don't care about source code, they just care about the working app. These days I avoid clients who are pretty nosy with asking for source code access upfront as it's a huge red flag for me, as like the OP, my personal experience also has been bitter with these clients running away with the source code.I run an IT shop, not a restaurant to serve you first and wait for your cheque. Sorry.
Here's our transfer of work clause:
"Transfer of Work. Except for any portion of the deliverables subject to license terms (collectively, the “licensed materials”), Stratosphere initially owns all rights in the work created. Subject only to Stratosphere’s receipt of the fees and costs described in the applicable SOW, Stratosphere assigns all of its right, title and interest in and to the deliverables (other than the licensed materials) provided to you by Stratosphere under that SOW. Licensed materials are copyright of their original authors and provided subject to the terms of their applicable licenses or the license terms described in the SOW. You may not use licensed materials other than as described in the SOW or their applicable licenses."
In case you're wondering, our lawyer is Gabe Levine, the same lawyer in the famous "F*ck you, Pay Me" talk by Mike Monteiro.
Wow, that's awesome. And thanks for sharing that clause :)
Set up frequent milestones and get paid for them.
But you can put anything in a contract, so whose to say.
If it meets the criteria for a work-for-hire, the contracting party is the creator from the beginning for copyright law purposes (this is significant for reasons other than those under discussion; copyright transfers can reversed by the legal creator during a legally-specified window that occurs a few decades after the transfer, but a work-for-hire can't be recovered this way by the actual creator, since they aren't the legal creator), and owns the copyright unless specific contract terms specify otherwise.
On the other hand, if the work is created by an independent contractor or freelancer, the work may be considered a work for hire only if all of the following conditions are met:
- the work must come within one of the nine limited categories of works listed in the definition above, namely (1) a contribution to a collective work, (2) a part of a motion picture or other audiovisual work, (3) a translation, (4) a supplementary work, (5) a compilation, (6) an instructional text, (7) a test, (8) answer material for a test, (9) an atlas;
- the work must be specially ordered or commissioned;
- there must be a written agreement between the parties specifying that the work is a work made for hire by use of the phrase "work for hire" or "work made for hire."
It doesn't seem that software written by one person meets any of the nine criteria above. (A "collective work" seems to refer to something like a magazine that contains the writings of several authors.[2])
[1] https://en.wikipedia.org/wiki/Work_for_hire#Law_in_the_Unite...
We don't negotiate on that clause, even under threat of losing very large contracts. IP ownership is the only real leverage contract developers have to get paid.
That said, it's smart to explicitly write it in the contract; I believe a typical formulation is that the developer owns the copyright until payment, when it transfers to the client.
It probably is better to explicitly stipulate this in the contract, to avoid any misunderstandings or protracted legal battles.
Depending on how payment in the contract was stipulated, you could also refuse partial payments. If it did go to court, I don't think a judge would find that an offer of $1 counts as a good faith effort on behalf of your client.
> Finally, although the First Assignment records both that Mr Dichand and Dr Spaziante were to receive one US dollar as consideration for the assignment of the PCT Applications and further records that they both acknowledged receipt of the dollar, it was never paid by HTI. Mr Edenborough argued that as a consequence the contract was void for lack of consideration. I think the consequence is that Mr Dichand and Dr Spaziante may or may not have a claim against HTI for an outstanding debt of 50 cents each.
I'd certainly check with a lawyer though - it's been a long time since I studied it ( English law), but my understanding is that not paying is a breach of contract, and it doesn't necessarily make it void for lack of consideration.
ie, the fact that the contract included consideration makes the contract valid.
however if one side is in breach i think it's fair for the other side to go ahead and breach their responsibility also. in a case like this, anyway.
To be a work for hire, a work must either be by an employee within the scope of their employment, or if by a contractor must meet three conditions:
1. it must be specially ordered or commissioned,
2. the written agreement with the contractor must explicitly say it will be a work for hire, and
3. it must fall into one of nine specific categories of works: (1) a contribution to a collective work, (2) a part of a motion picture or other audiovisual work, (3) a translation, (4) a supplementary work, (5) a compilation, (6) an instructional text, (7) a test, (8) answer material for a test, (9) an atlas.
Generally software fails on that third point. With software the copyright generally belongs to the contractor.
The employer can put something in the contract that requires the contractor to assign the copyright to the employer, but if the employer than breaks or cancels the contract the contractor has no need to do that.
Note: whether or not the person is an employee or contractor is determined by the common law of agency rather than by what the parties call their relationship.
Nice timing, in that I just wrote about this exact topic a few days ago at: https://nickjanetakis.com/blog/protecting-your-code-and-ip-w...
Firstly, the term "work for hire" refers to a quite specific situation where the copyright for work you create is not held by you as an individual but by the company employing you. It does not apply to contract work except for a very limited set of circumstances, such as work done for motion pictures in the USA.
Secondly, it is difficult to understand how exactly the client could come to hold any rights over code that they didn't pay for. If you have a contract saying "I'll do X if you pay me $Y" and they don't pay you $Y, you don't have to do X. Even if the contract had some kind of farcical "we still own everything even if we don't pay" language, that's about as meaningful as a clause promising that leprechauns are real. A contract is an agreement in which there must be consideration (ie, something of value) for both sides. What value is there in doing work for free?
I'd just take them to court if an invoice followed by "fuck you, pay me" didn't work.
Instead, this developer has put himself on industry blacklists by doing this. No way he’ll be trusted with sensitive projects. Don’t do this.
I guess he is hoping someone start using this project and asks him to expand or customize it.
He won't be trusted with sensitive projects that he doesn't get paid for.
It would be defined in the contract, but usually the contractors never own the copyright to code written for other people.
Anyway, I agree with the other comments that this is unprofessional and immature. We have a civil court system to deal with these kind of issues.
Under the terms of the contract that's now void due to non-payment?
The guy who promised to pay is breaching the contract by not paying, and the contractor's recourse is to sue him in civil court for the money.
It sounds very much like this was a freelancer creating a product, not a contractor providing work.
Lawyers say the legal system has its limitations and that not every morally legitimate gripe has a legal remedy.
Your comment reminds me of the typical objection, why crackdown on these evildoers instead of these worse evildoers? Why not both?
And I really doubt any legitimate operation would blacklist somebody for their entirely legal actions after a contract was broken.
If you hire me to build a book case for you, but then you decide to not pay me after the work is done, should I just destroy the book case and hope for better luck next time? Why couldn't I give the book case away for free?
The greater risk to the contractor is that this advertises that they deal with shitty clients who don't have those things in place. Working with what sound like fly-by-night clients signals that you're not able to be picky about your work.
If I were the contractor here, I'd bury the project and sprinkle some holy water on it, pursue legal action, and get on with my life. I wouldn't draw attention to what is essentially a failed project. It's naive for the contractor to think that everyone will accept his side of the story regarding the project's failure. From a distance, the failed project is more visible than the flaky client.
Whoever didn't pay should be the one on the blacklist - not the dev who is free to make whatever decision they want with a work product they own.
I would recommend removing or rewording the complaint about the client.
Never, never, never publicly complain about a client in a way that can be linked back to you and/or your client.
in the usa, you can't expect a lawyer to take a case without paying their fees up front. So $5000+ for any case.
Assuming you win, you are still looking at years before you might actually get paid (if ever).
That, plus a huge time and cognitive investment, means i'ts not surprising he took this route.
This awkward area between $6k to $15k seems to be a sweet spot for abusive business practices (intentional or otherwise) because of the big time and financial commitment it takes to pursue.
EDIT: Also I should add that it's not guaranteed that legal fees can be reclaimed from successful litigation. This is probably the main reason I keep putting it off (and keep pinging them about it every 6 months, paper trail seems important)
Otoh if there is an actual dispute (MS disagrees that they owe you money) then you need to walk away. Nobody is going to sue MS for $7k.
it's royaltees from xblig (xna on xbox360). they admitted to not paying me in email, but don't know where the money went.
I actually emailed msft legal about it aprox a year ago, which got traction for a couple months before their activity died off again.
so yes, as you say the general plan I'll probably go with is to retain a lawyer to send threatening emails. that'll cost in the area of $350. Just tried my best to resolve this without that drama.
Perhaps he's aware that every action that anyone ever takes, is approved of by some people and disapproved of by others, and your only choice is between who approves of you and who disapproves of you.
I for one, approve of this resolution a hell of a lot more than courts and suits. They are tools you may be forced to use sometimes. It's great that the system is there for when you need it. But they are merely detestable necessities, not my first or preferred choice.
Did it occur to you that by advertizing this attitude, you may have caused yourself to be blacklisted, even if only informally? Probably not.
It's a favor and a pleasure to be blacklisted by some people or organizations. It's the trash taking itself out.
For another, an attorney wouldn't even take this case in the first place. The relevant expression is "you can't get blood from a stone." What good would suing do when your adversary is a defunct LLC, or a wantrepreneur whose credit-card debt likely exceeds his or her assets?
If this person runs a shop where there's a bigger reputation at stake, I'd agree with what you said.
Yeah, go for it.
From what I can tell, it can only reduce the number of pompous jerks attempting to milk me for free work...
Edit: Wondering if it has happened doesn't mean I'm promoting it as a terrific idea.
That said, attributing those extracts that you are criticizing would be pretty bad form, maybe even basis for a defamation suit. So, sounds messy either way.
As an industry, we work so hard to build a culture of constructive critique via code reviews, of mentoring up new developers, of constantly improving our skills. We strive not to judge people for their code any more than we would want to be judged for our own.
Naming and shaming coders because they wrote bad code is just uncool, as it fights against the aspects of this work that make it enjoyable, and instead turns it toxic.
If I paid a photographer to take my wedding photos and they did a terrible job, am I a bad person for judging and shaming them to warn others who might be similarly conned? Or is it only developers who get the kid gloves treatment?
Not applicable in this particular case I think...
I think most small-end jobs end up going to shit for more reasons than bad code, I'm still trying to understand the whole dynamic of how it all goes to crap.
I'd also just like to add if your hypothetical was the case would said developer ever care? I doubt it, they'd just move on to the next sucker.
Over 30-some years of side-work, I've actually never gotten anything up-front and I've always been paid.
For me, the work has always been for clients I've known for quite a while before the contract work came up, and whom I had reason to trust.
I just bring it up as a counter-point to the idea you "always" get paid something up-front. Context counts.
We didn't know how to do a web app. I knew a bit of Python, him a bit of Javascript. So a month during, we learned how to and built the app they asked with Django. I never learned so quickly!
After a month, we shipped the app. They had a lot of users (900+), so our app that worked well with a database of two people failed miserably.
We spent nights fixing its problems. It used an external API that we had rate limiting problems with. I implemented a cache using Postgresql.
Then, they started to ask us for more features that weren't in the original contract. They said that if we wanted to get paid, we had to do them.
Eventually, we realized they weren't going to pay for us. We asked them to pay us, and they said yes. Then they said no, contact our lawyers. Their lawyers told us they wanted to engage charges because we didn't do the job well. They were still using our website without paying us! We contacted a lawyer and quickly realized that because of the legal fees (2500$ upfront + 500$/hour), it wasn't worth it to seek justice.
We were completely fucked.
Then, I remembered they used Heroku, which was based in the US and therefore applied the DMCA laws. We sent them an email explaining the situation and, in under 48H, they took the website down. I will always remember that morning when my friend woke me up to show me their site down.
As we did the deployment, they took a week to re-deploy our app at a server under French jurisdiction (that we could never have taken down).
Then, their whole company ran out of business as customers were leaving and asking refunds because of the lousy service. They laid off everyone, but our app is still freely accessible at https://crypto-analyse.com.
This experience taught us many lessons: - Never work for something that you're not paid for unless you're doing charity or working for yourself. - Contracts are no guarantee - They made a lot of money with our app. We could have made a lot more by just selling it ourselves.
And that's what we did! We just shipped our new app (it's an app to automate crypto trading with a conditions editor), https://kaktana.com
We now make more money than we had thought before, all of that using the experience we gained from that shitty deal.
“The phoenix must burn to emerge.” - Janet Fitch
Generally speaking the client owns the code whether or not they've paid yet. Of course if the client agrees this is fine. But it's not fine if the client hasn't agreed.
Stunts like this are a really bad idea. There's a right way to do it, and it works really well. Call a collections lawyer.
No payment would invalidate the license.
What about partial payment? What about a payment dispute? in all these cases ownership remains as defined in the contract.
You could try to make a contract that works the way you describe but it would be unwieldy and I’m skeptical anyone would use it.
It’s really straightforward to call a collections lawyer. In most cases the money is paid after one or two letters.
Not paying money owed can have bad consequences. The collections lawyer reminds them of this, and the situation is remedied in short order.
On the other hand, pulling some cowboy stunt to teach them a lesson (like releasing their source code, or the related idiotic idea of sabotaging their website or business) could lead to paying significant civil and even criminal penalties.
it’s done well though, so could certainly build it up if this model is what you are looking for.
Just screams unprofessionalism in my opinion.
Surely the guy not paying is the unprofessional one?
Sure, since "he signed", he could have probably taken legal action, but that's often a long and costly process. How is cutting your losses and walking away (but outsourcing the code you wrote) unprofessional?
Surely, both people in the relationship can behave unprofessionally.
> How is cutting your losses and walking away (but outsourcing the code you wrote) unprofessional?
That's not why people are suggesting the developer is unprofessional. It's because he's complaining about a client publicly.
I think there is a different way to phrase this, something like “this is the result of a collaboration that didn’t end up working out” or whatever. I get that it’s kind of mealy mouthed, but it avoids any aura of conflict in the evaluation.
Just saying the word "professionalism" doesn't make you the one who is more professiional, or make your concept of professinalism the better one.