> Authlib offers two licenses, one is BSD for open source projects, one is a commercial license for closed source projects.
> Authlib offers two licenses, one is BSD for open source projects, one is a commercial license for closed source projects.
> If your company is creating a closed source OAuth provider, it is strongly suggested that your company purchasing a commercial license.
And the text in the LICENSE file is a bog-standard BSD license, which doesn't say anything about not being able to use it for commercial purposes.
So it looks like they're relying on companies paying for support, or out of goodwill (or confusion), rather than because of any legal obligation.
And even if the licensing of this project holds up as the author intends: If I make an Open Source project based on this, and someone else uses that in a commercial product, it would be 100% legal according to the BSD license.
From looking at the plans, the value is mostly in support for the commercial license, which is a pretty common approach. I think the wording is the only part that is odd, although it may be an intention nudge.
Also, based on a blurb from their sponsorship page, it appears they give security patches to commercial license holders before the public. https://github.com/sponsors/lepture
GPL propagates. Presumably BSD doesn't.
Redistribution and use in source and binary forms [...] are permitted [...] provided that the following conditions are met:
[...]
* Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
[...]Or $2,000 a year if your company wants to pay by invoice.
""" authlib ~~~~~~~
The ultimate Python library in building OAuth 1.0, OAuth 2.0 and OpenID
Connect clients and providers. It covers from low level specification
implementation to high level framework integrations.
:copyright: (c) 2017 by Hsiaoming Yang.
:license: BSD, see LICENSE for more details.
"""