feat(studio): show a source module's data terms before the install button
Some checks failed
Security / Security check (push) Failing after 2s

The store detail sheet now carries a data-source block for source.*
modules: publisher, upstream url, the terms in plain words, and any
attribution the operator has to carry with the output. It sits above
maintainers and above the install button, because it is a decision
input rather than a footnote.

The values are selectable: compliance notes get written by copying,
not retyping. A note names whose terms these are, so nobody reads them
as the module's own licence. Four guards, including that an empty
attribution renders no empty row.

Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
This commit is contained in:
flemming-it 2026-09-09 12:36:45 +02:00
parent fb809a4cbd
commit 35a79d0bb6
8 changed files with 307 additions and 44 deletions

View file

@ -1711,6 +1711,10 @@
"installConfirmTrustTitle": "Trust & security",
"installConfirmTrustBody": "The module runs in a sandbox: it may only touch the network endpoints, files, and environment variables it declares itself — the hub enforces that list. The full permission list is visible in the module details after installation.",
"storeSectionMaintainers": "Maintainers",
"storeSectionDataSource": "Data source",
"storeDataSourceLicense": "Terms",
"storeDataSourceAttribution": "Attribution required",
"storeDataSourceNote": "These terms cover the material this module fetches, not the module itself. It downloads on your behalf and ships no copy of the data.",
"storeMaintainersNone": "not specified",
"installConfirmMaintainers": "Maintainers",
"storePolicyUnverifiedNotice": "Signature enforcement is switched off in the hub policy — installs are not cryptographically verified. The install dialog shows the per-module status; enable security.require_signatures for verified installs.",