feat(license): trust the production signing key

This commit is contained in:
2026-07-24 15:01:03 +01:00
parent 4f1fce32c1
commit 6fde319b2f
+2 -3
View File
@@ -20,9 +20,8 @@ import (
// root is a licensing bypass: a self-hosted operator could point it at a keypair
// they generated themselves.
var trustedPublicKeys = []string{
// Populated in Task 6 with the real production key.
// Until then this slice is empty and every licence fails to verify,
// which is the correct default for a build with no trust root.
// Production signing key, generated 2026-07-24. Index 0 is current.
"AS6Z4XBXF7HPTOMBUK47SWHPROAGOSBIW5ZZZHTLCA6FHMYSHCCTV3S6AIN6DOB6VKMHMTLRIWPSBAZ2FOHJV3A6NLOCWGEO2VA7KYGSG62SILEFA4SNJ7VWDDIVZZM4ZU4VJVE22LESH72STAAVIDYI77WA====",
}
func publicKeys() ([]*lk.PublicKey, error) {