ENTERPRISE-LICENSE.md
Copyright (c) MedusaJS, Inc. All rights reserved.
The Enterprise Edition materials identified below (the "Enterprise Materials") are proprietary software. They are not licensed under the MIT License that applies to the remainder of this repository.
You may use, reproduce, modify, distribute, or otherwise exploit the Enterprise Materials only under a separate, valid commercial agreement with MedusaJS, Inc. that expressly grants those rights. Possession of or access to the source code does not grant a license. If you do not have such an agreement, no rights are granted except those that cannot lawfully be restricted.
The terms of an applicable commercial agreement control if they conflict with this notice. To obtain a commercial license, contact MedusaJS, Inc. at https://medusajs.com/contact.
This notice applies prospectively and does not withdraw rights already granted for earlier versions of any material under the MIT License. Those earlier versions remain available under their original license terms.
Any use, reproduction, modification, or distribution of the Enterprise Materials without a valid commercial agreement is unlicensed and constitutes an infringement of MedusaJS, Inc.'s copyright. Circumventing, disabling, or removing any license validation or feature-gating mechanism does not create a license and is itself a violation of this notice. Enabling any Enterprise feature flag constitutes a representation that you hold a valid commercial agreement with MedusaJS, Inc.
MedusaJS, Inc. reserves all rights and remedies available at law and in equity, including injunctive relief, monetary damages, and recovery of costs and attorneys' fees where available.
RBAC (role-based access control) and SSO (single sign-on) are Medusa Enterprise Edition features. The following repository paths, including all files below a listed directory, are Enterprise Materials:
packages/modules/rbac/packages/core/core-flows/src/rbac/packages/medusa/src/api/admin/rbac/packages/core/types/src/rbac/packages/core/types/src/http/rbac/packages/core/framework/src/policies/packages/core/framework/src/http/middlewares/check-permissions.tspackages/core/framework/src/http/utils/policies/rbac-field-filter.tspackages/core/utils/src/modules-sdk/define-policies.tspackages/core/utils/src/modules-sdk/policy-to-types.tspackages/medusa/src/feature-flags/rbac.tspackages/medusa/src/feature-flags/rbac-filter-fields.tspackages/medusa/src/modules/rbac.tspackages/modules/link-modules/src/definitions/invite-rbac-role.tspackages/modules/link-modules/src/definitions/user-rbac-role.tspackages/core/core-flows/src/invite/steps/get-invite-roles.tspackages/core/core-flows/src/invite/steps/validate-roles-exist.tspackages/core/core-flows/src/user/steps/get-assignable-policies.tspackages/core/core-flows/src/user/steps/get-assignable-roles.tspackages/core/core-flows/src/user/steps/validate-user-role-permissions.tspackages/core/core-flows/src/user/workflows/assign-user-roles.tspackages/core/core-flows/src/user/workflows/get-assignable-policies.tspackages/core/core-flows/src/user/workflows/get-assignable-roles.tspackages/core/core-flows/src/user/workflows/remove-user-roles.tspackages/medusa/src/api/admin/users/[id]/roles/packages/core/js-sdk/src/admin/rbac-policy.tspackages/core/js-sdk/src/admin/rbac-role.tspackages/admin/dashboard/src/routes/policies/packages/admin/dashboard/src/routes/roles/packages/admin/dashboard/src/hooks/api/rbac-policies.tsxpackages/admin/dashboard/src/hooks/api/rbac-roles.tsxpackages/admin/dashboard/src/hooks/use-require-rbac-feature.tsxpackages/admin/dashboard/src/components/common/required-permissions-section/packages/admin/dashboard/src/lib/permissions/packages/admin/dashboard/src/providers/permissions-provider/packages/modules/rbac/integration-tests/integration-tests/http/__tests__/rbac/integration-tests/modules/__tests__/rbac/integration-tests/modules/__tests__/rbac-match-endpoint-entities.spec.tspackages/modules/providers/auth-oidc/packages/medusa/src/modules/auth-oidc.tspackages/core/types/src/auth/providers/oidc.tspackages/medusa/src/api/auth/[auth_provider]/user/route.tspackages/admin/dashboard/src/routes/login/components/sso-login.tsxGenerated, compiled, bundled, or otherwise transformed versions of the files listed above are also Enterprise Materials, even if emitted to another path.
Files outside this list remain under the MIT License in LICENSE, including
generic authentication, generic auth provider registration and discovery,
generic user and invite management, shared HTTP and workflow infrastructure,
and incidental integration points that only register, configure, export, or
display the availability of an Enterprise feature.
UNLESS A COMMERCIAL AGREEMENT WITH MEDUSAJS, INC. EXPRESSLY STATES OTHERWISE: THE ENTERPRISE MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY LAW, MEDUSAJS, INC. DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. TO THE SAME EXTENT, MEDUSAJS, INC. WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF DATA, PROFITS, REVENUE, GOODWILL, OR BUSINESS, ARISING OUT OF OR RELATING TO THE ENTERPRISE MATERIALS OR THEIR USE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.