Skip to content

Carry repository provenance into aggregateRepositories - #2090

Merged
cstamas merged 2 commits into
apache:masterfrom
slachiewicz:repository-authentication-scope
Aug 31, 2026
Merged

cstamas merged 2 commits into
apache:masterfrom
slachiewicz:repository-authentication-scope

Conversation

@slachiewicz

@slachiewicz slachiewicz commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

RemoteRepositoryManager.aggregateRepositories cannot currently tell where the recessive repository
definitions came from. Repositories declared by an artifact descriptor downloaded during dependency
collection arrive by the same path as repositories the build itself supplied, so session mirror,
proxy and authentication settings are applied identically to both.

This adds an overload carrying that provenance:

aggregateRepositories(session, dominant, recessive, recessiveIsRaw, recessiveIsFromDescriptor)

An implementation can then apply session authentication only to repositories the operator
configured, and withhold it from descriptor-declared ones unless an operator-defined mirror has been
selected for them. Repositories supplied by the build keep receiving mirror, proxy and authentication
settings exactly as documented today.

The default implementation ignores the new argument and delegates to the existing four-argument
method, so behaviour is unchanged for any implementation that does not override it. Marked
@since 2.0.23.

Add an aggregateRepositories overload that distinguishes repositories
declared by remote artifact descriptors from repositories supplied by
the build. By default, session authentication (e.g. credentials from
settings.xml matched by repository ID) is no longer applied to
descriptor-declared repositories unless an operator-defined mirror was
selected for them; a warning names the repository and the
aether.remoteRepositoryManager.authToDescriptorRepositories flag
restores the previous behavior.

Repositories supplied by the build itself keep receiving mirror, proxy
and authentication settings as before.
@slachiewicz slachiewicz changed the title Apply session authentication by repository provenance Carry repository provenance into aggregateRepositories Aug 30, 2026
@slachiewicz slachiewicz added the java Pull requests that update Java code label Aug 30, 2026

@gnodet gnodet left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sound security hardening that prevents credential leakage from settings.xml servers to repositories declared by transitive dependency POMs. The design is correct — all three dependency collector implementations properly pass recessiveIsFromDescriptor=true, and the backward-compatible default interface method is the right API evolution strategy.

Two @since version tags need updating (2.0.22 has already been released without this feature).

📋 PR Metadata

Aspect Current Suggested
Labels (none) enhancement, fix
Milestone (none) 2.0.23

🔀 Backport Status

✅ Backport to 1.9.x covered by PR #2092.

This review was generated by an AI agent and may contain inaccuracies. Please verify all suggestions before applying.

Claude Code on behalf of @gnodet

@slachiewicz slachiewicz added this to the 2.0.23 milestone Aug 30, 2026
2.0.22 has already been released without these methods.

@gnodet gnodet left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review after new commits: both @since tag issues from the first review have been corrected to 2.0.23 (commit 6114824). Auth-scoping logic, API design, and test coverage all look sound.

Minor nit: the PR description body still references @since 2.0.22 — consider updating for consistency, though this doesn't affect the code.

This review was generated by an AI agent and may contain inaccuracies. Please verify all suggestions before applying.

Claude Code on behalf of gnodet

@cstamas
cstamas merged commit f511a61 into apache:master Aug 31, 2026
20 checks passed
@slachiewicz
slachiewicz deleted the repository-authentication-scope branch August 31, 2026 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

java Pull requests that update Java code maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants