Carry repository provenance into aggregateRepositories - #2090
Conversation
Add an aggregateRepositories overload that distinguishes repositories declared by remote artifact descriptors from repositories supplied by the build. By default, session authentication (e.g. credentials from settings.xml matched by repository ID) is no longer applied to descriptor-declared repositories unless an operator-defined mirror was selected for them; a warning names the repository and the aether.remoteRepositoryManager.authToDescriptorRepositories flag restores the previous behavior. Repositories supplied by the build itself keep receiving mirror, proxy and authentication settings as before.
gnodet
left a comment
There was a problem hiding this comment.
Sound security hardening that prevents credential leakage from settings.xml servers to repositories declared by transitive dependency POMs. The design is correct — all three dependency collector implementations properly pass recessiveIsFromDescriptor=true, and the backward-compatible default interface method is the right API evolution strategy.
Two @since version tags need updating (2.0.22 has already been released without this feature).
📋 PR Metadata
| Aspect | Current | Suggested |
|---|---|---|
| Labels | (none) | enhancement, fix |
| Milestone | (none) | 2.0.23 |
🔀 Backport Status
✅ Backport to 1.9.x covered by PR #2092.
This review was generated by an AI agent and may contain inaccuracies. Please verify all suggestions before applying.
Claude Code on behalf of @gnodet
2.0.22 has already been released without these methods.
gnodet
left a comment
There was a problem hiding this comment.
Re-review after new commits: both @since tag issues from the first review have been corrected to 2.0.23 (commit 6114824). Auth-scoping logic, API design, and test coverage all look sound.
Minor nit: the PR description body still references @since 2.0.22 — consider updating for consistency, though this doesn't affect the code.
This review was generated by an AI agent and may contain inaccuracies. Please verify all suggestions before applying.
Claude Code on behalf of gnodet
RemoteRepositoryManager.aggregateRepositoriescannot currently tell where the recessive repositorydefinitions came from. Repositories declared by an artifact descriptor downloaded during dependency
collection arrive by the same path as repositories the build itself supplied, so session mirror,
proxy and authentication settings are applied identically to both.
This adds an overload carrying that provenance:
An implementation can then apply session authentication only to repositories the operator
configured, and withhold it from descriptor-declared ones unless an operator-defined mirror has been
selected for them. Repositories supplied by the build keep receiving mirror, proxy and authentication
settings exactly as documented today.
The default implementation ignores the new argument and delegates to the existing four-argument
method, so behaviour is unchanged for any implementation that does not override it. Marked
@since 2.0.23.