slawekjaranowski opened a new pull request, #13268:
URL: https://github.com/apache/maven/pull/13268

   ### Problem
   
   Credentials of a `<server>` are bound to the origin (scheme, host, port) of 
the repositories and mirrors declared with the same id 
(`maven.repository.credentialScope`, default `origin`). 
`declaredRepositoryOrigins` is built in `DefaultRepositorySystemSessionFactory` 
from the mirrors and from `request.getRemoteRepositories()` / 
`getPluginArtifactRepositories()`.
   
   Repositories declared inside a `settings.xml` `<profile>` only reach those 
lists when the profile id is listed in `<settings><activeProfiles>`. A profile 
activated through `<activation>` (property, jdk, os, file) or through `-P` 
contributes no origin at all, so a perfectly legitimate corporate repository 
gets:
   
   - under the default `origin` scope: a warning on every build, with no way to 
silence it;
   - under `strict`: refused credentials and a 401.
   
   This cannot be fixed automatically: the repository system session is created 
before any project is read, and profile activation is resolved later, per 
project, by the model builder.
   
   ### Solution
   
   A `<server>` can declare the origins its credentials may be used with:
   
   ```xml
   <server>
     <id>internal</id>
     <username>u</username>
     <password>p</password>
     <repositoryOrigins>
       <repositoryOrigin>https://repo.example.org</repositoryOrigin>
       <repositoryOrigin>https://mirror.example.org:8443</repositoryOrigin>
     </repositoryOrigins>
   </server>
   ```
   
   - **Union, not replacement** — declared origins are added to the ones Maven 
discovers itself, so existing configurations are unaffected.
   - **Bare origins**, not repository URLs. They go through the same 
normalization as every other origin: case-insensitive, `:80`/`:443` equivalent 
to no port. Values are checked by settings validation, so a typo is reported 
where it is written rather than surfacing later as a refused credential.
   - The warnings emitted by the origin binding now name `<repositoryOrigins>` 
as the place to declare a missing origin, so the message is actionable.
   
   ### Project settings
   
   `<repositoryOrigins>` is dropped from project settings (`.mvn/settings.xml`) 
and warned about, exactly like credentials are. This is a security requirement: 
settings list fields merge by union, and a project-settings `<server>` with the 
same id survives as a separate entry of the servers list, which the session 
factory reads too. Without the scrub, a project could widen the set of hosts 
its user's credentials are sent to. 
`DefaultSettingsParserTest#projectSettingsCannotWidenServerCredentialOrigins` 
fails without it.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to