slawekjaranowski opened a new pull request, #13268:
URL: https://github.com/apache/maven/pull/13268
### Problem
Credentials of a `<server>` are bound to the origin (scheme, host, port) of
the repositories and mirrors declared with the same id
(`maven.repository.credentialScope`, default `origin`).
`declaredRepositoryOrigins` is built in `DefaultRepositorySystemSessionFactory`
from the mirrors and from `request.getRemoteRepositories()` /
`getPluginArtifactRepositories()`.
Repositories declared inside a `settings.xml` `<profile>` only reach those
lists when the profile id is listed in `<settings><activeProfiles>`. A profile
activated through `<activation>` (property, jdk, os, file) or through `-P`
contributes no origin at all, so a perfectly legitimate corporate repository
gets:
- under the default `origin` scope: a warning on every build, with no way to
silence it;
- under `strict`: refused credentials and a 401.
This cannot be fixed automatically: the repository system session is created
before any project is read, and profile activation is resolved later, per
project, by the model builder.
### Solution
A `<server>` can declare the origins its credentials may be used with:
```xml
<server>
<id>internal</id>
<username>u</username>
<password>p</password>
<repositoryOrigins>
<repositoryOrigin>https://repo.example.org</repositoryOrigin>
<repositoryOrigin>https://mirror.example.org:8443</repositoryOrigin>
</repositoryOrigins>
</server>
```
- **Union, not replacement** — declared origins are added to the ones Maven
discovers itself, so existing configurations are unaffected.
- **Bare origins**, not repository URLs. They go through the same
normalization as every other origin: case-insensitive, `:80`/`:443` equivalent
to no port. Values are checked by settings validation, so a typo is reported
where it is written rather than surfacing later as a refused credential.
- The warnings emitted by the origin binding now name `<repositoryOrigins>`
as the place to declare a missing origin, so the message is actionable.
### Project settings
`<repositoryOrigins>` is dropped from project settings (`.mvn/settings.xml`)
and warned about, exactly like credentials are. This is a security requirement:
settings list fields merge by union, and a project-settings `<server>` with the
same id survives as a separate entry of the servers list, which the session
factory reads too. Without the scrub, a project could widen the set of hosts
its user's credentials are sent to.
`DefaultSettingsParserTest#projectSettingsCannotWidenServerCredentialOrigins`
fails without it.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]