slawekjaranowski opened a new pull request, #13275:
URL: https://github.com/apache/maven/pull/13275
Same change as #13268, for the `maven-3.10.x` branch.
### Problem
Credentials of a `<server>` are bound to the origin (scheme, host, port) of
the repositories and mirrors declared with the same id
(`maven.repository.credentialScope`, default `origin`, since 3.10.0).
`declaredRepositoryOrigins` is built in `DefaultRepositorySystemSessionFactory`
from the mirrors and from `request.getRemoteRepositories()` /
`getPluginArtifactRepositories()`.
Repositories declared inside a `settings.xml` `<profile>` only reach those
lists when the profile id is listed in `<settings><activeProfiles>`. A profile
activated through `<activation>` (property, jdk, os, file) or through `-P`
contributes no origin at all, so a perfectly legitimate corporate repository
gets:
- under the default `origin` scope: a warning on every build, with no way to
silence it;
- under `strict`: refused credentials and a 401.
This cannot be fixed automatically: the repository system session is created
before any project is read, and profile activation is resolved later, per
project, by the model builder.
### Solution
A `<server>` can declare the origins its credentials may be used with:
```xml
<server>
<id>internal</id>
<username>u</username>
<password>p</password>
<repositoryOrigins>
<repositoryOrigin>https://repo.example.org</repositoryOrigin>
<repositoryOrigin>https://mirror.example.org:8443</repositoryOrigin>
</repositoryOrigins>
</server>
```
- **Union, not replacement** — declared origins are added to the ones Maven
discovers itself, so existing configurations are unaffected.
- **Bare origins**, not repository URLs. They go through the same
normalization as every other origin: case-insensitive, `:80`/`:443` equivalent
to no port. Values are checked by settings validation, so a typo is reported
where it is written rather than surfacing later as a refused credential. Values
holding a property placeholder are skipped, since settings validation runs
before interpolation.
- The warnings emitted by the origin binding now name `<repositoryOrigins>`
as the place to declare a missing origin, so the message is actionable.
### Differences from #13268
- No V4 counterpart here: this branch has a single settings model and a
single settings validator.
- The project settings part of #13268 has no equivalent: Maven 3.x has no
`.mvn/settings.xml`, so there is nothing to scrub.
- `maven-core` had no test for `DefaultRepositorySystemSessionFactory` on
this branch, so the credential scoping tests come as a new
`DefaultRepositorySystemSessionFactoryTest`.
`mvn verify` is green on the whole repository.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]