slawekjaranowski opened a new pull request, #13275:
URL: https://github.com/apache/maven/pull/13275

   Same change as #13268, for the `maven-3.10.x` branch.
   
   ### Problem
   
   Credentials of a `<server>` are bound to the origin (scheme, host, port) of 
the repositories and mirrors declared with the same id 
(`maven.repository.credentialScope`, default `origin`, since 3.10.0). 
`declaredRepositoryOrigins` is built in `DefaultRepositorySystemSessionFactory` 
from the mirrors and from `request.getRemoteRepositories()` / 
`getPluginArtifactRepositories()`.
   
   Repositories declared inside a `settings.xml` `<profile>` only reach those 
lists when the profile id is listed in `<settings><activeProfiles>`. A profile 
activated through `<activation>` (property, jdk, os, file) or through `-P` 
contributes no origin at all, so a perfectly legitimate corporate repository 
gets:
   
   - under the default `origin` scope: a warning on every build, with no way to 
silence it;
   - under `strict`: refused credentials and a 401.
   
   This cannot be fixed automatically: the repository system session is created 
before any project is read, and profile activation is resolved later, per 
project, by the model builder.
   
   ### Solution
   
   A `<server>` can declare the origins its credentials may be used with:
   
   ```xml
   <server>
     <id>internal</id>
     <username>u</username>
     <password>p</password>
     <repositoryOrigins>
       <repositoryOrigin>https://repo.example.org</repositoryOrigin>
       <repositoryOrigin>https://mirror.example.org:8443</repositoryOrigin>
     </repositoryOrigins>
   </server>
   ```
   
   - **Union, not replacement** — declared origins are added to the ones Maven 
discovers itself, so existing configurations are unaffected.
   - **Bare origins**, not repository URLs. They go through the same 
normalization as every other origin: case-insensitive, `:80`/`:443` equivalent 
to no port. Values are checked by settings validation, so a typo is reported 
where it is written rather than surfacing later as a refused credential. Values 
holding a property placeholder are skipped, since settings validation runs 
before interpolation.
   - The warnings emitted by the origin binding now name `<repositoryOrigins>` 
as the place to declare a missing origin, so the message is actionable.
   
   ### Differences from #13268
   
   - No V4 counterpart here: this branch has a single settings model and a 
single settings validator.
   - The project settings part of #13268 has no equivalent: Maven 3.x has no 
`.mvn/settings.xml`, so there is nothing to scrub.
   - `maven-core` had no test for `DefaultRepositorySystemSessionFactory` on 
this branch, so the credential scoping tests come as a new 
`DefaultRepositorySystemSessionFactoryTest`.
   
   `mvn verify` is green on the whole repository.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to