slawekjaranowski opened a new pull request, #13314:
URL: https://github.com/apache/maven/pull/13314
Cherry-pick of #13268 (`c23bdb1fd1`) to `maven-4.0.x`.
A `<server>` in `settings.xml` can declare the repository origins its
credentials may be used with:
```xml
<server>
<id>internal</id>
<username>u</username>
<password>p</password>
<repositoryOrigins>
<repositoryOrigin>https://repo.example.org</repositoryOrigin>
<repositoryOrigin>https://mirror.example.org:8443</repositoryOrigin>
</repositoryOrigins>
</server>
```
The declared origins are added to the ones Maven derives from repositories
and mirrors, so repositories of a settings profile activated through
`<activation>` or `-P` no longer trigger origin-binding warnings (or refused
credentials under `strict`). The element is dropped from project settings
(`.mvn/settings.xml`), like credentials are. See #13268 for the full
description.
### Differences from master
- `maven-4.0.x` has no settings parser SPI, so there is no
`DefaultSettingsParserTest`; the security test
`projectSettingsCannotWidenServerCredentialOrigins` moved to
`DefaultSettingsBuilderFactoryTest`.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]