slawekjaranowski opened a new pull request, #13314:
URL: https://github.com/apache/maven/pull/13314

   Cherry-pick of #13268 (`c23bdb1fd1`) to `maven-4.0.x`.
   
   A `<server>` in `settings.xml` can declare the repository origins its 
credentials may be used with:
   
   ```xml
   <server>
     <id>internal</id>
     <username>u</username>
     <password>p</password>
     <repositoryOrigins>
       <repositoryOrigin>https://repo.example.org</repositoryOrigin>
       <repositoryOrigin>https://mirror.example.org:8443</repositoryOrigin>
     </repositoryOrigins>
   </server>
   ```
   
   The declared origins are added to the ones Maven derives from repositories 
and mirrors, so repositories of a settings profile activated through 
`<activation>` or `-P` no longer trigger origin-binding warnings (or refused 
credentials under `strict`). The element is dropped from project settings 
(`.mvn/settings.xml`), like credentials are. See #13268 for the full 
description.
   
   ### Differences from master
   
   - `maven-4.0.x` has no settings parser SPI, so there is no 
`DefaultSettingsParserTest`; the security test 
`projectSettingsCannotWidenServerCredentialOrigins` moved to 
`DefaultSettingsBuilderFactoryTest`.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to