jmkelm08 opened a new issue, #13383:
URL: https://github.com/apache/maven/issues/13383

   ### Affected version
   
   3.10.0
   
   ### Bug description
   
   ### Problem
   
   Artifactory can return `404 Not Found` instead of `401 Unauthorized` when a 
user is not authorized to access an artifact. In this situation, preemptive 
authentication is required because the client receives no authentication 
challenge.
   
   With Maven Resolver configured for:
   
   - preemptive authentication: `-Daether.transport.http.preemptiveAuth=true`
   - a repository URL without an explicit port: 
`https://artifactory.mycompany.com/artifactory/repo1`
   - server credentials with a matching id
   
   the initial request does not include the Authorization header.
   
   ### Investigation
   `ApacheTransporter.prepare` inserts the `BasicScheme` into the 
authentication cache using an `HttpHost` whose port is `-1`, because the 
repository URL does not specify a port. Before `RequestAuthCache.process` looks 
up the entry, Apache `HttpClient` resolves the default HTTPS port to `443`. It 
therefore searches using an `HttpHost` with port `443`, which does not match 
the cached `HttpHost` with port `-1`. The cached authentication scheme is 
missed and preemptive authentication is skipped.
   
   Specifying the default HTTPS port explicitly works around the issue: 
`https://artifactory.mycompany.com:443/artifactory/repo1`


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to