harshab054 opened a new pull request, #2188:
URL: https://github.com/apache/maven-resolver/pull/2188

   Description
   
   Fixes the Maven Resolver prefix filter behavior when a repository serves an 
artifact path that is missing from its "prefixes.txt".
   
   A repository such as an Artifactory/Nexus virtual repository may expose a 
prefixes file generated from a public repository index while also serving 
private/internal artifacts. When the requested artifact path is absent from 
that prefixes file, the prefix filter can reject an artifact that the 
repository actually serves.
   
   This change verifies a denied path against the repository before permanently 
rejecting it.
   
   Implementation
   
   - Successfully served denied paths are cached and allowed on subsequent 
requests.
   - Definitively absent paths remain blocked and are negative-cached to avoid 
repeated remote probes.
   - Transient/unknown transport failures are not negative-cached, allowing 
later requests to retry.
   - Verification is performed per exact artifact path.
   - Multiple independently denied paths can be verified without disabling the 
repository's prefix filter globally.
   - Existing "verifyDeniedDropsTree=true" legacy behavior remains unchanged.
   
   Security
   
   The implementation preserves the security invariant introduced by Resolver 
PR #2082.
   
   A successful verification of one denied path does NOT disable the prefix 
filter for the entire repository or authorize unrelated artifact paths.
   
   Only the exact remotely verified path is allowed.
   
   Tests
   
   - "PrefixesRemoteRepositoryFilterSourceVerifyDeniedTest": 14/14 passed
   - "PrefixesRemoteRepositoryFilterSourceTest": 6/6 passed
   - Checkstyle: passed with 0 violations
   - Spotless: passed
   - "git diff --check": clean
   
   Related Maven Issue
   
   This addresses the underlying Maven Resolver behavior reported in Apache 
Maven issue #13385:
   
   https://github.com/apache/maven/issues/13385
   
   The original issue is reported against Maven because Maven users experience 
the resolution failure, while the prefix filtering implementation itself lives 
in Maven Resolver.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to