harshab054 opened a new pull request, #2188: URL: https://github.com/apache/maven-resolver/pull/2188
Description Fixes the Maven Resolver prefix filter behavior when a repository serves an artifact path that is missing from its "prefixes.txt". A repository such as an Artifactory/Nexus virtual repository may expose a prefixes file generated from a public repository index while also serving private/internal artifacts. When the requested artifact path is absent from that prefixes file, the prefix filter can reject an artifact that the repository actually serves. This change verifies a denied path against the repository before permanently rejecting it. Implementation - Successfully served denied paths are cached and allowed on subsequent requests. - Definitively absent paths remain blocked and are negative-cached to avoid repeated remote probes. - Transient/unknown transport failures are not negative-cached, allowing later requests to retry. - Verification is performed per exact artifact path. - Multiple independently denied paths can be verified without disabling the repository's prefix filter globally. - Existing "verifyDeniedDropsTree=true" legacy behavior remains unchanged. Security The implementation preserves the security invariant introduced by Resolver PR #2082. A successful verification of one denied path does NOT disable the prefix filter for the entire repository or authorize unrelated artifact paths. Only the exact remotely verified path is allowed. Tests - "PrefixesRemoteRepositoryFilterSourceVerifyDeniedTest": 14/14 passed - "PrefixesRemoteRepositoryFilterSourceTest": 6/6 passed - Checkstyle: passed with 0 violations - Spotless: passed - "git diff --check": clean Related Maven Issue This addresses the underlying Maven Resolver behavior reported in Apache Maven issue #13385: https://github.com/apache/maven/issues/13385 The original issue is reported against Maven because Maven users experience the resolution failure, while the prefix filtering implementation itself lives in Maven Resolver. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
