gnodet-bot commented on code in PR #13386:
URL: https://github.com/apache/maven/pull/13386#discussion_r4223544801


##########
maven-core/src/main/java/org/apache/maven/internal/aether/DefaultRepositorySystemSessionFactory.java:
##########
@@ -238,6 +238,9 @@ public RepositorySystemSession.SessionBuilder 
newRepositorySessionBuilder(MavenE
         // Resolver's ConfigUtils solely rely on config properties, that is 
why we need to add both here as well.
         configProps.putAll(request.getSystemProperties());
         configProps.putAll(request.getUserProperties());
+        // Default true drops verified-denied tree entries so artifacts remain 
resolvable when a virtual repository
+        // publishes an incomplete prefix file. Set false to restore 
Resolver's fall-through behaviour.

Review Comment:
   ⚠️ **Accuracy concern:** The comment says `false` restores "fall-through 
behaviour", but per a reading of Resolver's source, `false` may keep the filter 
enforcing denials rather than falling through. If so, this description is 
inverted — it would be `true` (what this PR sets) that drops the tree entries. 
Please verify against `PrefixesRemoteRepositoryFilter` and update the wording 
accordingly.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to