001/*
002 * Licensed to the Apache Software Foundation (ASF) under one
003 * or more contributor license agreements.  See the NOTICE file
004 * distributed with this work for additional information
005 * regarding copyright ownership.  The ASF licenses this file
006 * to you under the Apache License, Version 2.0 (the
007 * "License"); you may not use this file except in compliance
008 * with the License.  You may obtain a copy of the License at
009 *
010 *   http://www.apache.org/licenses/LICENSE-2.0
011 *
012 * Unless required by applicable law or agreed to in writing,
013 * software distributed under the License is distributed on an
014 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
015 * KIND, either express or implied.  See the License for the
016 * specific language governing permissions and limitations
017 * under the License.
018 */
019package org.eclipse.aether.transport.apache;
020
021import org.eclipse.aether.ConfigurationProperties;
022import org.eclipse.aether.RepositorySystemSession;
023
024/**
025 * Configuration for Apache Transport.
026 *
027 * @since 2.0.0
028 */
029public final class ApacheTransporterConfigurationKeys {
030    private ApacheTransporterConfigurationKeys() {}
031
032    static final String CONFIG_PROPS_PREFIX =
033            ConfigurationProperties.PREFIX_TRANSPORT + ApacheTransporterFactory.NAME + ".";
034
035    /**
036     * If enabled, underlying Apache HttpClient will use system properties as well to configure itself (typically
037     * used to set up HTTP Proxy via Java system properties). See HttpClientBuilder for used properties. This mode
038     * is not recommended, better use documented ways of configuration instead. Proxy authentication may use
039     * {@code http.proxyUser}/{@code http.proxyPassword} or {@code https.proxyUser}/{@code https.proxyPassword}
040     * when the corresponding proxy host and port match. Explicit Resolver credentials take precedence;
041     * system proxy credentials are never used for repository authentication.
042     *
043     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
044     * @configurationType {@link java.lang.Boolean}
045     * @configurationDefaultValue {@link #DEFAULT_USE_SYSTEM_PROPERTIES}
046     * @configurationRepoIdSuffix Yes
047     */
048    public static final String CONFIG_PROP_USE_SYSTEM_PROPERTIES = CONFIG_PROPS_PREFIX + "useSystemProperties";
049
050    public static final boolean DEFAULT_USE_SYSTEM_PROPERTIES = false;
051
052    /**
053     * The name of retryHandler, supported values are “standard”, that obeys RFC-2616, regarding idempotent methods,
054     * and “default” that considers requests w/o payload as idempotent.
055     *
056     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
057     * @configurationType {@link java.lang.String}
058     * @configurationDefaultValue {@link #HTTP_RETRY_HANDLER_NAME_STANDARD}
059     * @configurationRepoIdSuffix Yes
060     */
061    public static final String CONFIG_PROP_HTTP_RETRY_HANDLER_NAME = CONFIG_PROPS_PREFIX + "retryHandler.name";
062
063    public static final String HTTP_RETRY_HANDLER_NAME_STANDARD = "standard";
064
065    public static final String HTTP_RETRY_HANDLER_NAME_DEFAULT = "default";
066
067    /**
068     * Set to true if it is acceptable to retry non-idempotent requests, that have been sent.
069     *
070     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
071     * @configurationType {@link java.lang.Boolean}
072     * @configurationDefaultValue {@link #DEFAULT_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED}
073     * @configurationRepoIdSuffix Yes
074     */
075    public static final String CONFIG_PROP_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED =
076            CONFIG_PROPS_PREFIX + "retryHandler.requestSentEnabled";
077
078    public static final boolean DEFAULT_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED = false;
079
080    /**
081     * Comma-separated list of
082     * <a href="https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#ciphersuites">Cipher
083     * Suites</a> which are enabled for HTTPS connections.
084     *
085     * @since 2.0.0
086     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
087     * @configurationType {@link java.lang.String}
088     */
089    public static final String CONFIG_PROP_CIPHER_SUITES = CONFIG_PROPS_PREFIX + "https.cipherSuites";
090
091    /**
092     * Comma-separated list of
093     * <a href="https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#jssenames">Protocols
094     * </a> which are enabled for HTTPS connections.
095     *
096     * @since 2.0.0
097     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
098     * @configurationType {@link java.lang.String}
099     */
100    public static final String CONFIG_PROP_PROTOCOLS = CONFIG_PROPS_PREFIX + "https.protocols";
101
102    /**
103     * If enabled, Apache HttpClient will follow HTTP redirects.
104     *
105     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
106     * @configurationType {@link Boolean}
107     * @configurationDefaultValue {@link #DEFAULT_FOLLOW_REDIRECTS}
108     * @configurationRepoIdSuffix Yes
109     * @since 2.0.2
110     */
111    public static final String CONFIG_PROP_FOLLOW_REDIRECTS = CONFIG_PROPS_PREFIX + "followRedirects";
112
113    public static final boolean DEFAULT_FOLLOW_REDIRECTS = true;
114
115    /**
116     * If enabled (default), operator-configured request headers ({@code aether.transport.http.headers}) are only
117     * sent on requests targeting the repository origin (the scheme, host and port the repository URL denotes).
118     * Apache HttpClient re-sends the original request headers on redirects, so without origin scoping a
119     * cross-origin redirect replays the configured headers - which frequently carry credentials such as
120     * {@code Authorization}, cookies or private token headers - to the redirect target host. Disable only when a
121     * redirect target legitimately requires the configured headers.
122     *
123     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
124     * @configurationType {@link Boolean}
125     * @configurationDefaultValue {@link #DEFAULT_ORIGIN_SCOPED_HEADERS}
126     * @configurationRepoIdSuffix Yes
127     * @since 2.0.23
128     */
129    public static final String CONFIG_PROP_ORIGIN_SCOPED_HEADERS = CONFIG_PROPS_PREFIX + "originScopedHeaders";
130
131    public static final boolean DEFAULT_ORIGIN_SCOPED_HEADERS = true;
132
133    /**
134     * The max redirect count to follow.
135     *
136     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
137     * @configurationType {@link java.lang.Integer}
138     * @configurationDefaultValue {@link #DEFAULT_MAX_REDIRECTS}
139     * @configurationRepoIdSuffix Yes
140     * @since 2.0.2
141     */
142    public static final String CONFIG_PROP_MAX_REDIRECTS = CONFIG_PROPS_PREFIX + "maxRedirects";
143
144    public static final int DEFAULT_MAX_REDIRECTS = 5;
145
146    /**
147     * If enabled, Apache HttpClient will follow redirects that downgrade the protocol from https to http. Disabled
148     * by default: such a downgrade strips transport encryption from artifact and checksum bytes and makes repository
149     * credentials eligible for transmission over plaintext, so a downgrading redirect fails the transfer instead.
150     *
151     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
152     * @configurationType {@link Boolean}
153     * @configurationDefaultValue {@link #DEFAULT_FOLLOW_INSECURE_REDIRECTS}
154     * @configurationRepoIdSuffix Yes
155     * @since 2.0.23
156     */
157    public static final String CONFIG_PROP_FOLLOW_INSECURE_REDIRECTS = CONFIG_PROPS_PREFIX + "followInsecureRedirects";
158
159    public static final boolean DEFAULT_FOLLOW_INSECURE_REDIRECTS = false;
160}