001/* 002 * Licensed to the Apache Software Foundation (ASF) under one 003 * or more contributor license agreements. See the NOTICE file 004 * distributed with this work for additional information 005 * regarding copyright ownership. The ASF licenses this file 006 * to you under the Apache License, Version 2.0 (the 007 * "License"); you may not use this file except in compliance 008 * with the License. You may obtain a copy of the License at 009 * 010 * http://www.apache.org/licenses/LICENSE-2.0 011 * 012 * Unless required by applicable law or agreed to in writing, 013 * software distributed under the License is distributed on an 014 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 015 * KIND, either express or implied. See the License for the 016 * specific language governing permissions and limitations 017 * under the License. 018 */ 019package org.eclipse.aether.spi.checksums; 020 021import java.util.List; 022import java.util.Map; 023 024import org.eclipse.aether.RepositorySystemSession; 025import org.eclipse.aether.repository.RemoteRepository; 026import org.eclipse.aether.spi.connector.ArtifactDownload; 027import org.eclipse.aether.spi.connector.MetadataDownload; 028import org.eclipse.aether.spi.connector.checksum.ChecksumAlgorithmFactory; 029import org.eclipse.aether.spi.connector.checksum.ChecksumPolicy; 030 031/** 032 * Component able to provide (expected) checksums to connector beforehand the download happens. Checksum provided by 033 * this component are of kind {@link ChecksumPolicy.ChecksumKind#PROVIDED}. Resolver by default provides one 034 * implementation: an adapter, that makes {@link TrustedChecksumsSource} into {@link ProvidedChecksumsSource}. Users 035 * are encouraged to rely on this adapter, and do not create their own implementations. 036 * 037 * @since 1.9.14 038 */ 039public interface ProvidedChecksumsSource { 040 /** 041 * May return the provided checksums (for given artifact transfer) from source other than remote repository, or 042 * {@code null} if it have no checksums available for given transfer. Provided checksums are "opt-in" for 043 * transfer, in a way IF they are available upfront, they will be enforced according to checksum policy 044 * in effect. Otherwise, provided checksum verification is completely left out. 045 * <p> 046 * For enabled provided checksum source is completely acceptable to return {@code null} values, as that carries 047 * the meaning "nothing to add here", as there are no checksums to be provided upfront transfer. Semantically, this 048 * is equivalent to returning empty map, but signals the intent better. 049 * 050 * @param session The current session. 051 * @param transfer The transfer that is about to be executed. 052 * @param remoteRepository The remote repository connector is about to contact. 053 * @param checksumAlgorithmFactories The checksum algorithms that are expected. 054 * @return Map of expected checksums, or {@code null}. 055 */ 056 Map<String, String> getProvidedArtifactChecksums( 057 RepositorySystemSession session, 058 ArtifactDownload transfer, 059 RemoteRepository remoteRepository, 060 List<ChecksumAlgorithmFactory> checksumAlgorithmFactories); 061 062 /** 063 * May return the provided checksums (for given metadata transfer) from source other than remote repository, 064 * or {@code null} if it has no checksums available for given transfer. Semantics are the same as for 065 * {@link #getProvidedArtifactChecksums(RepositorySystemSession, ArtifactDownload, RemoteRepository, List)}, 066 * but covering metadata downloads: metadata like {@code maven-metadata.xml} influences resolution decisions 067 * (for example version range selection), so it should be coverable by the strongest configured integrity 068 * source just like artifacts are. 069 * <p> 070 * The default implementation returns {@code null} ("nothing to add here"), preserving the behavior of 071 * implementations written before this method existed. 072 * 073 * @param session The current session. 074 * @param transfer The metadata transfer that is about to be executed. 075 * @param remoteRepository The remote repository connector is about to contact. 076 * @param checksumAlgorithmFactories The checksum algorithms that are expected. 077 * @return Map of expected checksums, or {@code null}. 078 * @since 2.0.23 079 */ 080 default Map<String, String> getProvidedMetadataChecksums( 081 RepositorySystemSession session, 082 MetadataDownload transfer, 083 RemoteRepository remoteRepository, 084 List<ChecksumAlgorithmFactory> checksumAlgorithmFactories) { 085 return null; 086 } 087}