001/*
002 * Licensed to the Apache Software Foundation (ASF) under one
003 * or more contributor license agreements.  See the NOTICE file
004 * distributed with this work for additional information
005 * regarding copyright ownership.  The ASF licenses this file
006 * to you under the Apache License, Version 2.0 (the
007 * "License"); you may not use this file except in compliance
008 * with the License.  You may obtain a copy of the License at
009 *
010 *   http://www.apache.org/licenses/LICENSE-2.0
011 *
012 * Unless required by applicable law or agreed to in writing,
013 * software distributed under the License is distributed on an
014 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
015 * KIND, either express or implied.  See the License for the
016 * specific language governing permissions and limitations
017 * under the License.
018 */
019package org.eclipse.aether.transport.jetty;
020
021import org.eclipse.aether.ConfigurationProperties;
022import org.eclipse.aether.RepositorySystemSession;
023
024/**
025 * Configuration for Jetty Transport.
026 *
027 * @since 2.0.1
028 */
029public final class JettyTransporterConfigurationKeys {
030    private JettyTransporterConfigurationKeys() {}
031
032    static final String CONFIG_PROPS_PREFIX =
033            ConfigurationProperties.PREFIX_TRANSPORT + JettyTransporterFactory.NAME + ".";
034
035    /**
036     * If enabled, Jetty client will follow HTTP redirects.
037     *
038     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
039     * @configurationType {@link Boolean}
040     * @configurationDefaultValue {@link #DEFAULT_FOLLOW_REDIRECTS}
041     * @configurationRepoIdSuffix Yes
042     */
043    public static final String CONFIG_PROP_FOLLOW_REDIRECTS = CONFIG_PROPS_PREFIX + "followRedirects";
044
045    public static final boolean DEFAULT_FOLLOW_REDIRECTS = true;
046
047    /**
048     * The max redirect count to follow.
049     *
050     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
051     * @configurationType {@link Integer}
052     * @configurationDefaultValue {@link #DEFAULT_MAX_REDIRECTS}
053     * @configurationRepoIdSuffix Yes
054     */
055    public static final String CONFIG_PROP_MAX_REDIRECTS = CONFIG_PROPS_PREFIX + "maxRedirects";
056
057    public static final int DEFAULT_MAX_REDIRECTS = 5;
058
059    /**
060     * If enabled, Jetty client will follow redirects that downgrade the protocol from https to http. Disabled by
061     * default: such a downgrade strips transport encryption from artifact and checksum bytes and makes repository
062     * credentials eligible for transmission over plaintext, so a downgrading redirect fails the transfer instead.
063     *
064     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
065     * @configurationType {@link Boolean}
066     * @configurationDefaultValue {@link #DEFAULT_FOLLOW_INSECURE_REDIRECTS}
067     * @configurationRepoIdSuffix Yes
068     * @since 2.0.23
069     */
070    public static final String CONFIG_PROP_FOLLOW_INSECURE_REDIRECTS = CONFIG_PROPS_PREFIX + "followInsecureRedirects";
071
072    public static final boolean DEFAULT_FOLLOW_INSECURE_REDIRECTS = false;
073
074    /**
075     * If enabled (default), operator-configured request headers ({@code aether.transport.http.headers}) and
076     * preemptively applied {@code Authorization} are only sent on requests targeting the repository origin (the
077     * scheme, host and port the repository URL denotes). Jetty's redirector copies the request headers onto every
078     * redirect hop it follows, so without origin scoping a cross-origin redirect replays the configured headers -
079     * which frequently carry credentials such as {@code Authorization} or private token headers - to the redirect
080     * target host. Disable only when a redirect target legitimately requires the configured headers.
081     *
082     * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
083     * @configurationType {@link Boolean}
084     * @configurationDefaultValue {@link #DEFAULT_ORIGIN_SCOPED_HEADERS}
085     * @configurationRepoIdSuffix Yes
086     * @since 2.0.23
087     */
088    public static final String CONFIG_PROP_ORIGIN_SCOPED_HEADERS = CONFIG_PROPS_PREFIX + "originScopedHeaders";
089
090    public static final boolean DEFAULT_ORIGIN_SCOPED_HEADERS = true;
091}