001/* 002 * Licensed to the Apache Software Foundation (ASF) under one 003 * or more contributor license agreements. See the NOTICE file 004 * distributed with this work for additional information 005 * regarding copyright ownership. The ASF licenses this file 006 * to you under the Apache License, Version 2.0 (the 007 * "License"); you may not use this file except in compliance 008 * with the License. You may obtain a copy of the License at 009 * 010 * http://www.apache.org/licenses/LICENSE-2.0 011 * 012 * Unless required by applicable law or agreed to in writing, 013 * software distributed under the License is distributed on an 014 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 015 * KIND, either express or implied. See the License for the 016 * specific language governing permissions and limitations 017 * under the License. 018 */ 019package org.eclipse.aether.transport.jetty; 020 021import org.eclipse.aether.ConfigurationProperties; 022import org.eclipse.aether.RepositorySystemSession; 023 024/** 025 * Configuration for Jetty Transport. 026 * 027 * @since 2.0.1 028 */ 029public final class JettyTransporterConfigurationKeys { 030 private JettyTransporterConfigurationKeys() {} 031 032 static final String CONFIG_PROPS_PREFIX = 033 ConfigurationProperties.PREFIX_TRANSPORT + JettyTransporterFactory.NAME + "."; 034 035 /** 036 * If enabled, Jetty client will follow HTTP redirects. 037 * 038 * @configurationSource {@link RepositorySystemSession#getConfigProperties()} 039 * @configurationType {@link Boolean} 040 * @configurationDefaultValue {@link #DEFAULT_FOLLOW_REDIRECTS} 041 * @configurationRepoIdSuffix Yes 042 */ 043 public static final String CONFIG_PROP_FOLLOW_REDIRECTS = CONFIG_PROPS_PREFIX + "followRedirects"; 044 045 public static final boolean DEFAULT_FOLLOW_REDIRECTS = true; 046 047 /** 048 * The max redirect count to follow. 049 * 050 * @configurationSource {@link RepositorySystemSession#getConfigProperties()} 051 * @configurationType {@link Integer} 052 * @configurationDefaultValue {@link #DEFAULT_MAX_REDIRECTS} 053 * @configurationRepoIdSuffix Yes 054 */ 055 public static final String CONFIG_PROP_MAX_REDIRECTS = CONFIG_PROPS_PREFIX + "maxRedirects"; 056 057 public static final int DEFAULT_MAX_REDIRECTS = 5; 058 059 /** 060 * If enabled, Jetty client will follow redirects that downgrade the protocol from https to http. Disabled by 061 * default: such a downgrade strips transport encryption from artifact and checksum bytes and makes repository 062 * credentials eligible for transmission over plaintext, so a downgrading redirect fails the transfer instead. 063 * 064 * @configurationSource {@link RepositorySystemSession#getConfigProperties()} 065 * @configurationType {@link Boolean} 066 * @configurationDefaultValue {@link #DEFAULT_FOLLOW_INSECURE_REDIRECTS} 067 * @configurationRepoIdSuffix Yes 068 * @since 2.0.23 069 */ 070 public static final String CONFIG_PROP_FOLLOW_INSECURE_REDIRECTS = CONFIG_PROPS_PREFIX + "followInsecureRedirects"; 071 072 public static final boolean DEFAULT_FOLLOW_INSECURE_REDIRECTS = false; 073 074 /** 075 * If enabled (default), operator-configured request headers ({@code aether.transport.http.headers}) and 076 * preemptively applied {@code Authorization} are only sent on requests targeting the repository origin (the 077 * scheme, host and port the repository URL denotes). Jetty's redirector copies the request headers onto every 078 * redirect hop it follows, so without origin scoping a cross-origin redirect replays the configured headers - 079 * which frequently carry credentials such as {@code Authorization} or private token headers - to the redirect 080 * target host. Disable only when a redirect target legitimately requires the configured headers. 081 * 082 * @configurationSource {@link RepositorySystemSession#getConfigProperties()} 083 * @configurationType {@link Boolean} 084 * @configurationDefaultValue {@link #DEFAULT_ORIGIN_SCOPED_HEADERS} 085 * @configurationRepoIdSuffix Yes 086 * @since 2.0.23 087 */ 088 public static final String CONFIG_PROP_ORIGIN_SCOPED_HEADERS = CONFIG_PROPS_PREFIX + "originScopedHeaders"; 089 090 public static final boolean DEFAULT_ORIGIN_SCOPED_HEADERS = true; 091}