View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one
3    * or more contributor license agreements.  See the NOTICE file
4    * distributed with this work for additional information
5    * regarding copyright ownership.  The ASF licenses this file
6    * to you under the Apache License, Version 2.0 (the
7    * "License"); you may not use this file except in compliance
8    * with the License.  You may obtain a copy of the License at
9    *
10   *   http://www.apache.org/licenses/LICENSE-2.0
11   *
12   * Unless required by applicable law or agreed to in writing,
13   * software distributed under the License is distributed on an
14   * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15   * KIND, either express or implied.  See the License for the
16   * specific language governing permissions and limitations
17   * under the License.
18   */
19  package org.eclipse.aether.transport.jetty;
20  
21  import org.eclipse.aether.ConfigurationProperties;
22  import org.eclipse.aether.RepositorySystemSession;
23  
24  /**
25   * Configuration for Jetty Transport.
26   *
27   * @since 2.0.1
28   */
29  public final class JettyTransporterConfigurationKeys {
30      private JettyTransporterConfigurationKeys() {}
31  
32      static final String CONFIG_PROPS_PREFIX =
33              ConfigurationProperties.PREFIX_TRANSPORT + JettyTransporterFactory.NAME + ".";
34  
35      /**
36       * If enabled, Jetty client will follow HTTP redirects.
37       *
38       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
39       * @configurationType {@link Boolean}
40       * @configurationDefaultValue {@link #DEFAULT_FOLLOW_REDIRECTS}
41       * @configurationRepoIdSuffix Yes
42       */
43      public static final String CONFIG_PROP_FOLLOW_REDIRECTS = CONFIG_PROPS_PREFIX + "followRedirects";
44  
45      public static final boolean DEFAULT_FOLLOW_REDIRECTS = true;
46  
47      /**
48       * The max redirect count to follow.
49       *
50       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
51       * @configurationType {@link Integer}
52       * @configurationDefaultValue {@link #DEFAULT_MAX_REDIRECTS}
53       * @configurationRepoIdSuffix Yes
54       */
55      public static final String CONFIG_PROP_MAX_REDIRECTS = CONFIG_PROPS_PREFIX + "maxRedirects";
56  
57      public static final int DEFAULT_MAX_REDIRECTS = 5;
58  
59      /**
60       * If enabled, Jetty client will follow redirects that downgrade the protocol from https to http. Disabled by
61       * default: such a downgrade strips transport encryption from artifact and checksum bytes and makes repository
62       * credentials eligible for transmission over plaintext, so a downgrading redirect fails the transfer instead.
63       *
64       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
65       * @configurationType {@link Boolean}
66       * @configurationDefaultValue {@link #DEFAULT_FOLLOW_INSECURE_REDIRECTS}
67       * @configurationRepoIdSuffix Yes
68       * @since 2.0.23
69       */
70      public static final String CONFIG_PROP_FOLLOW_INSECURE_REDIRECTS = CONFIG_PROPS_PREFIX + "followInsecureRedirects";
71  
72      public static final boolean DEFAULT_FOLLOW_INSECURE_REDIRECTS = false;
73  
74      /**
75       * If enabled (default), operator-configured request headers ({@code aether.transport.http.headers}) and
76       * preemptively applied {@code Authorization} are only sent on requests targeting the repository origin (the
77       * scheme, host and port the repository URL denotes). Jetty's redirector copies the request headers onto every
78       * redirect hop it follows, so without origin scoping a cross-origin redirect replays the configured headers -
79       * which frequently carry credentials such as {@code Authorization} or private token headers - to the redirect
80       * target host. Disable only when a redirect target legitimately requires the configured headers.
81       *
82       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
83       * @configurationType {@link Boolean}
84       * @configurationDefaultValue {@link #DEFAULT_ORIGIN_SCOPED_HEADERS}
85       * @configurationRepoIdSuffix Yes
86       * @since 2.0.23
87       */
88      public static final String CONFIG_PROP_ORIGIN_SCOPED_HEADERS = CONFIG_PROPS_PREFIX + "originScopedHeaders";
89  
90      public static final boolean DEFAULT_ORIGIN_SCOPED_HEADERS = true;
91  }