View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one
3    * or more contributor license agreements.  See the NOTICE file
4    * distributed with this work for additional information
5    * regarding copyright ownership.  The ASF licenses this file
6    * to you under the Apache License, Version 2.0 (the
7    * "License"); you may not use this file except in compliance
8    * with the License.  You may obtain a copy of the License at
9    *
10   *   http://www.apache.org/licenses/LICENSE-2.0
11   *
12   * Unless required by applicable law or agreed to in writing,
13   * software distributed under the License is distributed on an
14   * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15   * KIND, either express or implied.  See the License for the
16   * specific language governing permissions and limitations
17   * under the License.
18   */
19  package org.eclipse.aether.transport.apache;
20  
21  import org.eclipse.aether.ConfigurationProperties;
22  import org.eclipse.aether.RepositorySystemSession;
23  
24  /**
25   * Configuration for Apache Transport.
26   *
27   * @since 2.0.0
28   */
29  public final class ApacheTransporterConfigurationKeys {
30      private ApacheTransporterConfigurationKeys() {}
31  
32      static final String CONFIG_PROPS_PREFIX =
33              ConfigurationProperties.PREFIX_TRANSPORT + ApacheTransporterFactory.NAME + ".";
34  
35      /**
36       * If enabled, underlying Apache HttpClient will use system properties as well to configure itself (typically
37       * used to set up HTTP Proxy via Java system properties). See HttpClientBuilder for used properties. This mode
38       * is not recommended, better use documented ways of configuration instead. Proxy authentication may use
39       * {@code http.proxyUser}/{@code http.proxyPassword} or {@code https.proxyUser}/{@code https.proxyPassword}
40       * when the corresponding proxy host and port match. Explicit Resolver credentials take precedence;
41       * system proxy credentials are never used for repository authentication.
42       *
43       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
44       * @configurationType {@link java.lang.Boolean}
45       * @configurationDefaultValue {@link #DEFAULT_USE_SYSTEM_PROPERTIES}
46       * @configurationRepoIdSuffix Yes
47       */
48      public static final String CONFIG_PROP_USE_SYSTEM_PROPERTIES = CONFIG_PROPS_PREFIX + "useSystemProperties";
49  
50      public static final boolean DEFAULT_USE_SYSTEM_PROPERTIES = false;
51  
52      /**
53       * The name of retryHandler, supported values are “standard”, that obeys RFC-2616, regarding idempotent methods,
54       * and “default” that considers requests w/o payload as idempotent.
55       *
56       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
57       * @configurationType {@link java.lang.String}
58       * @configurationDefaultValue {@link #HTTP_RETRY_HANDLER_NAME_STANDARD}
59       * @configurationRepoIdSuffix Yes
60       */
61      public static final String CONFIG_PROP_HTTP_RETRY_HANDLER_NAME = CONFIG_PROPS_PREFIX + "retryHandler.name";
62  
63      public static final String HTTP_RETRY_HANDLER_NAME_STANDARD = "standard";
64  
65      public static final String HTTP_RETRY_HANDLER_NAME_DEFAULT = "default";
66  
67      /**
68       * Set to true if it is acceptable to retry non-idempotent requests, that have been sent.
69       *
70       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
71       * @configurationType {@link java.lang.Boolean}
72       * @configurationDefaultValue {@link #DEFAULT_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED}
73       * @configurationRepoIdSuffix Yes
74       */
75      public static final String CONFIG_PROP_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED =
76              CONFIG_PROPS_PREFIX + "retryHandler.requestSentEnabled";
77  
78      public static final boolean DEFAULT_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED = false;
79  
80      /**
81       * Comma-separated list of
82       * <a href="https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#ciphersuites">Cipher
83       * Suites</a> which are enabled for HTTPS connections.
84       *
85       * @since 2.0.0
86       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
87       * @configurationType {@link java.lang.String}
88       */
89      public static final String CONFIG_PROP_CIPHER_SUITES = CONFIG_PROPS_PREFIX + "https.cipherSuites";
90  
91      /**
92       * Comma-separated list of
93       * <a href="https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#jssenames">Protocols
94       * </a> which are enabled for HTTPS connections.
95       *
96       * @since 2.0.0
97       * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
98       * @configurationType {@link java.lang.String}
99       */
100     public static final String CONFIG_PROP_PROTOCOLS = CONFIG_PROPS_PREFIX + "https.protocols";
101 
102     /**
103      * If enabled, Apache HttpClient will follow HTTP redirects.
104      *
105      * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
106      * @configurationType {@link Boolean}
107      * @configurationDefaultValue {@link #DEFAULT_FOLLOW_REDIRECTS}
108      * @configurationRepoIdSuffix Yes
109      * @since 2.0.2
110      */
111     public static final String CONFIG_PROP_FOLLOW_REDIRECTS = CONFIG_PROPS_PREFIX + "followRedirects";
112 
113     public static final boolean DEFAULT_FOLLOW_REDIRECTS = true;
114 
115     /**
116      * If enabled (default), operator-configured request headers ({@code aether.transport.http.headers}) are only
117      * sent on requests targeting the repository origin (the scheme, host and port the repository URL denotes).
118      * Apache HttpClient re-sends the original request headers on redirects, so without origin scoping a
119      * cross-origin redirect replays the configured headers - which frequently carry credentials such as
120      * {@code Authorization}, cookies or private token headers - to the redirect target host. Disable only when a
121      * redirect target legitimately requires the configured headers.
122      *
123      * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
124      * @configurationType {@link Boolean}
125      * @configurationDefaultValue {@link #DEFAULT_ORIGIN_SCOPED_HEADERS}
126      * @configurationRepoIdSuffix Yes
127      * @since 2.0.23
128      */
129     public static final String CONFIG_PROP_ORIGIN_SCOPED_HEADERS = CONFIG_PROPS_PREFIX + "originScopedHeaders";
130 
131     public static final boolean DEFAULT_ORIGIN_SCOPED_HEADERS = true;
132 
133     /**
134      * The max redirect count to follow.
135      *
136      * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
137      * @configurationType {@link java.lang.Integer}
138      * @configurationDefaultValue {@link #DEFAULT_MAX_REDIRECTS}
139      * @configurationRepoIdSuffix Yes
140      * @since 2.0.2
141      */
142     public static final String CONFIG_PROP_MAX_REDIRECTS = CONFIG_PROPS_PREFIX + "maxRedirects";
143 
144     public static final int DEFAULT_MAX_REDIRECTS = 5;
145 
146     /**
147      * If enabled, Apache HttpClient will follow redirects that downgrade the protocol from https to http. Disabled
148      * by default: such a downgrade strips transport encryption from artifact and checksum bytes and makes repository
149      * credentials eligible for transmission over plaintext, so a downgrading redirect fails the transfer instead.
150      *
151      * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
152      * @configurationType {@link Boolean}
153      * @configurationDefaultValue {@link #DEFAULT_FOLLOW_INSECURE_REDIRECTS}
154      * @configurationRepoIdSuffix Yes
155      * @since 2.0.23
156      */
157     public static final String CONFIG_PROP_FOLLOW_INSECURE_REDIRECTS = CONFIG_PROPS_PREFIX + "followInsecureRedirects";
158 
159     public static final boolean DEFAULT_FOLLOW_INSECURE_REDIRECTS = false;
160 }