1 /*
2 * Licensed to the Apache Software Foundation (ASF) under one
3 * or more contributor license agreements. See the NOTICE file
4 * distributed with this work for additional information
5 * regarding copyright ownership. The ASF licenses this file
6 * to you under the Apache License, Version 2.0 (the
7 * "License"); you may not use this file except in compliance
8 * with the License. You may obtain a copy of the License at
9 *
10 * http://www.apache.org/licenses/LICENSE-2.0
11 *
12 * Unless required by applicable law or agreed to in writing,
13 * software distributed under the License is distributed on an
14 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15 * KIND, either express or implied. See the License for the
16 * specific language governing permissions and limitations
17 * under the License.
18 */
19 package org.eclipse.aether.transport.apache;
20
21 import org.eclipse.aether.ConfigurationProperties;
22 import org.eclipse.aether.RepositorySystemSession;
23
24 /**
25 * Configuration for Apache Transport.
26 *
27 * @since 2.0.0
28 */
29 public final class ApacheTransporterConfigurationKeys {
30 private ApacheTransporterConfigurationKeys() {}
31
32 static final String CONFIG_PROPS_PREFIX =
33 ConfigurationProperties.PREFIX_TRANSPORT + ApacheTransporterFactory.NAME + ".";
34
35 /**
36 * If enabled, underlying Apache HttpClient will use system properties as well to configure itself (typically
37 * used to set up HTTP Proxy via Java system properties). See HttpClientBuilder for used properties. This mode
38 * is not recommended, better use documented ways of configuration instead. Proxy authentication may use
39 * {@code http.proxyUser}/{@code http.proxyPassword} or {@code https.proxyUser}/{@code https.proxyPassword}
40 * when the corresponding proxy host and port match. Explicit Resolver credentials take precedence;
41 * system proxy credentials are never used for repository authentication.
42 *
43 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
44 * @configurationType {@link java.lang.Boolean}
45 * @configurationDefaultValue {@link #DEFAULT_USE_SYSTEM_PROPERTIES}
46 * @configurationRepoIdSuffix Yes
47 */
48 public static final String CONFIG_PROP_USE_SYSTEM_PROPERTIES = CONFIG_PROPS_PREFIX + "useSystemProperties";
49
50 public static final boolean DEFAULT_USE_SYSTEM_PROPERTIES = false;
51
52 /**
53 * The name of retryHandler, supported values are “standard”, that obeys RFC-2616, regarding idempotent methods,
54 * and “default” that considers requests w/o payload as idempotent.
55 *
56 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
57 * @configurationType {@link java.lang.String}
58 * @configurationDefaultValue {@link #HTTP_RETRY_HANDLER_NAME_STANDARD}
59 * @configurationRepoIdSuffix Yes
60 */
61 public static final String CONFIG_PROP_HTTP_RETRY_HANDLER_NAME = CONFIG_PROPS_PREFIX + "retryHandler.name";
62
63 public static final String HTTP_RETRY_HANDLER_NAME_STANDARD = "standard";
64
65 public static final String HTTP_RETRY_HANDLER_NAME_DEFAULT = "default";
66
67 /**
68 * Set to true if it is acceptable to retry non-idempotent requests, that have been sent.
69 *
70 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
71 * @configurationType {@link java.lang.Boolean}
72 * @configurationDefaultValue {@link #DEFAULT_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED}
73 * @configurationRepoIdSuffix Yes
74 */
75 public static final String CONFIG_PROP_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED =
76 CONFIG_PROPS_PREFIX + "retryHandler.requestSentEnabled";
77
78 public static final boolean DEFAULT_HTTP_RETRY_HANDLER_REQUEST_SENT_ENABLED = false;
79
80 /**
81 * Comma-separated list of
82 * <a href="https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#ciphersuites">Cipher
83 * Suites</a> which are enabled for HTTPS connections.
84 *
85 * @since 2.0.0
86 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
87 * @configurationType {@link java.lang.String}
88 */
89 public static final String CONFIG_PROP_CIPHER_SUITES = CONFIG_PROPS_PREFIX + "https.cipherSuites";
90
91 /**
92 * Comma-separated list of
93 * <a href="https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#jssenames">Protocols
94 * </a> which are enabled for HTTPS connections.
95 *
96 * @since 2.0.0
97 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
98 * @configurationType {@link java.lang.String}
99 */
100 public static final String CONFIG_PROP_PROTOCOLS = CONFIG_PROPS_PREFIX + "https.protocols";
101
102 /**
103 * If enabled, Apache HttpClient will follow HTTP redirects.
104 *
105 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
106 * @configurationType {@link Boolean}
107 * @configurationDefaultValue {@link #DEFAULT_FOLLOW_REDIRECTS}
108 * @configurationRepoIdSuffix Yes
109 * @since 2.0.2
110 */
111 public static final String CONFIG_PROP_FOLLOW_REDIRECTS = CONFIG_PROPS_PREFIX + "followRedirects";
112
113 public static final boolean DEFAULT_FOLLOW_REDIRECTS = true;
114
115 /**
116 * If enabled (default), operator-configured request headers ({@code aether.transport.http.headers}) are only
117 * sent on requests targeting the repository origin (the scheme, host and port the repository URL denotes).
118 * Apache HttpClient re-sends the original request headers on redirects, so without origin scoping a
119 * cross-origin redirect replays the configured headers - which frequently carry credentials such as
120 * {@code Authorization}, cookies or private token headers - to the redirect target host. Disable only when a
121 * redirect target legitimately requires the configured headers.
122 *
123 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
124 * @configurationType {@link Boolean}
125 * @configurationDefaultValue {@link #DEFAULT_ORIGIN_SCOPED_HEADERS}
126 * @configurationRepoIdSuffix Yes
127 * @since 2.0.23
128 */
129 public static final String CONFIG_PROP_ORIGIN_SCOPED_HEADERS = CONFIG_PROPS_PREFIX + "originScopedHeaders";
130
131 public static final boolean DEFAULT_ORIGIN_SCOPED_HEADERS = true;
132
133 /**
134 * The max redirect count to follow.
135 *
136 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
137 * @configurationType {@link java.lang.Integer}
138 * @configurationDefaultValue {@link #DEFAULT_MAX_REDIRECTS}
139 * @configurationRepoIdSuffix Yes
140 * @since 2.0.2
141 */
142 public static final String CONFIG_PROP_MAX_REDIRECTS = CONFIG_PROPS_PREFIX + "maxRedirects";
143
144 public static final int DEFAULT_MAX_REDIRECTS = 5;
145
146 /**
147 * If enabled, Apache HttpClient will follow redirects that downgrade the protocol from https to http. Disabled
148 * by default: such a downgrade strips transport encryption from artifact and checksum bytes and makes repository
149 * credentials eligible for transmission over plaintext, so a downgrading redirect fails the transfer instead.
150 *
151 * @configurationSource {@link RepositorySystemSession#getConfigProperties()}
152 * @configurationType {@link Boolean}
153 * @configurationDefaultValue {@link #DEFAULT_FOLLOW_INSECURE_REDIRECTS}
154 * @configurationRepoIdSuffix Yes
155 * @since 2.0.23
156 */
157 public static final String CONFIG_PROP_FOLLOW_INSECURE_REDIRECTS = CONFIG_PROPS_PREFIX + "followInsecureRedirects";
158
159 public static final boolean DEFAULT_FOLLOW_INSECURE_REDIRECTS = false;
160 }