Skip to content

feat: support Maven server credential origins - #1282

Open
YunaBraska wants to merge 2 commits into
actions:mainfrom
YunaBraska:feature/maven-server-origins
Open

YunaBraska wants to merge 2 commits into
actions:mainfrom
YunaBraska:feature/maven-server-origins

Conversation

@YunaBraska

@YunaBraska YunaBraska commented Oct 5, 2026 •

Copy link
Copy Markdown

Why

Maven 3.10 scopes a settings.xml server credential to repository origins. setup-java can generate Maven server credentials, but cannot declare the corresponding <repositoryOrigins>. When a publisher resolves a repository dynamically, such as Central Publishing using https://central.sonatype.com, Maven intentionally withholds the configured credential and deployment fails with HTTP 401.

This is the behaviour introduced by Maven 3.10: release notes, settings reference, and implementation change.

Consumers currently have to patch the settings.xml generated by this action after every setup step.

What

  • Add mvn-server-repository-origins, a multiline server-id:repository-origin input.
  • Generate <repositoryOrigins> within the matching Maven server.
  • Normalize origins and reject malformed values, paths, credentials, query strings, fragments, and unknown server IDs.
  • Document Central Publishing and multi-server use.

Example:

with:
  server-id: central
  server-username-env-var: CENTRAL_USER
  server-password-env-var: CENTRAL_PASS
  mvn-server-repository-origins: |
    central:https://central.sonatype.com

Verification

npm run check

  • 45 test suites passed
  • 1,523 tests passed
  • format, lint, bundle build, and coverage all passed

@YunaBraska
YunaBraska requested a review from a team as a code owner October 5, 2026 16:31
@brunoborges
brunoborges requested a balanced review from Copilot October 5, 2026 17:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Origin parsing accepts malformed values and can normalize non-HTTP ports incompatibly with Maven.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds Maven 3.10 repository-origin scoping for generated server credentials.

Changes:

  • Adds and validates mvn-server-repository-origins.
  • Emits <repositoryOrigins> in Maven settings.
  • Updates tests, documentation, and distribution bundles.
File Description
src/​constants.ts Defines the new input.
src/​auth.ts Parses origins and generates XML.
README.md Documents the input.
docs/​advanced-usage.md Adds multi-server examples.
action.yml Exposes the action input.
__tests__/​auth.test.ts Tests parsing and generation.
dist/​setup/​index.js Updates the setup bundle.
dist/​setup/​81.index.js Bundles authentication logic.
dist/​cleanup/​index.js Updates bundled constants.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/auth.ts
Comment on lines +196 to +200
let url: URL;
try {
url = new URL(value);
} catch {
throw new Error(
Comment thread src/auth.ts Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants