slachiewicz opened a new issue, #2159:
URL: https://github.com/apache/maven-resolver/issues/2159
### Affected version
2.0.23, 2.0.24-SNAPSHOT
### Bug description
In #2135,
`EnhancedLocalRepositoryManagerFactory.DEFAULT_LEGACY_LOCAL_REPOSITORY` was
introduced with a default value of `true`.
When `legacyLocalRepository` is enabled,
`EnhancedLocalRepositoryManager.applyTracking` includes a same-ID fallback for
URL-qualified tracking keys:
```java
String repoIdPrefix = getKey(path, legacyKey + "-");
for (Object key : props.keySet()) {
String k = key.toString();
if (k.startsWith(repoIdPrefix) && !k.equals(getKey(path, trackingKey))) {
result.setAvailable(true);
result.setRepository(repository);
return true;
}
}
```
Because `legacyLocalRepository` defaults to `true`, this prefix fallback is
active by default across all sessions. As a result, if an artifact was
previously downloaded and cached from a remote repository sharing the same
repository ID (e.g., `central` or a corporate repository ID) but with a
different URL, `applyTracking` accepts the locally cached artifact for requests
targeting other URLs without validating the URL hash.
This relaxes the URL-qualified provenance tracking introduced in Resolver 2
and allows same-ID collisions across different repository URLs to satisfy
artifact lookups.
To preserve strict URL-qualified origin tracking by default in Resolver 2
while still allowing users to opt into legacy behavior when sharing a local
repository with Maven 3.9 / Resolver 1.x, `DEFAULT_LEGACY_LOCAL_REPOSITORY`
should default to `false`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]