slachiewicz opened a new issue, #2159:
URL: https://github.com/apache/maven-resolver/issues/2159

   ### Affected version
   
   2.0.23, 2.0.24-SNAPSHOT
   
   ### Bug description
   
   In #2135, 
`EnhancedLocalRepositoryManagerFactory.DEFAULT_LEGACY_LOCAL_REPOSITORY` was 
introduced with a default value of `true`.
   
   When `legacyLocalRepository` is enabled, 
`EnhancedLocalRepositoryManager.applyTracking` includes a same-ID fallback for 
URL-qualified tracking keys:
   ```java
   String repoIdPrefix = getKey(path, legacyKey + "-");
   for (Object key : props.keySet()) {
       String k = key.toString();
       if (k.startsWith(repoIdPrefix) && !k.equals(getKey(path, trackingKey))) {
           result.setAvailable(true);
           result.setRepository(repository);
           return true;
       }
   }
   ```
   
   Because `legacyLocalRepository` defaults to `true`, this prefix fallback is 
active by default across all sessions. As a result, if an artifact was 
previously downloaded and cached from a remote repository sharing the same 
repository ID (e.g., `central` or a corporate repository ID) but with a 
different URL, `applyTracking` accepts the locally cached artifact for requests 
targeting other URLs without validating the URL hash.
   
   This relaxes the URL-qualified provenance tracking introduced in Resolver 2 
and allows same-ID collisions across different repository URLs to satisfy 
artifact lookups.
   
   To preserve strict URL-qualified origin tracking by default in Resolver 2 
while still allowing users to opt into legacy behavior when sharing a local 
repository with Maven 3.9 / Resolver 1.x, `DEFAULT_LEGACY_LOCAL_REPOSITORY` 
should default to `false`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to