Skip to content

fix(pm): support authenticated private registries - #2624

Open
RSS1102 wants to merge 8 commits into
voidzero-dev:mainfrom
RSS1102:rss1102/issue-2603-private-registry-auth
Open

RSS1102 wants to merge 8 commits into
voidzero-dev:mainfrom
RSS1102:rss1102/issue-2603-private-registry-auth

Conversation

@RSS1102

@RSS1102 RSS1102 commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Vite+ previously ignored .npmrc credentials when bootstrapping a package manager, causing downloads from authenticated private registries to fail with 401.

Load registry settings and scoped credentials from explicit global config, user config, workspace config, and npm_config_* environment variables, in that precedence order. Support bearer and Basic authentication, npm-style variable expansion, and common .npmrc encoding and quoting conventions.

Match credentials to the request host, port, and path, and recheck them on redirects. Keep authenticated metadata out of the shared latest-version cache.

Closes #2603

@netlify

netlify Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for viteplus-preview canceled.

Name Link
🔨 Latest commit 0ef0c52
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a9ff12e7e3a50000892a96e

@RSS1102
RSS1102 marked this pull request as ready for review September 8, 2026 12:11
@RSS1102 RSS1102 closed this Sep 9, 2026
@RSS1102 RSS1102 reopened this Sep 9, 2026
@fengmk2

fengmk2 commented Sep 10, 2026

Copy link
Copy Markdown
Member

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T11:39:23.339767Z 7c035ba Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f8c77a4a09

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/config.rs
Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/config.rs Outdated
@RSS1102
RSS1102 marked this pull request as draft September 11, 2026 02:47
@RSS1102
RSS1102 marked this pull request as ready for review September 16, 2026 08:05
@RSS1102
RSS1102 force-pushed the rss1102/issue-2603-private-registry-auth branch 4 times, most recently from e27a3c5 to b3ef6bd Compare September 28, 2026 09:52
@RSS1102
RSS1102 force-pushed the rss1102/issue-2603-private-registry-auth branch 2 times, most recently from 7df44ae to 4e2cfc0 Compare October 8, 2026 08:34
@RSS1102
RSS1102 force-pushed the rss1102/issue-2603-private-registry-auth branch from 4e2cfc0 to 1e3becc Compare October 8, 2026 08:46
@fengmk2
fengmk2 requested a review from liangmiQwQ October 8, 2026 09:03
@fengmk2 fengmk2 self-assigned this Oct 8, 2026

@fengmk2 fengmk2 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please address the credential-key expansion gap and the cache upgrade regression described in the inline comments.

Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/package_manager.rs
Expand npm credential keys before normalization, isolate the latest-version cache from legacy files, redact optional Vitest transform hints, and forward workspace cwd through the package-manager NAPI download entrypoint. Add regression coverage for each path.
@RSS1102
RSS1102 marked this pull request as draft October 9, 2026 02:57
@RSS1102
RSS1102 marked this pull request as ready for review October 9, 2026 06:30
@fengmk2

fengmk2 commented Oct 9, 2026

Copy link
Copy Markdown
Member

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 34d57c4a2b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vp_pm_cli/src/config.rs Outdated
Comment thread crates/vp_pm_cli/src/config.rs

@liangmiQwQ liangmiQwQ left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Direction and division of responsibilities LGTM 💯

@fengmk2

fengmk2 commented Oct 10, 2026

Copy link
Copy Markdown
Member

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c035baad8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


// A default global npmrc cannot be located reliably before npm exists.
// Honor an explicitly configured one, then layer user and project config.
if let Some(path) = env_value("globalconfig") {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Load globalconfig selected by the user npmrc

When $HOME/.npmrc contains globalconfig=/corp/npmrc, this lookup checks only the environment before the user file is parsed, and the later globalconfig value is never consumed as a path. The upstream npm configuration loader explicitly states that globalconfig set by the userconfig file is used to load global configs; as written, registry credentials kept in that corporate config are skipped, so a workspace pointing at the private registry receives a 401 (or falls back to the public registry). Resolve the global config path after reading the user layer while preserving global config's lower value precedence.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support authenticated private registries beyond NPM_CONFIG_REGISTRY

3 participants