Uploaded image for project: 'Dev - Nexus Repo'
  1. Dev - Nexus Repo
  2. NEXUS-7889

RUT Auth does not work for /content URL's

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 2.11.1
    • Fix Version/s: 3.0.0-m3, 2.11.2
    • Component/s: Security
    • Labels:
      None
    • Story Points:
      3
    • Sprint:
      Sprint 34

      Description

      Disable anonymous access in Nexus, and configure RUT auth. This works for /service/local URL's:

      $ curl -I -H "X-Forwarded-User: admin" http://localhost:8081/nexus/service/local/status
      HTTP/1.1 200 OK
      Date: Thu, 08 Jan 2015 15:07:24 GMT
      Server: Nexus/2.11.1-01
      X-Frame-Options: SAMEORIGIN
      X-Content-Type-Options: nosniff
      Set-Cookie: JSESSIONID=a84d2426-6dd9-4d32-a9e3-ad969ebf1ece; Path=/nexus; HttpOnly
      Set-Cookie: rememberMe=deleteMe; Path=/nexus; Max-Age=0; Expires=Wed, 07-Jan-2015 15:07:24 GMT
      Content-Type: application/xml; charset=UTF-8
      Date: Thu, 08 Jan 2015 15:07:24 GMT
      Vary: Accept-Charset, Accept-Encoding, Accept-Language, Accept
      Server: Noelios-Restlet-Engine/1.1.6-SONATYPE-5348-V8
      Content-Length: 1144
      

      It does not work for /content URLs:

      $ curl -I -H "X-Forwarded-User: admin" http://localhost:8081/nexus/content/repositories/releases/.meta/repository-metadata.xml
      HTTP/1.1 401 Unauthorized
      Date: Thu, 08 Jan 2015 15:08:10 GMT
      Server: Nexus/2.11.1-01
      X-Frame-Options: SAMEORIGIN
      X-Content-Type-Options: nosniff
      WWW-Authenticate: BASIC realm="Sonatype Nexus Repository Manager"
      Content-Length: 0
      

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              cstamas Tamás Cservenák
              Reporter:
              rseddon Rich Seddon
              Last Updated By:
              Peter Lynch Peter Lynch
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Date of First Response:

                  tigCommentSecurity.panel-title