Class InstallFileMojo
java.lang.Object
org.apache.maven.plugin.AbstractMojo
org.apache.maven.plugins.install.InstallFileMojo
- All Implemented Interfaces:
org.apache.maven.plugin.ContextEnabled, org.apache.maven.plugin.Mojo
@Mojo(name="install-file",
requiresProject=false,
aggregator=true,
threadSafe=true)
public class InstallFileMojo
extends org.apache.maven.plugin.AbstractMojo
Installs a file in the local repository.
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate StringArtifactId of the artifact to be installed.private StringClassifier type of the artifact to be installed.private static final PatternTheencodingpseudo-attribute of an XML declaration.private StringExtension of the artifact to be installed.private FileThe file to be installed in the local repository.private BooleanGenerate a minimal POM for the artifact if none is supplied via the parameterpomFile.private StringGroupId of the artifact to be installed.private static final Stringprivate FileThe bundled API docs for the artifact.private FileThe path for a specific local repository directory.private final org.slf4j.Loggerprivate static final Stringprivate StringPackaging type of the artifact to be installed.private static final Patternprivate FileLocation of an existing POM file to be installed alongside the main artifact, given by thefileparameter.private final org.eclipse.aether.RepositorySystemprivate org.apache.maven.execution.MavenSessionprivate FileThe bundled sources for the artifact.private StringVersion of the artifact to be installed.Fields inherited from interface org.apache.maven.plugin.Mojo
ROLE -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprivate CharsetcharsetOrFail(String name, String entryName) Resolves a detected or declared encoding name, failing closed if this JVM cannot decode it.private booleancontentDiffers(File existing, File candidate) Returnstrueif the two files exist with different content, or cannot be compared (fail-closed for warning purposes).private voidcrossCheckOperatorCoordinates(String entryName, org.apache.maven.model.Model model) Cross-checks every operator-supplied coordinate (groupId, artifactId, version) against the effective values declared by the embedded POM and fails on any mismatch.private CharsetdetectXmlCharset(byte[] bytes, String entryName) Detects the character encoding of raw XML bytes the way an XML parser is required to (XML 1.0 Appendix F): byte-order mark first, then the byte pattern of a leading<?xml, then theencodingpseudo-attribute of the XML declaration, defaulting to UTF-8.voidexecute()private org.apache.maven.model.ModelGenerates a minimal model from the user-supplied artifact information.private FileGenerates a (temporary) POM file from the plugin configuration.private FilegetLocalRepositoryFile(org.eclipse.aether.RepositorySystemSession session, org.eclipse.aether.artifact.Artifact artifact) Gets the path of the specified artifact within the local repository.private FilegetPomLocalRepositoryFile(org.eclipse.aether.RepositorySystemSession session, org.eclipse.aether.artifact.Artifact artifact) Gets the path of the specified artifact POM within the local repository.private booleanisValidGroupId(String groupId) Returnstrueif passed in string is a valid Maven groupId: a valid ID whose dot-separated segments are all non-empty.private booleanReturnstrueif passed in string is "valid Maven ID" (artifactId or packaging): non-empty, not consisting solely of'.'characters (so it can never form a./..path segment in the local repository layout), and using only allowed characters.private booleanisValidVersion(String version) Returnstrueif passed in string is "valid Maven (simple.private voidprocessModel(org.apache.maven.model.Model model) Populates missing mojo parameters from the specified POM.private Fileprivate org.apache.maven.model.ModelParses a POM.private voidrejectDoctype(Path embeddedPom, String entryName) Defense-in-depth pre-screen for the JAR embedded POM: the entry is wire-origin, potentially attacker-authored XML, and it is handed toMavenXpp3Readerwhose DTD and external-entity posture this plugin can neither configure nor guarantee across core versions.private voidvalidateEmbeddedPomEntryPath(String entryName, org.apache.maven.model.Model model) Verifies that the<groupId>/<artifactId>components of the matchedMETA-INF/maven/<groupId>/<artifactId>/pom.xmlentry path agree with the effective coordinates declared by the embedded POM itself.private voidverifyContainment(org.eclipse.aether.RepositorySystemSession repoSession, File artifactLocalFile) Defense in depth: verifies that the composed layout path stays inside the local repository.Methods inherited from class org.apache.maven.plugin.AbstractMojo
getLog, getPluginContext, setLog, setPluginContext
-
Field Details
-
LS
-
ILLEGAL_VERSION_CHARS
- See Also:
-
ENCODING_PSEUDO_ATTR
Theencodingpseudo-attribute of an XML declaration. -
log
private final org.slf4j.Logger log -
repositorySystem
private final org.eclipse.aether.RepositorySystem repositorySystem -
session
@Parameter(defaultValue="${session}", required=true, readonly=true) private org.apache.maven.execution.MavenSession session -
groupId
GroupId of the artifact to be installed. Retrieved from POM file if one is specified or extracted frompom.xmlin jar if available. -
artifactId
ArtifactId of the artifact to be installed. Retrieved from POM file if one is specified or extracted frompom.xmlin jar if available. -
version
Version of the artifact to be installed. Retrieved from POM file if one is specified or extracted frompom.xmlin jar if available. -
packaging
Packaging type of the artifact to be installed. Retrieved from POM file if one is specified or extracted frompom.xmlin jar if available. -
classifier
Classifier type of the artifact to be installed. For example, "sources" or "javadoc". Defaults to none which means this is the project's main artifact.- Since:
- 2.2
-
extension
Extension of the artifact to be installed. If set, will override plugin own logic to detect extension. If not set, as Maven expected, packaging determines the artifact extension.- Since:
- 3.1.3
-
file
The file to be installed in the local repository. -
javadoc
The bundled API docs for the artifact.- Since:
- 2.3
-
sources
The bundled sources for the artifact.- Since:
- 2.3
-
pomFile
-
generatePom
-
localRepositoryPath
The path for a specific local repository directory. If not specified the local repository path configured in the Maven settings will be used.- Since:
- 2.2
-
IS_EMPTY
-
IS_POM_PACKAGING
-
POM_ENTRY_PATTERN
-
IS_POM_ENTRY
-
-
Constructor Details
-
InstallFileMojo
@Inject public InstallFileMojo(org.eclipse.aether.RepositorySystem repositorySystem)
-
-
Method Details
-
execute
public void execute() throws org.apache.maven.plugin.MojoExecutionException, org.apache.maven.plugin.MojoFailureException- Throws:
org.apache.maven.plugin.MojoExecutionExceptionorg.apache.maven.plugin.MojoFailureException
-
readingPomFromJarFile
- Throws:
org.apache.maven.plugin.MojoExecutionException
-
readModel
private org.apache.maven.model.Model readModel(File pomFile) throws org.apache.maven.plugin.MojoExecutionException Parses a POM.- Parameters:
pomFile- The path of the POM file to parse, must not benull.- Returns:
- The model from the POM file, never
null. - Throws:
org.apache.maven.plugin.MojoExecutionException- If the POM could not be parsed.
-
rejectDoctype
private void rejectDoctype(Path embeddedPom, String entryName) throws org.apache.maven.plugin.MojoExecutionException Defense-in-depth pre-screen for the JAR embedded POM: the entry is wire-origin, potentially attacker-authored XML, and it is handed toMavenXpp3Readerwhose DTD and external-entity posture this plugin can neither configure nor guarantee across core versions. A valid POM never carries a DOCTYPE declaration, so any embedded POM containing one is rejected before it reaches the parser. The scan is encoding-aware: the bytes are decoded with the same charset an XML parser is required to autodetect (BOM / first-bytes / encoding pseudo-attribute, XML 1.0 Appendix F), so a UTF-16 or UTF-32 document cannot smuggle a NUL-interleaved DOCTYPE past a naive single-byte scan. This intentionally does not apply to the operator's own-DpomFile.- Parameters:
embeddedPom- the temporary file holding the extracted entry, must not benullentryName- the name of the matched JAR entry, must not benull- Throws:
org.apache.maven.plugin.MojoExecutionException- if the content contains a DOCTYPE declaration or cannot be read
-
detectXmlCharset
private Charset detectXmlCharset(byte[] bytes, String entryName) throws org.apache.maven.plugin.MojoExecutionException Detects the character encoding of raw XML bytes the way an XML parser is required to (XML 1.0 Appendix F): byte-order mark first, then the byte pattern of a leading<?xml, then theencodingpseudo-attribute of the XML declaration, defaulting to UTF-8.- Parameters:
bytes- the raw entry bytes, must not benullentryName- the name of the matched JAR entry, for error messages- Returns:
- the detected charset, never
null - Throws:
org.apache.maven.plugin.MojoExecutionException- if the detected/declared encoding is unsupported
-
charsetOrFail
-
validateEmbeddedPomEntryPath
private void validateEmbeddedPomEntryPath(String entryName, org.apache.maven.model.Model model) throws org.apache.maven.plugin.MojoExecutionException Verifies that the<groupId>/<artifactId>components of the matchedMETA-INF/maven/<groupId>/<artifactId>/pom.xmlentry path agree with the effective coordinates declared by the embedded POM itself.- Parameters:
entryName- the name of the matched JAR entry, must not benullmodel- the model parsed from that entry, must not benull- Throws:
org.apache.maven.plugin.MojoExecutionException- if the entry path does not match the model
-
crossCheckOperatorCoordinates
private void crossCheckOperatorCoordinates(String entryName, org.apache.maven.model.Model model) throws org.apache.maven.plugin.MojoExecutionException Cross-checks every operator-supplied coordinate (groupId, artifactId, version) against the effective values declared by the embedded POM and fails on any mismatch.- Parameters:
entryName- the name of the matched JAR entry, must not benullmodel- the model parsed from that entry, must not benull- Throws:
org.apache.maven.plugin.MojoExecutionException- if an operator-supplied coordinate disagrees with the embedded POM
-
contentDiffers
-
verifyContainment
private void verifyContainment(org.eclipse.aether.RepositorySystemSession repoSession, File artifactLocalFile) throws org.apache.maven.plugin.MojoExecutionException Defense in depth: verifies that the composed layout path stays inside the local repository.- Throws:
org.apache.maven.plugin.MojoExecutionException
-
processModel
private void processModel(org.apache.maven.model.Model model) Populates missing mojo parameters from the specified POM.- Parameters:
model- The POM to extract missing artifact coordinates from, must not benull.
-
generateModel
private org.apache.maven.model.Model generateModel()Generates a minimal model from the user-supplied artifact information.- Returns:
- The generated model, never
null.
-
generatePomFile
Generates a (temporary) POM file from the plugin configuration. It's the responsibility of the caller to delete the generated file when no longer needed.- Returns:
- The path to the generated POM file, never
null. - Throws:
org.apache.maven.plugin.MojoExecutionException- If the POM file could not be generated.
-
getLocalRepositoryFile
private File getLocalRepositoryFile(org.eclipse.aether.RepositorySystemSession session, org.eclipse.aether.artifact.Artifact artifact) Gets the path of the specified artifact within the local repository. Note that the returned path need not exist (yet). -
getPomLocalRepositoryFile
private File getPomLocalRepositoryFile(org.eclipse.aether.RepositorySystemSession session, org.eclipse.aether.artifact.Artifact artifact) Gets the path of the specified artifact POM within the local repository. Note that the returned path need not exist (yet). -
isValidId
Returnstrueif passed in string is "valid Maven ID" (artifactId or packaging): non-empty, not consisting solely of'.'characters (so it can never form a./..path segment in the local repository layout), and using only allowed characters. -
isValidGroupId
Returnstrueif passed in string is a valid Maven groupId: a valid ID whose dot-separated segments are all non-empty. Leading, trailing or consecutive dots would produce empty path segments after the dots-to-directories transform of the local repository layout. -
isValidVersion
Returnstrueif passed in string is "valid Maven (simple. non range, expression, etc) version": non-empty, not consisting solely of'.'characters, and free of illegal characters.
-