Skip to content

LDEV-XXXX: ExtensionProvider.detail() must not overwrite lite .lex with lite.asc - #2852

Merged
michaeloffner merged 2 commits into
lucee:7.0from
GianTschingt:LDEV-extensionprovider-lite-asc
Oct 5, 2026
Merged

michaeloffner merged 2 commits into
lucee:7.0from
GianTschingt:LDEV-extensionprovider-lite-asc

Conversation

@GianTschingt

Copy link
Copy Markdown
Contributor

Jira: TBD (filing as Gian)

Bug: ExtensionProvider.detail() / LuceeExtension() for a SNAPSHOT that publishes a lite classifier returns the GPG signature URL under key lite instead of the .lex artifact. Key lite.asc is missing. Keys lex, lex.asc, pom, pom.asc are correct.

Confirmed on Lucee 8.0 with mail-extension 1.1.0.9-SNAPSHOT; identical buggy remapping in core RepoReader.read() on 7.0, 7.1, and 8.0. Not in 6.2 (no core ExtensionProvider/RepoReader). Loader's lucee.loader.engine.mvn.RepoReader already uses classifier.extension keys — unchanged.

Cause: endElement stores internal keys as classifier + "." + extension (lite.lex, lite.lex.asc), but read() remapped both to "lite" via classifier alone, so the later HashMap entry overwrote the real lite .lex URL with the .asc URL.

Fix: in RepoReader.read() only — if classifier is non-empty, use classifier, or classifier + ".asc" when extension ends with .asc; else use extension; else e.getKey().

Test: test/tickets/LDEVXXXX.cfc — asserts lite ends with -lite.lex (not .asc) and lite.asc is present for mail-extension 1.1.0.9-SNAPSHOT (network to Sonatype snapshots, same pattern as existing LuceeExtension / ListExtensions tests).

Targeting 7.0 only (merge-up to 7.1→8.0).

…y .asc

RepoReader.read() remapped both classifier=lite/extension=lex and
classifier=lite/extension=lex.asc to key "lite", so the GPG signature URL
overwrote the real -lite.lex artifact. Use classifier+".asc" when the
extension ends with .asc; keep plain classifier otherwise.

Includes TestBox regression test against mail-extension 1.1.0.9-SNAPSHOT.
@michaeloffner
michaeloffner merged commit bcbb00e into lucee:7.0 Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants