Gradle Repository Authentication: Unresolved OAuth2 Token Refresh
26.5K reputation · 27 Nov 2024, 04:36 UTC
Gradle Repository Authentication: Unresolved OAuth2 Token Refresh
Gradle’s current repository authentication model supports HTTP Basic and static token credentials configured in settings.gradle or gradle.properties. The framework lacks a built‑in mechanism to detect or refresh an OAuth2 access token that has expired; a failed request results in an AuthenticationException and aborts the build.
Additionally, Gradle does not enforce a least‑privilege boundary: the same credential set can be applied to all configured repositories, even when only a subset of them requires authentication. This raises security concerns and complicates credential lifecycle management.
Key uncertainties remain:
- How can OAuth2 token refresh be integrated into Gradle’s authentication flow without external tooling?
- Should Gradle support per‑repository credential scopes to enforce least‑privilege access?