<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0">
<base href="https://shibboleth.atlassian.net">
<title>Message Title</title>
</head>
<body class="jira" style="color: #333333; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.429">
<table id="background-table" cellpadding="0" cellspacing="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; background-color: #f5f5f5; border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0" bgcolor="#f5f5f5"> <!-- header here -->
<tbody>
<tr>
<td id="header-pattern-container" style="padding: 0; border-collapse: collapse; padding: 10px 20px">
<table id="header-pattern" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0">
<tbody>
<tr>
<td id="header-avatar-image-container" valign="top" style="padding: 0; border-collapse: collapse; vertical-align: top; width: 32px; padding-right: 8px" width="32"> <img id="header-avatar-image" class="image_fix" src="https://secure.gravatar.com/avatar/352d2f41956c0c554e211142f24a666e?d=https%3A%2F%2Favatar-management--avatars.us-west-2.prod.public.atl-paas.net%2Finitials%2FDM-5.png" height="32" width="32" border="0" style="border-radius: 3px; vertical-align: top"> </td>
<td id="header-text-container" valign="middle" style="padding: 0; border-collapse: collapse; vertical-align: middle; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> <a class="user-hover" rel="557058:3a8d6dab-64f5-4a62-a23e-1603099d1796" style="color:#3b73af;; color: #3b73af; text-decoration: none" id="email_557058:3a8d6dab-64f5-4a62-a23e-1603099d1796" href="https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A3a8d6dab-64f5-4a62-a23e-1603099d1796"> Dan McLaughlin </a> <strong>commented</strong> on <a href="https://shibboleth.atlassian.net/browse/IDP-1955?atlOrigin=eyJpIjoiMjMwNjI4Y2E1Mzk2NDJjNzkzMWM2ODBhNDQ0MmEyMjMiLCJwIjoiaiJ9" style="color: #3b73af; text-decoration: none"><img src="cid:jira-generated-image-avatar-2e37210d-0b17-4277-a470-63ea3df1c8f6" height="16" width="16" border="0" align="absmiddle" alt="Improvement"> IDP-1955</a> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="email-content-container" style="padding: 0; border-collapse: collapse; padding: 0 20px">
<table id="email-content-table" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; border-spacing: 0; border-collapse: separate">
<tbody>
<tr> <!-- there needs to be content in the cell for it to render in some clients -->
<td class="email-content-rounded-top mobile-expand" style="padding: 0; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 15px; background-color: #ffffff; border-left: 1px solid #cccccc; border-top: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom: 0; border-top-right-radius: 5px; border-top-left-radius: 5px; height: 10px; line-height: 10px; padding: 0 15px 0 16px; mso-line-height-rule: exactly" height="10" bgcolor="#ffffff"> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand " style="padding: 0; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff">
<table class="page-title-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0">
<tbody>
<tr>
<td style="vertical-align: top;; padding: 0; border-collapse: collapse; padding-right: 5px; font-size: 20px; line-height: 30px; mso-line-height-rule: exactly" class="page-title-pattern-header-container"> <span class="page-title-pattern-header" style="font-family: Arial, sans-serif; padding: 0; font-size: 20px; line-height: 30px; mso-text-raise: 2px; mso-line-height-rule: exactly; vertical-align: middle"> <a href="https://shibboleth.atlassian.net/browse/IDP-1955?atlOrigin=eyJpIjoiMjMwNjI4Y2E1Mzk2NDJjNzkzMWM2ODBhNDQ0MmEyMjMiLCJwIjoiaiJ9" style="color: #3b73af; text-decoration: none">Re: Add attachClasses to the maven-war-plugin in idp-parent</a> </span> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="text-paragraph-pattern-top" class="email-content-main mobile-expand comment-top-pattern" style="padding: 0; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff; border-bottom: none; padding-bottom: 0" bgcolor="#ffffff">
<table class="text-paragraph-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 2px">
<tbody>
<tr>
<td class="text-paragraph-pattern-container mobile-resize-text " style="padding: 0; border-collapse: collapse; padding: 0 0 10px"> <p style="margin: 10px 0 0; margin-top: 0"><a href="https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A0fa99aa9-d698-454c-a274-7a41bee6cef5" class="user-hover" rel="557058:0fa99aa9-d698-454c-a274-7a41bee6cef5" data-account-id="557058:0fa99aa9-d698-454c-a274-7a41bee6cef5" accountid="557058:0fa99aa9-d698-454c-a274-7a41bee6cef5" style="color: #3b73af; text-decoration: none">Tom Zeller</a> The idp-war-distribution works until you need to override a dependency. That’s why we are asking that you add the attachClasses to the Maven war plugin. All that option does is add a jar as an additional build artifact to any of the war modules, which is going to be helpful for any project that wants to customize the war using Maven and be able to use dependency management to override any dependency versions when necessary. </p> <p style="margin: 10px 0 0"><a href="https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007" class="user-hover" rel="557058:5b78efc9-1379-42cc-a3f6-56c6ea3a0007" data-account-id="557058:5b78efc9-1379-42cc-a3f6-56c6ea3a0007" accountid="557058:5b78efc9-1379-42cc-a3f6-56c6ea3a0007" style="color: #3b73af; text-decoration: none">Scott Cantor</a> I would ask that you PLEASE reconsider this. It’s very important to have this change because without it we are restricted to only being able to use Maven WAR Overlays (<a href="https://maven.apache.org/plugins/maven-war-plugin/overlays.html" title="smart-link" class="external-link" rel="nofollow noreferrer" style="color: #3b73af; text-decoration: none">https://maven.apache.org/plugins/maven-war-plugin/overlays.html</a> ). WAR Overlays are fine until you have dependency convergence issues, or you need to patch a third-party dependency for any reason, then WAR Overlays become useless because you have to resort to hacking at the dependencies using various exclude/includes, or in most cases, the only way is to resort to extracting the war and using multiple plugins to try to delete and add dependencies, which is a nightmare to manage. The problem is caused by the fact that WAR’s aren’t tied into Maven dependency management. So any dependency versions you have defined in dependencyManagement are ignored with WAR Overlays, when a WAR is built without the attachClasses option your only option is WAR Overlays without dependency management. To do something as simple as update the Spring framework to the next patch release to pick up a security fix we would have to resort to hacking at the war dependencies using various excludes and then extract the jars we need, which can become a mess very quick and complicated to maintain. </p> <p style="margin: 10px 0 0">See the following URL is where the attachClasses option in the Maven WAR plugin is discussed. <a href="https://maven.apache.org/plugins/maven-war-plugin/faq.html#attached" class="external-link" rel="nofollow noreferrer" style="color: #3b73af; text-decoration: none">https://maven.apache.org/plugins/maven-war-plugin/faq.html#attached</a></p> <p style="margin: 10px 0 0">This change is very low risk, even for a patch release, and it doesn’t affect anyone using the war. All the attachClasses does is add a jar to the build artifacts so that downstream projects customizing the war using Maven can use Maven’s dependency management to override dependencies when necessary. For example, if there is a security issue in a third-party dependency used by the IDP that we need to upgrade prior to an IDP patch being released we can easily use Maven’s dependency management to specify the version of the dependency with the fix and Maven will make sure that the newer version of the dependency is used when packaging the final war with our customizations. </p> <p style="margin: 10px 0 0">Without this change, we either have to resort to manually building the IDP war and defining all the dependencies for the IDP so that dependency management will work, this is a huge pain because every time a new IDP is released I have to make sure all the dependencies are updated in our pom. This option I’m not going to do, it’s a huge headache to maintain. My other option is to maintain our own custom version of idp-parent with attachClasses added, this also means I have to build and deploy the build artifacts to our internal repository so we can use the <tt>idp-war-distribution</tt> and <tt>idp-war</tt> that have the jar attached. With the jar we can then use maven dependency management to pull in all the dependencies for the idp war, as well as do any version overrides we need. </p> <p style="margin: 10px 0 0">Please reconsider, this is very low risk, and the only thing anyone will notice is that there will be both a war and a jar included in the build artifacts. If you have the need to override dependencies, then instead of using the war, you would use the jars instead. I’ve attached an example pom.xml showing how we would use the idp-war and idp-war-distribution classes to pull in the dependencies and override spring and unbound-ldapsdk. </p> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand " style="padding: 0; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff"> <script type="application/ld+json">
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"description": "View Issue",
"potentialAction": {
"@type": "ViewAction",
"target": "https://shibboleth.atlassian.net/browse/IDP-1955?inbox=true&focusedCommentId=33021&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-33021",
"name": "View Comment"
},
"publisher": {
"@type": "Organization",
"name": "Atlassian",
"url": "https://www.atlassian.com"
}
}
</script>
<table id="actions-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px">
<tbody>
<tr>
<td id="actions-pattern-container" valign="middle" style="padding: 0; border-collapse: collapse; padding: 10px 0 10px 24px; vertical-align: middle; padding-left: 0">
<table align="left" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0">
<tbody>
<tr>
<td class="actions-pattern-action-icon-container" style="padding: 0; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 0; vertical-align: middle"> <a href="https://shibboleth.atlassian.net/browse/IDP-1955#add-comment?atlOrigin=eyJpIjoiMjMwNjI4Y2E1Mzk2NDJjNzkzMWM2ODBhNDQ0MmEyMjMiLCJwIjoiaiJ9" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none"> <img class="actions-pattern-action-icon-image" src="cid:jira-generated-image-static-comment-icon-f0862754-a7ad-4f0b-a02b-50872ce6d309" alt="Add Comment" title="Add Comment" height="16" width="16" border="0" style="vertical-align: middle"> </a> </td>
<td class="actions-pattern-action-text-container" style="padding: 0; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 4px; padding-left: 5px"> <a href="https://shibboleth.atlassian.net/browse/IDP-1955#add-comment?atlOrigin=eyJpIjoiMjMwNjI4Y2E1Mzk2NDJjNzkzMWM2ODBhNDQ0MmEyMjMiLCJwIjoiaiJ9" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none">Add Comment</a> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table> </td>
</tr> <!-- there needs to be content in the cell for it to render in some clients -->
<tr>
<td class="email-content-rounded-bottom mobile-expand" style="padding: 0; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 5px; line-height: 5px; background-color: #ffffff; border-top: 0; border-left: 1px solid #cccccc; border-bottom: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom-right-radius: 5px; border-bottom-left-radius: 5px; mso-line-height-rule: exactly" height="5" bgcolor="#ffffff"> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="footer-pattern" style="padding: 0; border-collapse: collapse; padding: 12px 20px">
<table id="footer-pattern-container" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0">
<tbody>
<tr>
<td id="footer-pattern-mobile-separated-links" class="mobile-resize-text" width="100%" colspan="2" style="padding: 0; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> Get Jira notifications on your phone! Download the Jira Cloud app for <a href="https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail" style="color: #3b73af; text-decoration: none">Android</a> or <a href="https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8" style="color: #3b73af; text-decoration: none">iOS</a>
<hr> </td>
</tr>
<tr>
<td id="footer-pattern-text" class="mobile-resize-text" width="100%" style="padding: 0; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> This message was sent by Atlassian Jira <span id="footer-build-information">(v1001.0.0-SNAPSHOT#100201-<span title="66eda1fef6779fe48dbb523efbbb80a654325d1e" data-commit-id="66eda1fef6779fe48dbb523efbbb80a654325d1e}">sha1:66eda1f</span>)</span> </td>
<td id="footer-pattern-logo-desktop-container" valign="top" style="padding: 0; border-collapse: collapse; padding-left: 20px; vertical-align: top">
<table style="border-collapse: collapse; mso-table-lspace: 0; mso-table-rspace: 0">
<tbody>
<tr>
<td id="footer-pattern-logo-desktop-padding" style="padding: 0; border-collapse: collapse; padding-top: 3px; opacity: 0.150"> <img id="footer-pattern-logo-desktop" src="cid:jira-generated-image-static-footer-desktop-logo-3a547924-1424-4292-980b-29f373b3f437" alt="Atlassian logo" title="Atlassian logo" width="192" height="24" class="image_fix"> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table>
</body>
</html>