voidzero-dev / voidzero-dev/vite-plus
Support authenticated private registries beyond NPM_CONFIG_REGISTRY
- Lingua principale
- Rust
- Stelle
- 5.8k
- Fork
- 261
- Merge medio
- 1g 34m
- PR unite (30g)
- 135
Descrizione
### Discussed in https://github.com/voidzero-dev/vite-plus/discussions/2599
Originally posted by **xmlking** September 3, 2026
I am in corporate environment where public npm registry is blocked.
even If I set `NPM_CONFIG_REGISTRY` , `vp install` still failing as it is not using the `apikey`
here is what Claude say:
---
Root cause found. Your package.json pins "packageManager": "pnpm@11.24.0" (package.json:52). Like Corepack, vp downloads that exact pnpm binary into its own managed store (~/.vite-plus/package_manager/pnpm, currently empty on your machine) rather than using whatever pnpm is on PATH. That download is done by vp's own Rust binary hitting the npm-style tarball URL directly — it's a separate code path from the pnpm/npm CLI that reads ~/.npmrc.
Verified this in two parts:
1. Registry choice: vp only honors the NPM_CONFIG_REGISTRY env var for this download (documented default https://registry.npmjs.org). Since that env var isn't exported in your shell (only present in ~/.npmrc), vp falls back to public npm.
2. Auth: even after exporting NPM_CONFIG_REGISTRY to your Artifactory URL, the download 401s — vp's downloader doesn't send the Bearer token from your .npmrc's _authToken. I confirmed with curl that the same URL only succeeds with an Authorization: Bearer header; Basic auth (token-as-username) fails too, so there's no URL-embedded-credential workaround.
So this is a real gap: for a pinned packageManager version, vp can't authenticate to a token-only private registry when fetching the manager itself.
Practical options:
- Ask your Artifactory admin if the mirror also accepts Basic auth with your AD username + an API key/identity token (common JFrog setup) — if so, `NPM_CONFIG_REGISTRY=https://:@xyz.jfrog.io/...` would let vp's downloader authenticate via URL-embedded Basic auth.
- Pre-seed the cache once from a machine/network that can reach the registry with proper auth (e.g. have plain pnpm dlx pnpm@11.24.0 --version or similar populate ~/.vite-plus/package_manager/pnpm manually), then subsequent vp install runs won't need to re-download it.
- Report this to vite-plus (viteplus.dev) as a gap — package-manager bootstrap doesn't support authenticated private registries beyond NPM_CONFIG_REGISTRY.
---
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.