Content Selectors, Repository Targets, Fine-Grained Privileges, and Path-Level Authorization: Diagnostics, Failure Modes, Security, and Performance
Diagnose selector overmatch, browse/read confusion, role inheritance, group exposure, wrong path assumptions, and misleading UI visibility by preserving evidence and testing controlled requests.
Learning objectives
- Diagnose selector overmatch and format-path mistakes without broadening privileges blindly.
- Separate browse/search visibility from direct read authorization.
- Trace privilege expansion through user roles and role inheritance.
- Detect group-endpoint exposure that member-level testing misses.
- Repair the smallest security object and prove the result with a controlled matrix.
1. Diagnostic sequence: authorization is an evidence problem
- Preserve concise client status/body, requested URL/path, principal, and time.
- Confirm Nexus version/edition/runtime and whether the server is writable.
- Confirm the client is hitting the intended direct or group endpoint and authenticating as the expected user.
- Inspect repository type/format/group membership.
- Inspect the selector expression and Preview result.
- Inspect every privilege and inherited role assigned to the principal.
- Inspect matching asset path/metadata state.
- Only then consider proxy/cache/upstream, database/blob/disk, logs/tasks/metrics if the symptom actually points there.
- Change one smallest policy object and repeat the exact request.
2. Failure: selector matches more than intended
Intentionally compare these two expressions:
# BROKEN: can match /team-a-archive/
format == "raw" and path =^ "/team-a"
# REPAIRED: namespace delimiter is explicit
format == "raw" and path =^ "/team-a/"
Use Content Selector Preview against synthetic paths. If the broken selector matches an unintended asset, preserve that preview evidence. Fix the expression—not the blob path, database row, or client cache—and then repeat the authorization request.
3. Failure: UI visibility and direct read disagree
browse and read are different actions.
Search visibility also involves nx-search-read.
Therefore “I cannot see it in Browse” is not equivalent to “the
server denies a direct GET.” Capture both:
curl -sS --netrc-file "$TA_AUTH" -o "$LAB/evidence/direct-read.body" -w 'direct-read http=%{http_code}\n' "$HOSTED_URL/team-a/app/1.0.0/release.txt" | tee "$LAB/evidence/direct-read.status"
curl -fsS --netrc-file "$NX_AUTH_FILE" "$NX_URL/service/rest/v1/security/roles/academy-ch14-team-a-role" > "$LAB/evidence/team-a-role.json"
If direct read works but browse/search does not, add only the missing browse/search privilege required by the intended UX. Do not grant wildcard repository access.
4. Failure: role inheritance expands access
A team user unexpectedly reads Team B. The selector itself is correct. Before editing it, inspect the user and every role. A broader inherited role, a default role, or a second direct role can authorize the request. Nexus privileges cannot “deny back” a grant from another role.
| Evidence | Interpretation |
|---|---|
| Selector Preview matches only Team A | Selector may be correct; effective role still needs review |
Role includes
nx-repository-view-raw-academy-ch14-group-read
|
Broad group read can expose both namespaces |
| User also has operator/admin role | Fine-grained test is invalid because broader grant wins |
| User has only expected selector privileges | Continue to endpoint/group/path analysis |
5. Intentionally broken example: broad group read defeats member precision
For a disposable Team A role, temporarily add the repository-wide
read privilege for academy-ch14-group.
Keep the direct hosted privilege narrow. Test Team B through both
endpoints.
for base in "$HOSTED_URL" "$GROUP_URL"; do
curl -sS --netrc-file "$TA_AUTH" -o "$LAB/evidence/overbroad-$(basename "$base").body" -w "$base team-b http=%{http_code}\n" "$base/team-b/app/1.0.0/release.txt" | tee -a "$LAB/evidence/overbroad-status.txt"
done
Expected causal interpretation: the direct hosted request remains denied by the narrow member policy, while the group request can succeed because the broad group privilege independently authorizes content surfaced through the group.
Repair: remove the broad group repository-view
privilege and retain only academy-ch14-a-group-read.
Repeat the same group GET. The Team B path should now be denied
while Team A remains readable.
6. Failure: path assumptions copied from another format
Do not copy /team-a/ Raw logic into Docker, Maven,
PyPI, or APT without checking current format semantics. Docker
client and REST paths differ. Maven can use enhanced selector
attributes but path remains predictable. PyPI and APT uploads may
POST to the repository root, which prevents path selectors from
restricting upload in the same way. A policy can be syntactically
valid and still fail to enforce the intended write boundary for a
particular protocol.
7. Failure: relying on UI visibility as security proof
Admin UI screens are not the request path used by a build agent. Always test the actual principal, endpoint, HTTP method, and path. Conversely, do not conclude that an item shown in a search result is downloadable; browse/search and read are distinct grants.
8. When logs and infrastructure matter
If both allowed and denied requests return the same unexpected transport failure, authorization may not be the problem. Preserve HTTP status and Nexus request/log evidence, then separate TLS/reverse-proxy errors, server read-only state, database latency, blob IO, and JVM pressure from permission decisions. Performance tuning is not a fix for a 403 caused by a selector mismatch.
9. Security-sensitive changes
High-impact controls. Changing local passwords, realms, roles, content selectors, TLS/reverse proxy, remote credentials, cleanup/tasks, database/blob configuration, backups, migration/upgrade state, or public exposure changes a security or recovery boundary. Keep experiments in this disposable chapter topology, use fake identities, and preserve the original failure before repair.
10. Knowledge check
The selector Preview is correct but Team A still reads Team B. What should you inspect next?
All effective privileges and roles, especially broad group or wildcard grants. Selectors do not revoke access granted elsewhere.
Why can direct hosted access be denied while group access succeeds?
Group privileges authorize member content through the group independently of direct member privileges.
A user sees an asset but GET returns 403. What distinction matters?
Browse/search visibility is separate from read/download authorization.
Why is editing the blob store never the right fix for a selector mismatch?
The failure is in security configuration, not content persistence; direct blob edits can corrupt consistency.
What is the safest repair when a broad group role caused exposure?
Remove the broad group grant and replace it with the intended selector-backed group privilege, then repeat the same controlled request.
11. Summary and next step
The diagnostic method is now deterministic: prove identity and endpoint, inspect selector and role composition, then reproduce the exact request before changing policy. Lesson 5 combines this into a two-team checkpoint with an intentionally overbroad group grant and a final authorization matrix.
Official references and version notes
- Sonatype: Content Selectors — CSEL syntax, preview, supported formats, performance guidance, and upload limitations.
- Sonatype: Privileges — repository view versus content-selector privileges, actions, additive grants, and group semantics.
- Sonatype: Access Control — RBAC object model.
- Sonatype: Security Management API and API Reference.
- Sonatype: Changes During the Upgrade Process — Nexus Repository 2 repository targets become Nexus Repository 3 content selectors.
- Self-Hosted Feature Matrix — Repo Targets / Content Selectors are Community and Pro capabilities.
- Sonatype: Database Options — coordinate-based selectors are deprecated with PostgreSQL and no longer supported.
- Sonatype verified Nexus Docker image tags.
Version-sensitive statements were rechecked on 2026-08-26. Sonatype's verified container registry exposes Nexus Repository 3.95.2 as the current latest image line. The mandatory chapter path uses Community-compatible content selectors, local users/roles, Raw hosted/group repositories, and the self-hosted security APIs. It does not require Pro user tokens, SAML/OIDC, HA, staging, Repository Firewall, or deployment to a group repository.
Keep the academy open
Support free, practical DevOps education.
Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0
Send only Ethereum/ERC-20 compatible assets to this
address.