无法将私有npm包发布至私有Nexus仓库,求排查方案
核心问题
执行npm publish时提示需要登录,但已在.npmrc配置了_auth凭证,无法正常完成发布。
现有配置
package.json 配置
{ "name": "@organization/the-repo", "version": "14.2.0", "main": "build/lib/index.js", "types": "build/lib/index.d.ts", "private": false, "repository": { "type": "git", "url": "git://github.com/organization/the-repo.git" }, "publishConfig": { "registry": "https://internal.company.com/nexus/content/repositories/npm-private/" } }
.npmrc 配置
registry=https://internal.company.com/nexus/content/groups/npm/ _auth=mYtOkEn= always-auth=true save-exact=true
可能的问题点及解决方法
发布仓库未单独配置凭证
当前.npmrc里的_auth仅对应默认registry(https://internal.company.com/nexus/content/groups/npm/),但发布时使用的是publishConfig指定的独立仓库https://internal.company.com/nexus/content/repositories/npm-private/,该仓库没有绑定对应权限凭证。需在.npmrc中为发布仓库单独添加配置:@organization:registry=https://internal.company.com/nexus/content/repositories/npm-private/ //internal.company.com/nexus/content/repositories/npm-private/:_auth=mYtOkEn=其中
@organization是包的scope,确保该scope下的包发布时指向目标仓库,同时为该仓库配置对应_auth凭证。_auth凭证格式错误
_auth的值必须是用户名:密码经过Base64编码后的字符串。检查mYtOkEn=是否为正确的编码结果,若存在拼写或编码不完整问题,可重新生成:将username:password进行Base64编码后替换现有值。Nexus仓库权限配置问题
确认Nexus的npm-private仓库是否允许当前_auth对应的用户执行发布操作。需联系管理员检查:该用户是否开启npm Bearer Token Realm权限,以及是否被分配了该仓库的publish权限。always-auth作用范围未覆盖发布仓库
尽管设置了always-auth=true,但默认配置仅对默认registry生效。通过单独为发布仓库配置_auth,可确保权限验证覆盖发布流程。
内容的提问来源于stack exchange,提问作者baitendbidz

