Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Support authenticated private registries beyond NPM_CONFIG_REGISTRY

Open
#2,603 1 comment 1 reaction 1 assignee View on GitHub

Maintainers usually reply within 1 day

@RSS1102 is already working on this.

Since Sep 7, 2026.

Assessment

This issue has not been assessed yet.

Description

contribution welcome
Discussed in https://github.com/voidzero-dev/vite-plus/discussions/2599

Originally posted by xmlking September 3, 2026
I am in corporate environment where public npm registry is blocked.
even If I set NPM_CONFIG_REGISTRY , vp install still failing as it is not using the apikey

here is what Claude say:

Root cause found. Your package.json pins "packageManager": "[email protected]" (package.json:52). Like Corepack, vp downloads that exact pnpm binary into its own managed store (~/.vite-plus/package_manager/pnpm, currently empty on your machine) rather than using whatever pnpm is on PATH. That download is done by vp's own Rust binary hitting the npm-style tarball URL directly — it's a separate code path from the pnpm/npm CLI that reads ~/.npmrc.

Verified this in two parts:

  1. Registry choice: vp only honors the NPM_CONFIG_REGISTRY env var for this download (documented default https://registry.npmjs.org). Since that env var isn't exported in your shell (only present in ~/.npmrc), vp falls back to public npm.
  2. Auth: even after exporting NPM_CONFIG_REGISTRY to your Artifactory URL, the download 401s — vp's downloader doesn't send the Bearer token from your .npmrc's _authToken. I confirmed with curl that the same URL only succeeds with an Authorization: Bearer header; Basic auth (token-as-username) fails too, so there's no URL-embedded-credential workaround.

So this is a real gap: for a pinned packageManager version, vp can't authenticate to a token-only private registry when fetching the manager itself.

Practical options:

  • Ask your Artifactory admin if the mirror also accepts Basic auth with your AD username + an API key/identity token (common JFrog setup) — if so, NPM_CONFIG_REGISTRY=https://<user>:<apikey>@xyz.jfrog.io/... would let vp's downloader authenticate via URL-embedded Basic auth.
  • Pre-seed the cache once from a machine/network that can reach the registry with proper auth (e.g. have plain pnpm dlx [email protected] --version or similar populate ~/.vite-plus/package_manager/pnpm manually), then subsequent vp install runs won't need to re-download it.
  • Report this to vite-plus (viteplus.dev) as a gap — package-manager bootstrap doesn't support authenticated private registries beyond NPM_CONFIG_REGISTRY.

---

Dominant language
Rust
Stars
5.8k
Forks
267
Avg merge
20h 7m
Merged PRs (30d)
139

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from voidzero-dev/vite-plus

All issues in voidzero-dev/vite-plus

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.