Support authenticated private registries beyond NPM_CONFIG_REGISTRY
Maintainers usually reply within 1 day
@RSS1102 is already working on this.
Since Sep 7, 2026.
Assessment
This issue has not been assessed yet.
Description
Discussed in https://github.com/voidzero-dev/vite-plus/discussions/2599
Originally posted by xmlking September 3, 2026
I am in corporate environment where public npm registry is blocked.
even If I set NPM_CONFIG_REGISTRY , vp install still failing as it is not using the apikey
here is what Claude say:
Root cause found. Your package.json pins "packageManager": "[email protected]" (package.json:52). Like Corepack, vp downloads that exact pnpm binary into its own managed store (~/.vite-plus/package_manager/pnpm, currently empty on your machine) rather than using whatever pnpm is on PATH. That download is done by vp's own Rust binary hitting the npm-style tarball URL directly — it's a separate code path from the pnpm/npm CLI that reads ~/.npmrc.
Verified this in two parts:
- Registry choice: vp only honors the NPM_CONFIG_REGISTRY env var for this download (documented default https://registry.npmjs.org). Since that env var isn't exported in your shell (only present in ~/.npmrc), vp falls back to public npm.
- Auth: even after exporting NPM_CONFIG_REGISTRY to your Artifactory URL, the download 401s — vp's downloader doesn't send the Bearer token from your .npmrc's _authToken. I confirmed with curl that the same URL only succeeds with an Authorization: Bearer header; Basic auth (token-as-username) fails too, so there's no URL-embedded-credential workaround.
So this is a real gap: for a pinned packageManager version, vp can't authenticate to a token-only private registry when fetching the manager itself.
Practical options:
- Ask your Artifactory admin if the mirror also accepts Basic auth with your AD username + an API key/identity token (common JFrog setup) — if so,
NPM_CONFIG_REGISTRY=https://<user>:<apikey>@xyz.jfrog.io/...would let vp's downloader authenticate via URL-embedded Basic auth. - Pre-seed the cache once from a machine/network that can reach the registry with proper auth (e.g. have plain pnpm dlx [email protected] --version or similar populate ~/.vite-plus/package_manager/pnpm manually), then subsequent vp install runs won't need to re-download it.
- Report this to vite-plus (viteplus.dev) as a gap — package-manager bootstrap doesn't support authenticated private registries beyond NPM_CONFIG_REGISTRY.
---
- Dominant language
- Rust
- Stars
- 5.8k
- Forks
- 267
- Avg merge
- 20h 7m
- Merged PRs (30d)
- 139
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from voidzero-dev/vite-plus
-
pending triage
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
voidzero-dev/vite-plus#2854 · 1 assignee ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
voidzero-dev/vite-plus#2849 ·
Maintainers usually reply within 1 day
-
pending triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
voidzero-dev/vite-plus#2801 · 1 reaction ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
voidzero-dev/vite-plus#2097 · 10 comments · 2 reactions ·
Maintainers usually reply within 1 day
-
pending triage
Difficulty 4/5 3-5 days Newbie friendliness 48/100
voidzero-dev/vite-plus#2866 · 1 assignee ·
Maintainers usually reply within 1 day
All issues in voidzero-dev/vite-plus
Similar issues
-
area:release bug
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
registrystack/registry-stack#1874 ·
Maintainers usually reply within 1 day
-
component:midnight-toolkit status:untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
midnightntwrk/midnight-node#2237 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Maintainers usually reply within 1 day