<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>

    <groupId>xyz.tcheeric</groupId>
    <artifactId>cashu-vault</artifactId>
    <version>0.13.0</version>
    <packaging>pom</packaging>

    <name>cashu-vault</name>
    <url>http://maven.apache.org</url>

    <modules>
        <module>cashu-vault-jpa</module>
        <module>cashu-vault-api</module>
        <module>cashu-vault-hashi</module>
    </modules>

    <properties>
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
        <java.version>21</java.version>
        <maven.compiler.source>21</maven.compiler.source>
        <maven.compiler.target>21</maven.compiler.target>

        <!-- Spring Boot -->
        <spring-boot.version>3.5.16</spring-boot.version>

        <!-- Tomcat, overriding what Spring Boot pins. Boot 3.5.16 ships
             10.1.55, which OSV still reports as carrying three CRITICALs
             including CVE-2026-43512 and CVE-2026-65905, both authentication
             bypasses. The advisories name 10.1.58 as the fix, but that version
             was never published to Maven Central (the index skips .57 to .59),
             so the real floor is 10.1.59.
             Remove this override once a Boot release ships >= 10.1.59. -->
        <tomcat.version>10.1.59</tomcat.version>

        <!-- Cashu Library -->
        <cashu-lib.version>0.30.5</cashu-lib.version>

        <!-- Database Dependencies -->
        <postgresql.version>42.7.7</postgresql.version>
        <h2.version>2.2.224</h2.version>
        <flyway.version>11.2.0</flyway.version>
        <hibernate-envers.version>6.6.26.Final</hibernate-envers.version>

        <!-- Annotation Processors -->
        <lombok.version>1.18.40</lombok.version>

        <!-- Test Dependencies -->
        <testcontainers.version>1.20.4</testcontainers.version>

        <!-- Maven Plugin Versions -->
        <maven-compiler-plugin.version>3.14.0</maven-compiler-plugin.version>
        <maven-surefire-plugin.version>3.5.3</maven-surefire-plugin.version>
        <spring-boot-maven-plugin.version>3.5.5</spring-boot-maven-plugin.version>
        <flatten-maven-plugin.version>1.7.2</flatten-maven-plugin.version>
    </properties>

    <dependencyManagement>
        <dependencies>
            <!-- Tomcat, pinned AHEAD of the Spring Boot import below.
                 Order is load-bearing: the imported spring-boot-dependencies
                 resolves ${tomcat.version} against its OWN properties, not
                 ours, so setting the property alone looks right and does
                 nothing. Only an explicit entry declared BEFORE the import
                 wins, because Maven takes the first declaration it sees. -->
            <dependency>
                <groupId>org.apache.tomcat.embed</groupId>
                <artifactId>tomcat-embed-core</artifactId>
                <version>${tomcat.version}</version>
            </dependency>
            <dependency>
                <groupId>org.apache.tomcat.embed</groupId>
                <artifactId>tomcat-embed-el</artifactId>
                <version>${tomcat.version}</version>
            </dependency>
            <dependency>
                <groupId>org.apache.tomcat.embed</groupId>
                <artifactId>tomcat-embed-websocket</artifactId>
                <version>${tomcat.version}</version>
            </dependency>

            <!-- BouncyCastle, both artifacts. CVE-2025-14813 (GOSTCTR) is
                 fixed in 1.80.2, 1.81.1 and 1.84 only; this tree carried
                 jdk18on 1.81 and jdk15to18 1.80 transitively via cashu-lib and
                 bitcoinj. Managed here so the provider cannot drift back to a
                 vulnerable version through a transitive path nobody reads.
                 NOT 1.83: OSV reports it as carrying more vulnerabilities than
                 the 1.81 it would replace.

                 1.84 to 1.85 for CVE-2026-8763 (CRITICAL): X.509 Name
                 Constraints can be bypassed with a trailing dot in an
                 rfc822Name or URI, so a certificate can assert a name the
                 constraint exists to forbid. This repository pins its own
                 versions rather than importing imani-bom, so fixing the BOM
                 did not reach it. That is the cost of the second copy, and
                 the reason the dependency scan here is worth keeping. -->
            <dependency>
                <groupId>org.bouncycastle</groupId>
                <artifactId>bcprov-jdk18on</artifactId>
                <version>1.85</version>
            </dependency>
            <dependency>
                <groupId>org.bouncycastle</groupId>
                <artifactId>bcprov-jdk15to18</artifactId>
                <version>1.85</version>
            </dependency>

            <!-- Import Spring Boot BOM -->
            <dependency>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-dependencies</artifactId>
                <version>${spring-boot.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>

            <!-- Import Testcontainers BOM -->
            <dependency>
                <groupId>org.testcontainers</groupId>
                <artifactId>testcontainers-bom</artifactId>
                <version>${testcontainers.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>

            <!-- Cashu Library Modules -->
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>cashu-lib-common</artifactId>
                <version>${cashu-lib.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>cashu-lib-entities</artifactId>
                <version>${cashu-lib.version}</version>
            </dependency>

            <!-- Database Dependencies -->
            <dependency>
                <groupId>org.postgresql</groupId>
                <artifactId>postgresql</artifactId>
                <version>${postgresql.version}</version>
            </dependency>
            <dependency>
                <groupId>com.h2database</groupId>
                <artifactId>h2</artifactId>
                <version>${h2.version}</version>
            </dependency>
            <dependency>
                <groupId>org.flywaydb</groupId>
                <artifactId>flyway-core</artifactId>
                <version>${flyway.version}</version>
            </dependency>
            <!-- Pinned to the SAME property as flyway-core, and that is the whole point.
                 Only flyway-core was managed here, so flyway-database-postgresql took
                 Spring Boot's managed version instead and the two drifted apart —
                 core 11.2.0 against postgresql 11.7.2 on the resolved classpath. The
                 database module calls into core internals, so the mismatch fails at
                 RUNTIME, not at build time:

                   NoSuchMethodError: UrlUtils.isSecretManagerUrl(String, String)

                 Nothing in the test suite caught it because the tests run on H2 and
                 never load the postgresql module at all. -->
            <dependency>
                <groupId>org.flywaydb</groupId>
                <artifactId>flyway-database-postgresql</artifactId>
                <version>${flyway.version}</version>
            </dependency>
            <dependency>
                <groupId>org.hibernate.orm</groupId>
                <artifactId>hibernate-envers</artifactId>
                <version>${hibernate-envers.version}</version>
            </dependency>

            <!-- Annotation Processors -->
            <dependency>
                <groupId>org.projectlombok</groupId>
                <artifactId>lombok</artifactId>
                <version>${lombok.version}</version>
                <scope>provided</scope>
            </dependency>
        </dependencies>
    </dependencyManagement>

    <repositories>
        <repository>
            <id>reposilite-releases</id>
            <name>Reposilite</name>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
    </repositories>

    <distributionManagement>
        <repository>
            <id>reposilite-releases</id>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
        <snapshotRepository>
            <id>reposilite-snapshots</id>
            <url>https://maven.398ja.xyz/snapshots</url>
        </snapshotRepository>
    </distributionManagement>

    <build>
        <pluginManagement>
            <plugins>
                <plugin>
                    <groupId>org.springframework.boot</groupId>
                    <artifactId>spring-boot-maven-plugin</artifactId>
                    <version>${spring-boot-maven-plugin.version}</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-compiler-plugin</artifactId>
                    <version>${maven-compiler-plugin.version}</version>
                    <configuration>
                        <source>${java.version}</source>
                        <target>${java.version}</target>
                        <showDeprecation>true</showDeprecation>
                        <annotationProcessorPaths>
                            <annotationProcessorPath>
                                <groupId>org.projectlombok</groupId>
                                <artifactId>lombok</artifactId>
                                <version>${lombok.version}</version>
                            </annotationProcessorPath>
                        </annotationProcessorPaths>
                    </configuration>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-surefire-plugin</artifactId>
                    <version>${maven-surefire-plugin.version}</version>
                    <configuration>
                        <excludes>
                            <exclude>**/*IT.java</exclude>
                        </excludes>
                    </configuration>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-failsafe-plugin</artifactId>
                    <version>${maven-surefire-plugin.version}</version>
                </plugin>
                <plugin>
                    <groupId>org.codehaus.mojo</groupId>
                    <artifactId>flatten-maven-plugin</artifactId>
                    <version>${flatten-maven-plugin.version}</version>
                    <configuration>
                        <updatePomFile>true</updatePomFile>
                        <flattenMode>resolveCiFriendliesOnly</flattenMode>
                    </configuration>
                    <executions>
                        <execution>
                            <id>flatten</id>
                            <phase>process-resources</phase>
                            <goals>
                                <goal>flatten</goal>
                            </goals>
                        </execution>
                        <execution>
                            <id>flatten.clean</id>
                            <phase>clean</phase>
                            <goals>
                                <goal>clean</goal>
                            </goals>
                        </execution>
                    </executions>
                </plugin>
            </plugins>
        </pluginManagement>
    </build>

    <profiles>
        <profile>
            <id>integration-test</id>
            <build>
                <plugins>
                    <plugin>
                        <groupId>org.apache.maven.plugins</groupId>
                        <artifactId>maven-failsafe-plugin</artifactId>
                        <executions>
                            <execution>
                                <goals>
                                    <goal>integration-test</goal>
                                    <goal>verify</goal>
                                </goals>
                            </execution>
                        </executions>
                    </plugin>
                </plugins>
            </build>
        </profile>
    </profiles>
</project>
