Implement NuGet feed search and version listing strategies
Summary
- Add
NuGetPackageSearchStrategyandNuGetPackageVersionStrategy— the registry'sIPackageSearchStrategy.CanHandle("NuGet")andIPackageVersionStrategy.CanHandle("NuGet")previously returnedfalsefor every registered strategy, so the resolver fell through andExternalFeedPackageSearchService.SearchAsync+ the version service silently returned[]for any NuGet feed. Operators selecting a NuGet feed in the IIS-deploy step package picker saw "no results" regardless of feed contents. - Each strategy tries V3 first (service index →
SearchQueryService/PackageBaseAddress), falls back to V2 OData (/Search()//FindPackagesById()) when V3 is unreachable or undeclared. Tested live against a V2-only NuGet.Server. - Both send
prerelease=true+semVerLevel=2.0.0unconditionally so feeds with prerelease-only / SemVer 2.0 packages aren't silently filtered out. Auth via Basic header fromfeed.Username/feed.Password, matching the existingNuGetPackageNotesStrategy. - 74 unit tests pin JSON/XML parser shapes, URL construction (encoding, escaping, dedup, take, semVerLevel), and the V3-fail → V2-success integration path. 5 live integration tests against
https://nuget.sjfood.us/nuget(operator's V2-only production feed) prove end-to-end correctness with feed-reachability skip on outage.
Test plan
-
dotnet build Squid.sln— 0 errors -
dotnet test --filter NuGetPackageSearchStrategyTests|NuGetPackageVersionStrategyTests— 74/74 pass, 220ms -
dotnet test --filter NuGetFeedLiveIntegrationTests— 5/5 pass against the live operator feed, 46s -
dotnet test --filter ExternalFeedsregression — 329/329 pass (Docker/GitHub/Helm strategies unaffected) -
CI: unit + integration tests on the workflow -
Manual smoke (post-merge): bind the NuGet feed in SquidWeb, type query in the IIS-deploy step package picker, verify results appear; pick a package, verify versions populate
Why this matters
- Affects every operator using NuGet feeds — not "some packages search-blank", every package on every NuGet feed. The bug effectively made NuGet feeds unusable for IIS deploy.
- Two halves of the same gap — search was the symptom; version listing was the hidden second symptom. Even if an operator typed the exact package ID manually as a workaround, the version dropdown would still be empty.
-
V2 fallback isn't theoretical —
https://nuget.sjfood.us/nugetis a real production V2-only NuGet.Server instance bound in SquidWeb. Live integration tests prove the V2 path actually works against this exact server.