{"record":{"id":"986ec41907f7146b","repo":"rust-lang/cargo","slug":"credential-alias-name-defined-in-will-be-ignored-because-it","errorCode":null,"errorMessage":"credential-alias `{name}` (defined in `{}`) will be ignored because it would shadow a built-in credential-provider","messagePattern":"credential-alias `(.+?)` \\(defined in `(.+?)`\\) will be ignored because it would shadow a built-in credential-provider","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"src/util/auth/mod.rs","lineNumber":231,"sourceCode":"\n    if let Some(name) = &name {\n        tracing::debug!(\"found alternative registry name `{name}` for {sid}\");\n        gctx.get::<Option<RegistryConfig>>([\"registries\", name.as_str()])\n    } else {\n        tracing::debug!(\"no registry name found for {sid}\");\n        Ok(None)\n    }\n}\n\n/// Use the `[credential-alias]` table to see if the provider name has been aliased.\nfn resolve_credential_alias(gctx: &GlobalContext, mut provider: PathAndArgs) -> Vec<String> {\n    if provider.args.is_empty() {\n        let name = provider.path.raw_value();\n        let key = format!(\"credential-alias.{name}\");\n        if let Ok(alias) = gctx.get::<Value<PathAndArgs>>([\"credential-alias\", name]) {\n            tracing::debug!(\"resolving credential alias '{key}' -> '{alias:?}'\");\n            if BUILT_IN_PROVIDERS.contains(&name) {\n                let _ = gctx.shell().warn(format!(\n                    \"credential-alias `{name}` (defined in `{}`) will be \\\n                    ignored because it would shadow a built-in credential-provider\",\n                    alias.definition\n                ));\n            } else {\n                provider = alias.val;\n            }\n        }\n    }\n    provider.args.insert(\n        0,\n        provider\n            .path\n            .resolve_program(gctx)\n            .to_str()\n            .unwrap()\n            .to_string(),\n    );","sourceCodeStart":213,"sourceCodeEnd":249,"githubUrl":"https://github.com/rust-lang/cargo/blob/98a09e7e7d62850f14e5b6132101fc1edd19a16f/src/util/auth/mod.rs#L213-L249","documentation":"When resolving a credential provider, if the provider path names a built-in provider (e.g. `cargo:token`, `cargo:macos-keychain`) and the user has also defined a `credential-alias.<name>` entry, the alias would shadow the built-in. Cargo ignores the alias and emits this warning, reporting which config file defined it, and keeps using the built-in provider.","triggerScenarios":"Calling resolve_credential_alias via credential_provider when the resolved provider has no args, its path matches a name in BUILT_IN_PROVIDERS, and gctx.get([\"credential-alias\", name]) successfully resolves an alias definition from config (e.g. [credential-alias] \"cargo\" = [\"!\", ...]).","commonSituations":"Users defining [credential-alias] entries named like built-in providers (`cargo`, `cargo:token`) by mistake; config copied from examples that named an alias the same as a built-in; combining custom providers with the global-credential-providers defaults.","solutions":["Rename the alias in the config file named in the warning (the `defined in` part) to something that does not collide with a built-in provider name.","If you intended custom behavior, point the provider list at the alias's new name instead of the built-in provider name.","Remove the credential-alias entry entirely if the built-in provider already does what you want."],"exampleFix":"// before: ~/.cargo/config.toml\n[credential-alias]\n\"cargo\" = [\"!\", \"my-login\"]\n\n// after: ~/.cargo/config.toml\n[credential-alias]\n\"my-login\" = [\"!\", \"my-login\"]","handlingStrategy":"validation","validationCode":"# ensure no credential-alias shadows a built-in (anything starting with 'cargo:')\nawk -F= '/\\[credential-alias\\]/{f=1;next} /^\\[/{f=0} f{print}' ~/.cargo/config.toml \\\n  | tr -d '\" ' | cut -d= -f1 | grep -E '^cargo(:|$)' && echo 'alias shadows built-in'","typeGuard":null,"tryCatchPattern":"// warning is advisory; surface it when wiring providers programmatically\nif stderr.contains(\"will be ignored because it would shadow a built-in\") {\n    // rename the alias and reconfigure\n}","preventionTips":["Name custom credential aliases distinctly from built-in providers (avoid names starting with `cargo`).","Keep [credential-alias] definitions in one config scope and review them when changing global-credential-providers.","Read cargo's startup warnings after editing credential config — shadowing is silent otherwise."],"tags":["config","authentication","credential-provider","cargo"],"backgroundTag":"conflicting-config-options","analyzedSha":"98a09e7e7d62850f14e5b6132101fc1edd19a16f","analyzedAt":"2026-09-22T13:55:30.201Z","contentChangedAt":"2026-09-22T13:55:30.201Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}