# How to allow incomming request for specific users

**URL:** <https://community.sonatype.com/t/how-to-allow-incomming-request-for-specific-users/8835>\
**Category:** Best Practices\
**Tags:** help\
**Created:** [June 17, 2022, 7:37am UTC](https://community.sonatype.com/t/how-to-allow-incomming-request-for-specific-users/8835 "2022-06-17T07:37:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![leejh900811](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@leejh900811](https://community.sonatype.com/u/leejh900811)\
**Post date:** [June 17, 2022, 7:37am UTC](https://community.sonatype.com/t/how-to-allow-incomming-request-for-specific-users/8835/1 "2022-06-17T07:37:21Z")

</div>

hello i’m new to Nexus.

i found when nexus repository doesn’t have artifacts, it automatically downloads artifacts from public repository.

what i want is only allowed users can download from public.

i found a repository option to prevent download from public  
( online : If checked, the repository accepts incoming requests)

but it’s for all users…

is there any way to download artifacts from public for allowed users?

please help

---

<div class="post-metadata">

**Author:** ![dsawa](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/dsawa/32/729_2.png) [@dsawa](https://community.sonatype.com/u/dsawa)\
**Post date:** [June 17, 2022, 11:03am UTC](https://community.sonatype.com/t/how-to-allow-incomming-request-for-specific-users/8835/2 "2022-06-17T11:03:43Z")

</div>

Hi Jong-Hyeok!

> i found when nexus repository doesn’t have artifacts, it automatically downloads artifacts from public repository.

Yes, this is correct behaviour for a proxy repository. You can learn more about different types of repositories in our documentation for [Proxy Repository Concepts](https://help.sonatype.com/repomanager3/using-nexus-repository/repository-manager-concepts/proxy-repository-concepts)

> i want is only allowed users can download from public  
> is there any way to download artifacts from public for allowed users?

It sounds like you’re trying to build a “golden repo” which is an anti-pattern. We recommend using [Nexus Firewall](https://www.sonatype.com/products/firewall) to prevent undesired packages from entering your software supply chain, or [Nexus Lifecycle](https://www.sonatype.com/products/lifecycle) to keep you protected throughout software development lifecycle.

However, if you insist on building your golden repo, you will not be able to accomplish this using proxy repository, because there is no granular permission that would allow user to only download pre-existing content and prevent from downloading new content. You can restrict what content can be served (and downloaded from remote) based on their path using either [Routing Rules](https://help.sonatype.com/repomanager3/repository-management/routing-rules) or [Content Selectors](https://help.sonatype.com/repomanager3/system-configuration/access-control/content-selectors), but this will require you to write down all allowed paths manually. If you really have to restrict your users to be able to download only the pre-approved components, you would have to use a hosted repository where you manually upload your approved content. Please believe us, this is truly terrible, terrible idea.
