{"version":3,"file":"http-options.cjs","sources":["../../../../src/core/http/http-options.ts"],"sourcesContent":["/**\n * The axios keys a caller may hand the SDK at construction, and the runtime\n * filter that enforces it.\n *\n * The list is the single source of truth for both halves: `TypeHttpOptions`\n * (in `types/http.ts`) is `Pick<AxiosRequestConfig, typeof HTTP_OPTION_KEYS[number]>`,\n * and `pickHttpOptions` below drops everything else before the config reaches\n * `axios.create`.\n *\n * A type alone does not enforce this. TypeScript's excess-property check fires\n * only on a direct object literal with no overlapping key, so\n * `{ timeout: 5000, transformRequest: [...] }` — or any value passed through a\n * variable, or any call from plain JavaScript — used to reach axios untouched.\n * Measured: a `transformRequest` smuggled in that way replaced the request body\n * wholesale, with no error on either side and a portal-side failure only, and a\n * `headers` entry was merged over the SDK's own. `baseURL`, `paramsSerializer`\n * and `validateStatus` are the same class of problem: they are how the SDK talks\n * to the portal, and overriding them breaks it quietly.\n *\n * `headers` is the one exception, and it is not in the list: the transport\n * constructor has merged a caller's headers over the SDK's own since #144 and\n * still does, so that contract is untouched. It is not *offered* either —\n * `TypeHttpOptions` does not accept it, so `httpOptions: { headers: … }` is a\n * compile error on every entry point. The merge survives for the path that\n * predates the type: a direct `new HttpV2(...)`, or a call from untyped\n * JavaScript. It stays out of the type because the SDK's own `Content-Type` and\n * `Authorization` are decided per request, where an instance header cannot\n * reach them — see `abstract-http.ts`.\n *\n * Dropped rather than refused, deliberately. These arrive at construction, where\n * throwing would take down an app over a key it may have carried for years; and\n * the caller is not left guessing — the dropped **names** are logged (never the\n * values: a `headers` entry can carry a credential). Everything outside this\n * list stays reachable through `getHttpClient(version).ajaxClient.defaults`,\n * where it reads as the deliberate act it is.\n */\nexport const HTTP_OPTION_KEYS = [\n  'adapter',\n  'timeout',\n  'timeoutErrorMessage',\n  'proxy',\n  'httpAgent',\n  'httpsAgent',\n  'maxRedirects',\n  'maxContentLength',\n  'maxBodyLength',\n  'decompress',\n  'withCredentials'\n] as const\n\n/**\n * Keep only the allowed keys of `options`, and report the names of the rest.\n *\n * Own enumerable string keys only: a value inherited from a prototype, and a\n * symbol key, are neither kept nor reported. Both are the safe direction — the\n * previous spread copied symbol keys into axios, and nothing in the option\n * surface is reachable that way — but an allowed key that exists only on a\n * prototype is lost silently, which is why it is said here.\n *\n * @param options - Whatever a caller passed as `httpOptions` — typed or not.\n * @returns The filtered config and the names that were dropped, in input order.\n */\nexport function pickHttpOptions(options?: null | object): {\n  picked: Record<string, unknown>\n  dropped: string[]\n} {\n  const picked: Record<string, unknown> = {}\n  const dropped: string[] = []\n\n  if (!options) {\n    return { picked, dropped }\n  }\n\n  for (const [key, value] of Object.entries(options)) {\n    if ((HTTP_OPTION_KEYS as readonly string[]).includes(key)) {\n      picked[key] = value\n      continue\n    }\n\n    if ('headers' === key) {\n      // Handled by the caller of this function, which merges it over the SDK's\n      // own defaults (#144). Neither kept here nor reported as dropped.\n      continue\n    }\n\n    dropped.push(key)\n  }\n\n  return { picked, dropped }\n}\n"],"names":[],"mappings":";;;;;;;;;;;;AAoCO,MAAM,gBAAA,GAAmB;AAAA,EAC9B,SAAA;AAAA,EACA,SAAA;AAAA,EACA,qBAAA;AAAA,EACA,OAAA;AAAA,EACA,WAAA;AAAA,EACA,YAAA;AAAA,EACA,cAAA;AAAA,EACA,kBAAA;AAAA,EACA,eAAA;AAAA,EACA,YAAA;AAAA,EACA;AACF;AAcO,SAAS,gBAAgB,OAAA,EAG9B;AACA,EAAA,MAAM,SAAkC,EAAC;AACzC,EAAA,MAAM,UAAoB,EAAC;AAE3B,EAAA,IAAI,CAAC,OAAA,EAAS;AACZ,IAAA,OAAO,EAAE,QAAQ,OAAA,EAAQ;AAAA,EAC3B;AAEA,EAAA,KAAA,MAAW,CAAC,GAAA,EAAK,KAAK,KAAK,MAAA,CAAO,OAAA,CAAQ,OAAO,CAAA,EAAG;AAClD,IAAA,IAAK,gBAAA,CAAuC,QAAA,CAAS,GAAG,CAAA,EAAG;AACzD,MAAA,MAAA,CAAO,GAAG,CAAA,GAAI,KAAA;AACd,MAAA;AAAA,IACF;AAEA,IAAA,IAAI,cAAc,GAAA,EAAK;AAGrB,MAAA;AAAA,IACF;AAEA,IAAA,OAAA,CAAQ,KAAK,GAAG,CAAA;AAAA,EAClB;AAEA,EAAA,OAAO,EAAE,QAAQ,OAAA,EAAQ;AAC3B;AA3BgB,MAAA,CAAA,eAAA,EAAA,iBAAA,CAAA;;;;;"}