Cesium Ion Auth Provider
Cesium Ion auth. Point the layer at https://api.cesium.com/v1/assets/<id>/endpoint; the first fetch returns {type, url, accessToken} — redirectFor follows url and captures the per-asset token for subsequent Bearer headers. One provider instance per asset.
Properties
Hard-coded identifier used as the discriminator when serializing the provider via Ogc3dAuthCredentials; must survive R8 / ProGuard / Kotlin-Native obfuscation.
Per-asset tokens are re-issued by the /endpoint fetch, so recovery can cure a rejection.
Functions
Drop the captured asset access token + endpoint-followed latch so a re-fetch of the /endpoint URL re-issues a fresh Bearer token.
Whether statusCode on a fetch means the credential is stale and the session must be rebootstrapped. Default 401/403; providers override for their own codes (Google returns 400 on an expired/mismatched session=).
Endpoint URL carries the per-asset token in its body envelope and must always re-fetch to refresh; the redirected tileset.json is also session-bound to the bearer header so neither should be cached.
Inspect a successful tileset.json fetch result so the provider can update its internal state from the response (e.g. Google's session query parameter on the response URL, Cesium Ion's asset endpoint URL + access token in the response body). Default no-op.
Ask the provider whether a successful tileset fetch should redirect to a different URL. Returns the new URL when the response is itself a redirect envelope (e.g. Cesium Ion's api.cesium.com/v1/assets/<id>/endpoint returns JSON with url + accessToken fields; the actual tileset.json lives at the returned URL), or null when body is the final tileset.json content.
Rewrite a child URI discovered while parsing a tileset. Lets providers propagate persistent query parameters (Google's session token) onto every child URI as soon as the tree is built, instead of waiting until each child fetch fires. Default returns the URI unchanged.
Rewrite an outgoing request. Called once per HTTP fetch immediately before the GET. Implementations may mutate the URL (e.g. append a token) and/or supply extra headers. Returning the input unchanged is fine — see NoAuthProvider.