Composite Auth Provider
Chains multiple providers so callers can stack auth (e.g. Ion bearer token + internal tracing headers). Providers are applied in order; each one sees the URL + headers produced by the previous one.
Properties
Hard-coded identifier used as the discriminator when serializing the provider via Ogc3dAuthCredentials; must survive R8 / ProGuard / Kotlin-Native obfuscation.
Recovery is worth attempting if any child can refresh its session.
Functions
Invalidate every child's session state — used on auth-rejection recovery.
Auth-rejection if any child treats the code as one (e.g. Google's 400).
Cacheable iff every child says so — any veto from one provider wins.
Inspect a successful tileset.json fetch result so the provider can update its internal state from the response (e.g. Google's session query parameter on the response URL, Cesium Ion's asset endpoint URL + access token in the response body). Default no-op.
Returns the first non-null redirect URL in chain order. Multiple providers requesting redirects at the same time would be a configuration error — the spec is "one redirect per response," and chained Cesium-Ion-plus-Custom-Headers cases want Ion's redirect.
Rewrite a child URI discovered while parsing a tileset. Lets providers propagate persistent query parameters (Google's session token) onto every child URI as soon as the tree is built, instead of waiting until each child fetch fires. Default returns the URI unchanged.
Rewrite an outgoing request. Called once per HTTP fetch immediately before the GET. Implementations may mutate the URL (e.g. append a token) and/or supply extra headers. Returning the input unchanged is fine — see NoAuthProvider.