basalt / fastify/src / DEFAULT_IDEMPOTENCY_CREDENTIAL_HEADERS
Variable: DEFAULT_IDEMPOTENCY_CREDENTIAL_HEADERS
> const DEFAULT_IDEMPOTENCY_CREDENTIAL_HEADERS: readonly ["authorization", "x-session-id", "cookie", "x-api-key"]
Defined in: fastify/src/idempotency.ts:13
Headers that carry caller credentials. Every one present is folded into the replay scope, so a cached response can only be replayed to a caller presenting the exact same credential material (bearer token, session id, session cookie or API key). The replay runs before route guards, so this is what keeps a stranger who guesses an Idempotency-Key from receiving someone else's response.