The MAL settings used by the shared token machinery: the token endpoint,
error label, header to strip after refresh, and diagnostics identity.
Replayed requests use the bearer token, so they do not need
X-MAL-CLIENT-ID. That header is only for client-ID-only access to public
endpoints. Keeping it could expose the client ID to intermediaries that log
request headers and would conflict with resolveMalCredentials.
The MAL settings used by the shared token machinery: the token endpoint, error label, header to strip after refresh, and diagnostics identity. Replayed requests use the bearer token, so they do not need
X-MAL-CLIENT-ID. That header is only for client-ID-only access to public endpoints. Keeping it could expose the client ID to intermediaries that log request headers and would conflict withresolveMalCredentials.