MAX_TOKEN_BYTES
const MAX_TOKEN_BYTES: 4096 = 4096;Defined in: src/token-identity.ts:95
Cap on a credential we will even attempt to resolve. Anything longer is not a bearer token; refusing early keeps a resolver from being handed megabytes.
Measured in UTF-8 bytes, which is the unit the purpose implies – what
is bounded is what a resolver would have to handle, and megabytes are
bytes. Spelled out because the ports reached for three different units:
codepoints in Python and Rust, UTF-16 code units in Java, C# and (until
now) TypeScript, bytes in Go and C++. All three agree for an ASCII
credential, which every real bearer token is, so this bites only on a
multibyte one – and "x".length counting UTF-16 units means this port was
measuring a multibyte credential short. Bytes is also the most
conservative of the three, so standardising on it can only refuse earlier.
