Requests can be sent through a tunnel host with inherited headers stripped, only for callers that ask.
What's wrong with this entry?
The shared HTTP request helper accepts a new tunnel option that sends the request to a tunnel host instead of the normal API base URL and removes a reserved set of headers before sending. It only does anything for callers that pass the option, and it refuses to run unless the request also targets the frame host with no authentication.
- Any header whose lowercased name is in the reserved set is deleted, so headers inherited from the surrounding request are not forwarded through the tunnel.
- Misuse throws with the message "frameTunnel requires host 'frame' and auth 'none'".
frameTunnel requires host 'frame' and auth 'none'
Strings lifted out of the shipped bundle, so the claim above can be checked against them.