DPoPRequestDecorator
Public convenience API for app developers stamping DPoP/Bearer authorization headers on HTTP requests built outside the SDK's RestClient.
Gating is per-credential via DPoPKeyManager.shouldAttachDPoP, not the global com.salesforce.androidsdk.app.SalesforceSDKManager.useDPoP flag. A DPoP-bound credential normally carries proofs regardless of that flag; when a UI session exists, SalesforceSDKManager.shouldUseUiSidBearerForPath may select clean UI-session Bearer authentication for a request path instead.
Functions
Stamps Authorization and, if the account is DPoP-bound, a DPoP proof header on builder. No-op when UserAccount.getAuthToken is null or empty. Rejects an incomplete DPoP credential with IOException before mutating builder.
Stores DPOP_NONCE_HEADER from response in DPoPNonceCache when present. No-op if the header, credentialsIdentifier, or host is missing or empty.
Returns true if response is a DPoP nonce challenge per RFC 9449 §8: