Skip to content

identity_fn.AuthBlockingEvent is still missing auth_type and resource #316

Description

@jhuleatt

Summary

#231 added event_type, email_type, and sms_type to identity_fn.AuthBlockingEvent (thanks!). Two properties from the blocking functions doc are still missing, so code written from the doc fails on Python:

Doc property Node firebase-functions Python firebase-functions
authType authType: "USER" | "UNAUTHENTICATED" not present
resource resource: { service, name } not present

Repro

from firebase_functions import identity_fn

@identity_fn.before_user_signed_in()
def handle(event: identity_fn.AuthBlockingEvent):
    event.auth_type  # AttributeError
    event.resource   # AttributeError

Checked against the AuthBlockingEvent dataclass on main (identity_fn.py) and in 0.6.0.

Where the values come from

The Node SDK derives both from the blocking token rather than reading dedicated claims, so Python can do the same. From parseAuthEventContext:

  • authType is "USER" when the token has a user_record, otherwise "UNAUTHENTICATED".
  • resource.service is identitytoolkit.googleapis.com, and resource.name is projects/<project-id>/tenants/<tenant_id> when the token has a tenant_id, otherwise projects/<project-id>.

Context

First reported in firebase/functions-samples#1129 and in #224, which #231 partly addressed. I'm closing the samples issue in favor of this one, since the fix belongs in the SDK. Until then, the tenant is available as event.data.tenant_id.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions