Summary
#231 added event_type, email_type, and sms_type to identity_fn.AuthBlockingEvent (thanks!). Two properties from the blocking functions doc are still missing, so code written from the doc fails on Python:
| Doc property |
Node firebase-functions |
Python firebase-functions |
authType |
authType: "USER" | "UNAUTHENTICATED" |
not present |
resource |
resource: { service, name } |
not present |
Repro
from firebase_functions import identity_fn
@identity_fn.before_user_signed_in()
def handle(event: identity_fn.AuthBlockingEvent):
event.auth_type # AttributeError
event.resource # AttributeError
Checked against the AuthBlockingEvent dataclass on main (identity_fn.py) and in 0.6.0.
Where the values come from
The Node SDK derives both from the blocking token rather than reading dedicated claims, so Python can do the same. From parseAuthEventContext:
authType is "USER" when the token has a user_record, otherwise "UNAUTHENTICATED".
resource.service is identitytoolkit.googleapis.com, and resource.name is projects/<project-id>/tenants/<tenant_id> when the token has a tenant_id, otherwise projects/<project-id>.
Context
First reported in firebase/functions-samples#1129 and in #224, which #231 partly addressed. I'm closing the samples issue in favor of this one, since the fix belongs in the SDK. Until then, the tenant is available as event.data.tenant_id.
Summary
#231 added
event_type,email_type, andsms_typetoidentity_fn.AuthBlockingEvent(thanks!). Two properties from the blocking functions doc are still missing, so code written from the doc fails on Python:firebase-functionsfirebase-functionsauthTypeauthType: "USER" | "UNAUTHENTICATED"resourceresource: { service, name }Repro
Checked against the
AuthBlockingEventdataclass onmain(identity_fn.py) and in 0.6.0.Where the values come from
The Node SDK derives both from the blocking token rather than reading dedicated claims, so Python can do the same. From
parseAuthEventContext:authTypeis"USER"when the token has auser_record, otherwise"UNAUTHENTICATED".resource.serviceisidentitytoolkit.googleapis.com, andresource.nameisprojects/<project-id>/tenants/<tenant_id>when the token has atenant_id, otherwiseprojects/<project-id>.Context
First reported in firebase/functions-samples#1129 and in #224, which #231 partly addressed. I'm closing the samples issue in favor of this one, since the fix belongs in the SDK. Until then, the tenant is available as
event.data.tenant_id.