Skip to content

Commit ff27308

Browse files
committed
chore(identity): address review cleanups on blocking token audiences
Reject a non-string "aud" with InvalidAuthBlockingTokenError rather than letting the membership test raise TypeError, fix the class comment to name the renamed kwarg, drop a stale test comment, and declare cryptography in the dev group since the tests import it directly.
1 parent 7848ad4 commit ff27308

4 files changed

Lines changed: 8 additions & 4 deletions

File tree

‎pyproject.toml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,7 @@ dev = [
4545
"pytest>=7.1.2,<10",
4646
"setuptools>=63.4.2",
4747
"pytest-cov>=3.0.0",
48+
"cryptography>=3.4.0",
4849
"mypy>=1.0.0",
4950
"sphinx>=6.1.3",
5051
"sphinxcontrib-napoleon>=0.7",

‎src/firebase_functions/private/token_verifier.py‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@
3434
# mypy: ignore-errors
3535
# TODO remove once firebase-admin supports this directly.
3636
# Modified from src/firebase_admin/_token_gen.py to add
37-
# support for app_check tokens (expected_audience kwarg and
37+
# support for app_check tokens (expected_audiences kwarg and
3838
# usage are new, plus None for audience on google.oauth2.id_token.verify_token call)
3939
class _JWTVerifier:
4040
"""Verifies Firebase JWTs (ID tokens or session cookies)."""
@@ -105,7 +105,10 @@ def verify(self, token, request):
105105
elif (
106106
not emulated
107107
and self.expected_audiences
108-
and not any(expected in audience for expected in self.expected_audiences)
108+
and not (
109+
isinstance(audience, str)
110+
and any(expected in audience for expected in self.expected_audiences)
111+
)
109112
):
110113
expected = " or ".join(f'"{expected}"' for expected in self.expected_audiences)
111114
error_message = (

‎tests/test_identity_fn.py‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,6 @@
2121
"iat": 0,
2222
}
2323
)
24-
# Patch the reference _identity_fn holds rather than the sys.modules entry, which
25-
# `import ... as` bypasses once anything else has imported the real module.
2624

2725

2826
class TestIdentity(unittest.TestCase):

‎uv.lock‎

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)