firebase / firebase/firebase-admin-node

When using application default credentials, `access_token` is present but `expires_in` is missing from OAuth response, causing "Unexpected response while fetching access token"

未关闭
#2,291 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
TypeScript
星标
1.7k
派生
419
平均合并
3 天 10 小时
30 天内合并 PR
16

描述

* Operating System version: Mac
* Firebase SDK version: 11.5.0
* Firebase Product: Admin SDK (Auth)
* Node.js version: 18.17.1
* NPM version: 9.6.7

### [REQUIRED] Step 3: Describe the problem

I'm getting the following error from the Admin SDK when using application default credentials to authenticate:

```
{
code: 'app/invalid-credential',
message: 'Credential implementation provided to initializeApp() via the "credential" property failed to fetch a valid Google OAuth2 access token with the following error:
"Error fetching access token: Unexpected response while fetching access token:
{"access_token":"ya29.","token_type":"Bearer"}".'
}
```
_(line breaks added for legibility)_

Which seems to indicate a valid access token _is_ being provisioned (there's a token in there that starts with `ya29.`), but the library isn't reading it correctly.

It seems like the library is [expecting an `expires_in` key to appear as well](https://github.com/firebase/firebase-admin-node/blob/master/src/app/credential-internal.ts#L523) but that key is missing in the response it's getting from Google's auth APIs.

#### Steps to reproduce:

1. Use application default credentials (`GOOGLE_APPLICATION_CREDENTIALS=sa.json` and `credential: applicationDefault()`) with the Node Admin SDK
2. Grab `sa.json` from your project's Service Accounts tab in the Firebase console.
3. Try to use Admin SDK APIs such as `getAuth`, `auth.verifySessionCookie`, etc. (my code is [here](https://github.com/romannurik/express-firebase-auth-gate/blob/main/src/make-gated-app.ts) if needed).
4. Observe [in some cases?] you see the error cited above.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。