firebase / firebase/firebase-admin-node

Firebase Admin SDK: getDownloadUrl - Permission denied. No READ permission

Open
#2,344 17 comments 16 reactions 2 assignees Claimed by @maneesht View on GitHub
api: storage
Dominant language
TypeScript
Stars
1.7k
Forks
419
Avg merge
3d 10h
Merged PRs (30d)
16

Description

### Describe your environment

* Operating System version: OSX (and in the cloud environment)
* Firebase SDK version: ^11.11.0 <= firebase-admin
* Firebase Product: firebase-admin / google-storage / firebase-admin/storage
* Node.js version: 16.16.0
* NPM version: 8.11.0

### Describe the problem:

I have now tried for a very long time to follow these docs in order to get `getDownloadURL` to work. https://firebase.google.com/docs/storage/admin/start#use_a_default_bucket
https://firebase.google.com/docs/storage/admin/start#shareable_urls

Regardless of how I initialize my app, when trying to use `getDownloadURL` I get `Error: Permission denied. No READ permission.`

Here is how different ways I tried initializing:
```js
initializeApp({
credential: applicationDefault(),
storageBucket: "my-bucket.appspot.com",
});
```
```js
initializeApp();
```
```js
initializeApp({
credential: cert(serviceAcount), // loaded from .json file (directly downloaded from firebase console)
storageBucket: "my-bucket.appspot.com",
});
```
```js
initializeApp({
credential: cert({
projectId: "my-project-id",
privateKey: "my-private-key",
clientEmail: "my-client-email"
}), // grabbed from .json file (directly downloaded from firebase console)
storageBucket: "my-bucket.appspot.com",
});
```

Furthermore, I have tried adding IAM roles to the service account:
![Screenshot 2023-10-19 at 16 54 45](https://github.com/firebase/firebase-admin-node/assets/16811871/8da9e338-4d60-4744-adf7-8ae933bc2f58)
-
What I am trying to accomplish is simply what is done in the before-mentioned docs:
```js
// Triggered from storage.object().onFinalize(generateThumbnail);
const bucket = getStorage().bucket(object.bucket);
...
// Cloud Storage files.
const file = bucket.file(filePath);
const url = await getDownloadURL(file);
console.log({ url });
```

What is going wrong here, as the docs states clearly I firebase admin sdk should have access by default?

Stacktrace: (from emulator)

```
⚠ functions: Error: Permission denied. No READ permission.
at new ApiError (/../functions/node_modules/firebase-admin/node_modules/@google-cloud/storage/build/src/nodejs-common/util.js:80:15)
at Util.parseHttpRespBody (/../functions/node_modules/firebase-admin/node_modules/@google-cloud/storage/build/src/nodejs-common/util.js:215:38)
at Util.handleResp (/../functions/node_modules/firebase-admin/node_modules/@google-cloud/storage/build/src/nodejs-common/util.js:156:117)
at /../functions/node_modules/firebase-admin/node_modules/@google-cloud/storage/build/src/nodejs-common/util.js:538:22
at onResponse (/../functions/node_modules/firebase-admin/node_modules/retry-request/index.js:240:7)
at /../functions/node_modules/firebase-admin/node_modules/teeny-request/build/src/index.js:217:17
at processTicksAndRejections (node:internal/process/task_queues:96:5)
```

My service account file:
```json
{
"type":"..",
"project_id":"..",
"private_key_id":"..",
"private_key":"..",
"client_email":"..",
"client_id":"..",
"auth_uri":"..",
"token_uri":"..",
"auth_provider_x509_cert_url":"..",
"client_x509_cert_url":"..",
"universe_domain":"..",
}
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.