firebase / firebase/firebase-admin-node

import HMAC1 users with different hash algorithm keys one after another not setting correct passwords

未关闭
#2,590 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
needs-triage
主要语言
TypeScript
星标
1.7k
派生
419
平均合并
3 天 10 小时
30 天内合并 PR
16

描述

### [READ] Step 1: Are you in the right place?

* For issues related to __the code in this repository__ file a Github issue.
* If the issue pertains to Cloud Firestore, read the instructions in the "Firestore issue"
template.
* For general technical questions, post a question on [StackOverflow](http://stackoverflow.com/)
with the firebase tag.
* For general Firebase discussion, use the [firebase-talk](https://groups.google.com/forum/#!forum/firebase-talk)
google group.
* For help troubleshooting your application that does not fall under one
of the above categories, reach out to the personalized
[Firebase support channel](https://firebase.google.com/support/).

### [REQUIRED] Step 2: Describe your environment

* Operating System version: windows 10
* Firebase SDK version: 12.1.1
* Firebase Product: admin
* Node.js version: 20.11.0
* NPM version: 10.2.4

### [REQUIRED] Step 3: Describe the problem
When using the importUsers function, it is not correctly importing users where each one has a different hash key.

I am importing users where each user's password was created using HMAC sha1 but each user had its own key. I was trying to import 1 user per function call but when I import say 100 users one at a time, the majority of them import incorrectly(code below should make this easy to understand) . If I rerun a subset of around 10 users using the exact same information passed in they then will login correctly.

Is there some internal limitation or batching happening? I am importing users one at a time and respecting the API quotas and they are successful imports. This has been very confusing to understand the correct way to handle this scenario is and it feels difficult to understand a pattern.

Given they all import with no issues but only some actually log in correctly and when I rerun then more will work, tells me I am not passing in bad data but something about how they process is different each time.

#### Steps to reproduce:

What happened? How can we make the problem occur?
This could be a description, log/console output, etc.

#### Relevant Code:
The code below will generate 100 users and import them one at a time and then when I attempt to log in, only the last 10 ish will even work, all others get incorrect password errors.

```
const crypto = require('crypto');
const admin = require('firebase-admin');

var serviceAccount = require(".\\key.json");
admin.initializeApp({
credential: admin.credential.cert(serviceAccount),
});

const randomString = (length) => {
return Math.random().toString(36).slice(2, length + 2)
}

const users = [];
for(let i = 0; i <= 100; i++) {
const text = 'password'
const key = randomString(12);
const passwordHash = crypto.createHmac('sha1', key)
.update(text)
.digest('hex')

users.push({
plainPassword: text,
passwordHash,
key,
email_address: `${i}@gmail.com`,
id: i.toString()
})
}

async function start() {
for (const user of users) {
const result = await admin.auth().importUsers([
{
uid: user.id,
email: user.email_address,
passwordHash: Buffer.from(user.passwordHash, 'hex'),
emailVerified: true
}
], {
hash: {
algorithm: "HMAC_SHA1",
key: Buffer.from(user.key)
}
})

console.log(result.errors[0]);
}
}

start();
```

贡献指南

打开贡献指南

调研方向

Start at the admin.auth().importUsers entry point and trace how the hash option and per-user HMAC_SHA1 key are handled across sequential imports. Reproduce the supplied script, then verify that users imported with different keys all authenticate with their supplied passwords and that import results remain successful.

由索引模型根据 Issue 内容生成。

评估

技术栈
firebase, javascript, nodejs
领域
authentication, backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
38/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。