firebase / firebase/firebase-admin-node

getUser() return value contains passwordHash and passwordSalt

未关闭
#501 15 条评论 5 个 reaction 已指派 1 人 已被 @bojeil-google 认领 在 GitHub 查看
api: auth type: bug
主要语言
TypeScript
星标
1.7k
派生
419
平均合并
3 天 10 小时
30 天内合并 PR
16

描述

The `UserRecord` returned by `admin.auth().getUser()` contains `passwordHash` and `passwordSalt` fields.

```
const admin = require('firebase-admin')
admin.initializeApp();
admin.auth().getUser(uid)
.then((user) => console.log(user));
```

This resulted in:

```
UserRecord {
uid: 'e1b2NmnasZXw0QtpYFcZ88IeK5t1',
email: '********@gmail.com',
emailVerified: true,
displayName: undefined,
photoURL: undefined,
phoneNumber: undefined,
disabled: false,
metadata:
UserMetadata {
creationTime: 'Wed, 03 Apr 2019 23:36:27 GMT',
lastSignInTime: 'Thu, 04 Apr 2019 00:38:10 GMT' },
providerData:
[ UserInfo {
uid: '********@gmail.com',
displayName: undefined,
email: '********@gmail.com',
photoURL: undefined,
providerId: 'password',
phoneNumber: undefined } ],
passwordHash: 'UkVEQUNURUQ=',
passwordSalt: undefined,
customClaims: undefined,
tokensValidAfterTime: 'Wed, 03 Apr 2019 23:36:27 GMT' }
```

This is contrary to the [documented behavior](https://firebase.google.com/docs/reference/admin/node/admin.auth.UserRecord#passwordHash):

> passwordHash
> (string or undefined)
>
> The user’s hashed password (base64-encoded), only if Firebase Auth hashing algorithm (SCRYPT) is used. If a different hashing algorithm had been used when uploading this user, as is typical when migrating from another Auth system, this will be an empty string. If no password is set, this is null. This is only available when the user is obtained from listUsers().

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。