firebase / firebase/firebase-admin-python

[FR] Support VERIFY_AND_CHANGE_EMAIL in generate_email_action_link (parity with firebase-admin-node)

Offen
#949 2 Kommentare 1 Reaktion 1 zugewiesene Person Beansprucht von @lahirumaramba Auf GitHub ansehen
api: auth
Vorherrschende Sprache
Python
Sterne
1.2k
Forks
359
Ø Merge
5 T. 6 Min.
Gemergte PRs (30 T.)
2

Beschreibung

**Is your feature request related to a problem? Please describe.**

The Identity Toolkit `accounts:sendOobCode` endpoint supports a `VERIFY_AND_CHANGE_EMAIL` request type that generates an OOB link which, when followed, both verifies the new address and updates the user's email. This is the recommended way to implement a secure "change email" flow — the verification link is sent to the *current* address so the flow isn't vulnerable to a stolen session setting a new email without the original owner's knowledge.

The Python Admin SDK cannot generate these links today. `firebase_admin/_auth_utils.py` declares:

```python
VALID_EMAIL_ACTION_TYPES = set(['VERIFY_EMAIL', 'EMAIL_SIGNIN', 'PASSWORD_RESET'])
```

`validate_action_type()` rejects `'VERIFY_AND_CHANGE_EMAIL'` before the request is made, and there is no `new_email` parameter on `generate_email_action_link` to carry the target address.

**Describe the solution you'd like**

Mirror the API added to firebase-admin-node in firebase/firebase-admin-node#1633 (merged April 2022):

1. Add `'VERIFY_AND_CHANGE_EMAIL'` to `VALID_EMAIL_ACTION_TYPES`.
2. Add an optional `new_email: str | None = None` parameter to `generate_email_action_link` (and the corresponding `Client` / `auth` module methods), required when `action_type == 'VERIFY_AND_CHANGE_EMAIL'`.
3. Include `newEmail` in the `accounts:sendOobCode` payload when set.

For reference, the Node signature is:

```ts
generateEmailActionLink(requestType, email, actionCodeSettings?, newEmail?)
```

**Describe alternatives you've considered**

Calling `accounts:sendOobCode` directly through `Client._user_manager._make_request(...)` with `{"requestType": "VERIFY_AND_CHANGE_EMAIL", "email": ..., "newEmail": ..., "returnOobLink": True, ...}`, reusing `firebase_admin._user_mgt.encode_action_code_settings` for `ActionCodeSettings` serialization. This works but depends on SDK internals (private `_user_manager`, private `_make_request`, private `encode_action_code_settings`) and bypasses the SDK's validation and error mapping.

**Additional context**

- Node SDK PR adding the same feature: firebase/firebase-admin-node#1633
- The Identity Toolkit `requestType` enum already includes `VERIFY_AND_CHANGE_EMAIL`; the REST surface is unchanged.
- Verified against `firebase-admin` 7.4.0.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.