firebase / firebase/firebase-admin-python

[FR] Support VERIFY_AND_CHANGE_EMAIL in generate_email_action_link (parity with firebase-admin-node)

Abierto
#949 2 comentarios 1 reacción 1 asignado Reclamado por @lahirumaramba Ver en GitHub
api: auth
Lenguaje dominante
Python
Estrellas
1.2k
Forks
359
Merge medio
5 d 6 min
PR fusionados (30 d)
2

Descripción

**Is your feature request related to a problem? Please describe.**

The Identity Toolkit `accounts:sendOobCode` endpoint supports a `VERIFY_AND_CHANGE_EMAIL` request type that generates an OOB link which, when followed, both verifies the new address and updates the user's email. This is the recommended way to implement a secure "change email" flow — the verification link is sent to the *current* address so the flow isn't vulnerable to a stolen session setting a new email without the original owner's knowledge.

The Python Admin SDK cannot generate these links today. `firebase_admin/_auth_utils.py` declares:

```python
VALID_EMAIL_ACTION_TYPES = set(['VERIFY_EMAIL', 'EMAIL_SIGNIN', 'PASSWORD_RESET'])
```

`validate_action_type()` rejects `'VERIFY_AND_CHANGE_EMAIL'` before the request is made, and there is no `new_email` parameter on `generate_email_action_link` to carry the target address.

**Describe the solution you'd like**

Mirror the API added to firebase-admin-node in firebase/firebase-admin-node#1633 (merged April 2022):

1. Add `'VERIFY_AND_CHANGE_EMAIL'` to `VALID_EMAIL_ACTION_TYPES`.
2. Add an optional `new_email: str | None = None` parameter to `generate_email_action_link` (and the corresponding `Client` / `auth` module methods), required when `action_type == 'VERIFY_AND_CHANGE_EMAIL'`.
3. Include `newEmail` in the `accounts:sendOobCode` payload when set.

For reference, the Node signature is:

```ts
generateEmailActionLink(requestType, email, actionCodeSettings?, newEmail?)
```

**Describe alternatives you've considered**

Calling `accounts:sendOobCode` directly through `Client._user_manager._make_request(...)` with `{"requestType": "VERIFY_AND_CHANGE_EMAIL", "email": ..., "newEmail": ..., "returnOobLink": True, ...}`, reusing `firebase_admin._user_mgt.encode_action_code_settings` for `ActionCodeSettings` serialization. This works but depends on SDK internals (private `_user_manager`, private `_make_request`, private `encode_action_code_settings`) and bypasses the SDK's validation and error mapping.

**Additional context**

- Node SDK PR adding the same feature: firebase/firebase-admin-node#1633
- The Identity Toolkit `requestType` enum already includes `VERIFY_AND_CHANGE_EMAIL`; the REST surface is unchanged.
- Verified against `firebase-admin` 7.4.0.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.