firebase / firebase/firebase-admin-python
[FR] Support VERIFY_AND_CHANGE_EMAIL in generate_email_action_link (parity with firebase-admin-node)
- Linguagem predominante
- Python
- Estrelas
- 1.2k
- Forks
- 359
- Merge médio
- 5d 6min
- PRs com merge (30d)
- 2
Descrição
**Is your feature request related to a problem? Please describe.**
The Identity Toolkit `accounts:sendOobCode` endpoint supports a `VERIFY_AND_CHANGE_EMAIL` request type that generates an OOB link which, when followed, both verifies the new address and updates the user's email. This is the recommended way to implement a secure "change email" flow — the verification link is sent to the *current* address so the flow isn't vulnerable to a stolen session setting a new email without the original owner's knowledge.
The Python Admin SDK cannot generate these links today. `firebase_admin/_auth_utils.py` declares:
```python
VALID_EMAIL_ACTION_TYPES = set(['VERIFY_EMAIL', 'EMAIL_SIGNIN', 'PASSWORD_RESET'])
```
`validate_action_type()` rejects `'VERIFY_AND_CHANGE_EMAIL'` before the request is made, and there is no `new_email` parameter on `generate_email_action_link` to carry the target address.
**Describe the solution you'd like**
Mirror the API added to firebase-admin-node in firebase/firebase-admin-node#1633 (merged April 2022):
1. Add `'VERIFY_AND_CHANGE_EMAIL'` to `VALID_EMAIL_ACTION_TYPES`.
2. Add an optional `new_email: str | None = None` parameter to `generate_email_action_link` (and the corresponding `Client` / `auth` module methods), required when `action_type == 'VERIFY_AND_CHANGE_EMAIL'`.
3. Include `newEmail` in the `accounts:sendOobCode` payload when set.
For reference, the Node signature is:
```ts
generateEmailActionLink(requestType, email, actionCodeSettings?, newEmail?)
```
**Describe alternatives you've considered**
Calling `accounts:sendOobCode` directly through `Client._user_manager._make_request(...)` with `{"requestType": "VERIFY_AND_CHANGE_EMAIL", "email": ..., "newEmail": ..., "returnOobLink": True, ...}`, reusing `firebase_admin._user_mgt.encode_action_code_settings` for `ActionCodeSettings` serialization. This works but depends on SDK internals (private `_user_manager`, private `_make_request`, private `encode_action_code_settings`) and bypasses the SDK's validation and error mapping.
**Additional context**
- Node SDK PR adding the same feature: firebase/firebase-admin-node#1633
- The Identity Toolkit `requestType` enum already includes `VERIFY_AND_CHANGE_EMAIL`; the REST surface is unchanged.
- Verified against `firebase-admin` 7.4.0.
Guia de contribuição
Avaliação
Esta issue ainda não foi avaliada.