firebase / firebase/firebase-admin-python

[FR] Support VERIFY_AND_CHANGE_EMAIL in generate_email_action_link (parity with firebase-admin-node)

未关闭
#949 2 条评论 1 个 reaction 已指派 1 人 已被 @lahirumaramba 认领 在 GitHub 查看
api: auth
主要语言
Python
星标
1.2k
派生
359
平均合并
5 天 6 分钟
30 天内合并 PR
2

描述

**Is your feature request related to a problem? Please describe.**

The Identity Toolkit `accounts:sendOobCode` endpoint supports a `VERIFY_AND_CHANGE_EMAIL` request type that generates an OOB link which, when followed, both verifies the new address and updates the user's email. This is the recommended way to implement a secure "change email" flow — the verification link is sent to the *current* address so the flow isn't vulnerable to a stolen session setting a new email without the original owner's knowledge.

The Python Admin SDK cannot generate these links today. `firebase_admin/_auth_utils.py` declares:

```python
VALID_EMAIL_ACTION_TYPES = set(['VERIFY_EMAIL', 'EMAIL_SIGNIN', 'PASSWORD_RESET'])
```

`validate_action_type()` rejects `'VERIFY_AND_CHANGE_EMAIL'` before the request is made, and there is no `new_email` parameter on `generate_email_action_link` to carry the target address.

**Describe the solution you'd like**

Mirror the API added to firebase-admin-node in firebase/firebase-admin-node#1633 (merged April 2022):

1. Add `'VERIFY_AND_CHANGE_EMAIL'` to `VALID_EMAIL_ACTION_TYPES`.
2. Add an optional `new_email: str | None = None` parameter to `generate_email_action_link` (and the corresponding `Client` / `auth` module methods), required when `action_type == 'VERIFY_AND_CHANGE_EMAIL'`.
3. Include `newEmail` in the `accounts:sendOobCode` payload when set.

For reference, the Node signature is:

```ts
generateEmailActionLink(requestType, email, actionCodeSettings?, newEmail?)
```

**Describe alternatives you've considered**

Calling `accounts:sendOobCode` directly through `Client._user_manager._make_request(...)` with `{"requestType": "VERIFY_AND_CHANGE_EMAIL", "email": ..., "newEmail": ..., "returnOobLink": True, ...}`, reusing `firebase_admin._user_mgt.encode_action_code_settings` for `ActionCodeSettings` serialization. This works but depends on SDK internals (private `_user_manager`, private `_make_request`, private `encode_action_code_settings`) and bypasses the SDK's validation and error mapping.

**Additional context**

- Node SDK PR adding the same feature: firebase/firebase-admin-node#1633
- The Identity Toolkit `requestType` enum already includes `VERIFY_AND_CHANGE_EMAIL`; the REST surface is unchanged.
- Verified against `firebase-admin` 7.4.0.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。