firebase / firebase/firebase-admin-python

[FR] Support VERIFY_AND_CHANGE_EMAIL in generate_email_action_link (parity with firebase-admin-node)

未關閉
#949 2 則留言 1 個 reaction 已指派 1 人 已被 @lahirumaramba 認領 在 GitHub 檢視
api: auth
主要語言
Python
星號
1.2k
分支
359
平均合併
5 天 6 分鐘
30 天內合併 PR
2

描述

**Is your feature request related to a problem? Please describe.**

The Identity Toolkit `accounts:sendOobCode` endpoint supports a `VERIFY_AND_CHANGE_EMAIL` request type that generates an OOB link which, when followed, both verifies the new address and updates the user's email. This is the recommended way to implement a secure "change email" flow — the verification link is sent to the *current* address so the flow isn't vulnerable to a stolen session setting a new email without the original owner's knowledge.

The Python Admin SDK cannot generate these links today. `firebase_admin/_auth_utils.py` declares:

```python
VALID_EMAIL_ACTION_TYPES = set(['VERIFY_EMAIL', 'EMAIL_SIGNIN', 'PASSWORD_RESET'])
```

`validate_action_type()` rejects `'VERIFY_AND_CHANGE_EMAIL'` before the request is made, and there is no `new_email` parameter on `generate_email_action_link` to carry the target address.

**Describe the solution you'd like**

Mirror the API added to firebase-admin-node in firebase/firebase-admin-node#1633 (merged April 2022):

1. Add `'VERIFY_AND_CHANGE_EMAIL'` to `VALID_EMAIL_ACTION_TYPES`.
2. Add an optional `new_email: str | None = None` parameter to `generate_email_action_link` (and the corresponding `Client` / `auth` module methods), required when `action_type == 'VERIFY_AND_CHANGE_EMAIL'`.
3. Include `newEmail` in the `accounts:sendOobCode` payload when set.

For reference, the Node signature is:

```ts
generateEmailActionLink(requestType, email, actionCodeSettings?, newEmail?)
```

**Describe alternatives you've considered**

Calling `accounts:sendOobCode` directly through `Client._user_manager._make_request(...)` with `{"requestType": "VERIFY_AND_CHANGE_EMAIL", "email": ..., "newEmail": ..., "returnOobLink": True, ...}`, reusing `firebase_admin._user_mgt.encode_action_code_settings` for `ActionCodeSettings` serialization. This works but depends on SDK internals (private `_user_manager`, private `_make_request`, private `encode_action_code_settings`) and bypasses the SDK's validation and error mapping.

**Additional context**

- Node SDK PR adding the same feature: firebase/firebase-admin-node#1633
- The Identity Toolkit `requestType` enum already includes `VERIFY_AND_CHANGE_EMAIL`; the REST surface is unchanged.
- Verified against `firebase-admin` 7.4.0.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。