firebase / firebase/firebase-js-sdk

High percentage of invalid assessments using App Check with reCAPTCHA Enterprise

Open
#7,969 8 comments 0 reactions 0 assignees View on GitHub
api: appcheck needs-attention question
Dominant language
TypeScript
Stars
5.1k
Forks
1k
Avg merge
2d 21h
Merged PRs (30d)
37

Description

### Operating System

Various

### Browser Version

Various

### Firebase SDK Version

10.7.0

### Firebase SDK Product:

App Check

### Describe your project's tooling

React app on desktop web and mobile web

### Describe the problem

# App Check
I'm observing a high percentage of invalid requests for App Check on the Firestore Database and the Realtime Database:
Screen Shot 2024-01-22 at 4 01 01 PM
Screen Shot 2024-01-22 at 4 01 32 PM
Additionally, the graph for Storage is showing 100% verified, but it only has a few hundred requests.
# reCAPTCHA Enterprise
Below are screenshots from the GCP reCAPTCHA Enterprise dashboard, also for the past 30 days:
Screen Shot 2024-01-22 at 4 07 41 PM
Screen Shot 2024-01-22 at 4 08 20 PM
Screen Shot 2024-01-22 at 4 09 30 PM
# Issue and thoughts
Given that requests are almost all marked as low risk on the GCP dashboard, I'm guessing there might be some bug on the App Check client that's not sending valid requests to reCAPTCHA. I could be wrong, but given the high false positive rates (as reported by users), I simply cannot enforce it across the databases. I'm grateful to the Firebase team for supporting this and hope I can enforce it one day. Let me know if there's any more information I can provide.

### Steps and code to reproduce issue

This is hard to reproduce. I opened an issue a while back https://github.com/firebase/firebase-js-sdk/issues/7116 that was related. From my own usage in the past, app check starts to fail after having the app opened for a long period of time, potentially related to https://github.com/firebase/firebase-js-sdk/issues/6708. However, I've also had a (returning) user seeing it on app open, meaning assessment passed before but failed later on the same device.

In the app, I would `initializeApp()` then `initializeAppCheck` immediately. This happens when users open the app.
```javascript
const app = initializeApp(options, name)

initializeAppCheck(app, {
provider: new ReCaptchaEnterpriseProvider(key),
isTokenAutoRefreshEnabled: true
})
```

Contributor guide

Open the contributing guide

Research direction

No source file or test is named. Start by reviewing the App Check initialization using initializeApp and initializeAppCheck with ReCaptchaEnterpriseProvider, then compare the behavior with issues 7116 and 6708. Done means identifying whether long-lived or returning sessions cause invalid assessments and documenting a reproducible failure or confirmed cause.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, react, typescript
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.