Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
16 commits
Select commit Hold shift + click to select a range
7b86a97
DataConnectAuth.kt: Add authUid property
dconeybe Oct 17, 2025
44bcda8
DataConnectAuth.kt: add authUid to GetAuthTokenResult
dconeybe Oct 17, 2025
2567711
DataConnectAuthUnitTest.kt: Add tests for authUids population
dconeybe Oct 17, 2025
5b851e7
CHANGELOG.md: add entry
dconeybe Oct 17, 2025
0d99e6e
Merge remote-tracking branch 'origin/main' into QueryHashIncorporates…
dconeybe Oct 22, 2025
c2e6da1
DataConnectAuth.kt: remove authUid property, since it's not needed
dconeybe Oct 22, 2025
eb214ad
DataConnectAuth.kt: just get the authUid from the sub claim, not the …
dconeybe Oct 22, 2025
386cfaa
DataConnectGrpcMetadataUnitTest.kt: fix for non-null access token res…
dconeybe Oct 22, 2025
c6e1a05
DataConnectGrpcMetadataUnitTest.kt: fix tests for null access token.
dconeybe Oct 22, 2025
b93107c
Merge branch 'main' into dconeybe/dataconnect/QueryHashIncorporatesAu…
dconeybe Oct 22, 2025
883681e
Merge branch 'main' into dconeybe/dataconnect/GrpcMetadataUnitTestNul…
dconeybe Oct 22, 2025
d702f5d
Merge remote-tracking branch 'remotes/origin/dconeybe/dataconnect/Grp…
dconeybe Oct 22, 2025
a88833b
Merge branch 'main' into dconeybe/dataconnect/GrpcMetadataUnitTestNul…
dconeybe Oct 22, 2025
b16d173
Merge branch 'dconeybe/dataconnect/GrpcMetadataUnitTestNullTokenFix' …
dconeybe Oct 22, 2025
8e282cc
Merge remote-tracking branch 'origin/main' into QueryHashIncorporates…
dconeybe Oct 24, 2025
afb2b76
DataConnectAuth.kt: add a link to the docs to justify using the "sub"…
dconeybe Oct 24, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion firebase-dataconnect/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
# Unreleased

- [changed] Internal refactor for managing Auth and App Check tokens
([#7184](https://github.com/firebase/firebase-android-sdk/pull/7184))
([#7484](https://github.com/firebase/firebase-android-sdk/pull/7484),
[#7485](https://github.com/firebase/firebase-android-sdk/pull/7485))

# 17.1.0

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,13 +49,22 @@ internal class DataConnectAuth(
provider.removeIdTokenListener(idTokenListener)

override suspend fun getToken(provider: InternalAuthProvider, forceRefresh: Boolean) =
provider.getAccessToken(forceRefresh).await().let { GetAuthTokenResult(it.token) }
provider.getAccessToken(forceRefresh).await().let {
GetAuthTokenResult(it.token, it.getAuthUid())
}

data class GetAuthTokenResult(override val token: String?) : GetTokenResult
data class GetAuthTokenResult(override val token: String?, val authUid: String?) : GetTokenResult

private class IdTokenListenerImpl(private val logger: Logger) : IdTokenListener {
override fun onIdTokenChanged(tokenResult: InternalTokenResult) {
logger.debug { "onIdTokenChanged(token=${tokenResult.token?.toScrubbedAccessToken()})" }
}
}

private companion object {

// The "sub" claim is documented to be "a non-empty string and must be the uid of the user or
// device". See http://goo.gle/4oGjEQt for the relevant Firebase documentation.
fun com.google.firebase.auth.GetTokenResult.getAuthUid(): String? = claims["sub"] as? String
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,9 @@ import io.kotest.matchers.shouldBe
import io.kotest.matchers.types.shouldBeSameInstanceAs
import io.kotest.property.Arb
import io.kotest.property.RandomSource
import io.kotest.property.arbitrary.map
import io.kotest.property.arbitrary.next
import io.kotest.property.arbs.products.brand
import io.mockk.coEvery
import io.mockk.confirmVerified
import io.mockk.every
Expand Down Expand Up @@ -311,6 +313,46 @@ class DataConnectAuthUnitTest {
mockLogger.shouldNotHaveLoggedAnyMessagesContaining(accessToken)
}

@Test
fun `getToken() should populate authUid from sub claim`() = runTest {
val dataConnectAuth = newDataConnectAuth()
dataConnectAuth.initialize()
advanceUntilIdle()
val uid = Arb.brand().map { it.value }.next(rs)
coEvery { mockInternalAuthProvider.getAccessToken(any()) } returns
taskForToken(accessToken, mapOf("sub" to uid))

val result = dataConnectAuth.getToken(requestId)

result.shouldNotBeNull().authUid shouldBe uid
}

@Test
fun `getToken() should populate null authUid if sub claim is missing`() = runTest {
val dataConnectAuth = newDataConnectAuth()
dataConnectAuth.initialize()
advanceUntilIdle()
coEvery { mockInternalAuthProvider.getAccessToken(any()) } returns
taskForToken(accessToken, emptyMap())

val result = dataConnectAuth.getToken(requestId)

result.shouldNotBeNull().authUid.shouldBeNull()
}

@Test
fun `getToken() should populate null authUid if sub claim is not a String`() = runTest {
val dataConnectAuth = newDataConnectAuth()
dataConnectAuth.initialize()
advanceUntilIdle()
coEvery { mockInternalAuthProvider.getAccessToken(any()) } returns
taskForToken(accessToken, mapOf("sub" to 42))

val result = dataConnectAuth.getToken(requestId)

result.shouldNotBeNull().authUid.shouldBeNull()
}

@Test
fun `getToken() should return re-throw the exception from the task returned from FirebaseAuth`() =
runTest {
Expand Down Expand Up @@ -613,7 +655,7 @@ class DataConnectAuthUnitTest {
interval = 100.milliseconds
}

fun taskForToken(token: String?): Task<GetTokenResult> =
Tasks.forResult(mockk(relaxed = true) { every { getToken() } returns token })
fun taskForToken(token: String?, claims: Map<String, Any> = emptyMap()): Task<GetTokenResult> =
Tasks.forResult(GetTokenResult(token, claims))
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -334,7 +334,9 @@ internal inline fun <Data, reified Variables> DataConnectArb.operationRefConstru

internal fun DataConnectArb.authTokenResult(
accessToken: Arb<String?> = accessToken().orNull(nullProbability = 0.33),
): Arb<GetAuthTokenResult> = accessToken.map { GetAuthTokenResult(it) }
authUid: Arb<String?> =
Arb.string(0..10, Codepoint.alphanumeric()).orNull(nullProbability = 0.33),
): Arb<GetAuthTokenResult> = Arb.bind(accessToken, authUid, ::GetAuthTokenResult)

internal fun DataConnectArb.appCheckTokenResult(
accessToken: Arb<String?> = accessToken().orNull(nullProbability = 0.33),
Expand Down