import HMAC1 users with different hash algorithm keys one after another not setting correct passwords
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 38/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- firebase, javascript, nodejs
- Ambito
- authentication, backend
Direzione di ricerca
Inizia dal punto di ingresso admin.auth().importUsers e segui come vengono gestiti l’opzione hash e il valore HMAC_SHA1 specifico per utente durante le importazioni sequenziali. Riproduci lo script fornito, quindi verifica che tutti gli utenti importati con chiavi diverse eseguano l’autenticazione con le password fornite e che i risultati dell’importazione rimangano corretti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
[READ] Step 1: Are you in the right place?
- For issues related to the code in this repository file a Github issue.
- If the issue pertains to Cloud Firestore, read the instructions in the "Firestore issue"
template. - For general technical questions, post a question on StackOverflow
with the firebase tag. - For general Firebase discussion, use the firebase-talk
google group. - For help troubleshooting your application that does not fall under one
of the above categories, reach out to the personalized
Firebase support channel.
[REQUIRED] Step 2: Describe your environment
- Operating System version: windows 10
- Firebase SDK version: 12.1.1
- Firebase Product: admin
- Node.js version: 20.11.0
- NPM version: 10.2.4
[REQUIRED] Step 3: Describe the problem
When using the importUsers function, it is not correctly importing users where each one has a different hash key.
I am importing users where each user's password was created using HMAC sha1 but each user had its own key. I was trying to import 1 user per function call but when I import say 100 users one at a time, the majority of them import incorrectly(code below should make this easy to understand) . If I rerun a subset of around 10 users using the exact same information passed in they then will login correctly.
Is there some internal limitation or batching happening? I am importing users one at a time and respecting the API quotas and they are successful imports. This has been very confusing to understand the correct way to handle this scenario is and it feels difficult to understand a pattern.
Given they all import with no issues but only some actually log in correctly and when I rerun then more will work, tells me I am not passing in bad data but something about how they process is different each time.
Steps to reproduce:
What happened? How can we make the problem occur?
This could be a description, log/console output, etc.
Relevant Code:
The code below will generate 100 users and import them one at a time and then when I attempt to log in, only the last 10 ish will even work, all others get incorrect password errors.
const crypto = require('crypto');
const admin = require('firebase-admin');
var serviceAccount = require(".\\key.json");
admin.initializeApp({
credential: admin.credential.cert(serviceAccount),
});
const randomString = (length) => {
return Math.random().toString(36).slice(2, length + 2)
}
const users = [];
for(let i = 0; i <= 100; i++) {
const text = 'password'
const key = randomString(12);
const passwordHash = crypto.createHmac('sha1', key)
.update(text)
.digest('hex')
users.push({
plainPassword: text,
passwordHash,
key,
email_address: `${i}@gmail.com`,
id: i.toString()
})
}
async function start() {
for (const user of users) {
const result = await admin.auth().importUsers([
{
uid: user.id,
email: user.email_address,
passwordHash: Buffer.from(user.passwordHash, 'hex'),
emailVerified: true
}
], {
hash: {
algorithm: "HMAC_SHA1",
key: Buffer.from(user.key)
}
})
console.log(result.errors[0]);
}
}
start();
- Lingua principale
- TypeScript
- Stelle
- 1.7k
- Fork
- 419
- Merge medio
- 4g 20h
- PR unite (30g)
- 16
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di firebase/firebase-admin-node
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
firebase/firebase-admin-node#3234 ·
-
firebase/firebase-admin-node#3221 · 3 commenti · 1 assegnatario ·
-
api: messaging
Difficoltà 3/5 1-2 giorni Idoneità per principianti 70/100
firebase/firebase-admin-node#3215 ·
-
api: messaging
Difficoltà 5/5 Più di una settimana Idoneità per principianti 28/100
firebase/firebase-admin-node#3214 ·
-
api: firestore type: feature request
firebase/firebase-admin-node#3183 · 1 commento · 1 assegnatario ·
Tutte le issue di firebase/firebase-admin-node
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
bcgov/bc-wallet-mobile#4761 · 1 commento ·
-
external-issue to-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
area-deployment area-integrations triage:bot-seen
Difficoltà 2/5 Mezza giornata Idoneità per principianti 86/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
refactor
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100