Misleading error message for THIRD_PARTY_AUTH_ERROR: raw "OAuth 2 access token" text surfaced instead of the APNs-specific message
I maintainer di solito rispondono entro 7 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 70/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- typescript
Direzione di ricerca
Inizia in src/messaging/error.ts leggendo la mappatura di THIRD_PARTY_AUTH_ERROR e la successiva assegnazione di error.message. Verifica come viene selezionato il messaggio canonico di APNs quando è presente la risposta UNAUTHENTICATED grezza, quindi aggiorna il comportamento e la formulazione in modo da coprire le chiavi di autenticazione APNs e le credenziali VAPID di Web Push. Il lavoro è completato quando third-party-auth-error non presenta più come messaggio principale le indicazioni OAuth grezze e fuorvianti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
When FCM rejects an iOS send with UNAUTHENTICATED, the SDK surfaces the raw
gateway message ("...Expected OAuth 2 access token...") instead of its own
APNs-specific message, even though the error is classified as
messaging/third-party-auth-error. This sends developers down the wrong path
(debugging their own service-account / OAuth setup) when the real cause is a
downstream APNs credential problem.
What happened
Sending to iOS device tokens, some tokens fail with:
HTTP 401
{
"error": {
"code": 401,
"status": "UNAUTHENTICATED",
"message": "Request is missing required authentication credential. Expected OAuth 2 access token, login cookie or other valid authentication credential. ...",
"details": [{ "@type": "...FcmError", "errorCode": "THIRD_PARTY_AUTH_ERROR" }]
}
}
error.code is correctly messaging/third-party-auth-error, but error.message
is the raw "Expected OAuth 2 access token" text. That message strongly implies
a problem with the caller's own authentication (service account / access token),
so it's natural to spend several debugging cycles verifying OAuth, the service
account, token refresh, etc. — all of which are fine. The actual cause is on the
APNs side (e.g. an APNs auth key/certificate that doesn't cover the environment a
given token was minted in). The misleading message cost us multiple debugging
rounds before we inspected details[].errorCode.
Root cause in the SDK
In src/messaging/error.ts on current main:
-
UNAUTHENTICATEDis mapped toTHIRD_PARTY_AUTH_ERROR(line ~201), and there is
a clear canonical message for it (lines ~133–137):"A message targeted to an iOS device could not be sent because the required
APNs SSL certificate was not uploaded or has expired. Check the validity of
your development and production certificates." -
But the error message is assigned as (line ~260):
error.message = message || error.message;Since the raw server
messageis truthy, it always wins, so the SDK's own
clearer, APNs-specific message is never shown for this code — the misleading
"OAuth 2 access token" text is surfaced instead.
A second, smaller issue: the canonical message is dated
Even when shown, the canonical message only mentions an "APNs SSL certificate"
and "development and production certificates" — i.e. the .p12 model. Modern
setups use .p8 APNs auth keys (token-based auth), and Web Push uses VAPID
keys. For those, "certificate ... has expired / check your certificates" is
itself misleading, because there is no certificate involved.
Suggested fix
- For
third-party-auth-error, prefer (or prepend) the SDK's canonical message
rather than the rawUNAUTHENTICATEDgateway text, since that raw text
systematically points debugging in the wrong direction. The raw text can be
kept as "Raw server response: ..." (the SDK already appends that in some
paths). - Update the canonical message to cover APNs auth keys (
.p8) and Web Push
(VAPID), not just SSL certificates.
Environment
- Verified against current
main,src/messaging/error.ts. - Reproduced on a real send to an affected iOS token (401 / UNAUTHENTICATED /
details[].errorCode = THIRD_PARTY_AUTH_ERROR).
Happy to open a PR along the lines of the suggested fix if this direction sounds right.
- Lingua principale
- TypeScript
- Stelle
- 1.8k
- Fork
- 420
- Merge medio
- 5g 6h
- PR unite (30g)
- 11
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di firebase/firebase-admin-node
-
Password policy violation is reported as `auth/internal-error` instead of a specific error codeAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
firebase/firebase-admin-node#3265 ·
I maintainer di solito rispondono entro 7 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
firebase/firebase-admin-node#3234 ·
I maintainer di solito rispondono entro 7 giorni
-
[email protected] stable dependency tree fails npm audit via Storage uuid and Firestore google-gaxForse già presa @lahirumaramba l’ha presa 24 giorni fa. Aperta
firebase/firebase-admin-node#3221 · 3 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 7 giorni
-
api: messaging
Difficoltà 5/5 Più di una settimana Idoneità per principianti 28/100
firebase/firebase-admin-node#3214 ·
I maintainer di solito rispondono entro 7 giorni
-
[Firestore] Re-export functions from '@google-cloud/firestore/pipelines'Forse di nuovo libera @jonathanedey l’ha presa 94 giorni fa e non c’è nessuna pull request aperta. Apertaapi: firestore type: feature request
firebase/firebase-admin-node#3183 · 1 commento · 1 assegnatario ·
I maintainer di solito rispondono entro 7 giorni
Tutte le issue di firebase/firebase-admin-node
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
external-issue to-triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
diegosouzapw/OmniRoute#15401 ·
I maintainer di solito rispondono entro 2 giorni
-
Sign the pledgeAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
input-output-hk/devx-updates#163 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
code-yeongyu/oh-my-openagent#9454 ·
I maintainer di solito rispondono entro 1 giorno