Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Password policy violation is reported as `auth/internal-error` instead of a specific error code

Aperta Adatta ai principianti
#3,265 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 7 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
85/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
firebase, node.js, typescript

Direzione di ricerca

Inizia in src/auth/error.ts leggendo AUTH_SERVER_TO_CLIENT_CODE, la voce AuthErrorCode e FirebaseAuthError.fromServerError. Verifica il mapping con la stringa PASSWORD_DOES_NOT_MEET_REQUIREMENTS fornita. Il lavoro è completato quando createUser, updateUser e il mapping diretto restituiscono auth/password-does-not-meet-requirements mantenendo il messaggio sui requisiti mancanti.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

[REQUIRED] Step 2: Describe your environment
  • Operating System version: macOS 15.7.7 (local), Cloud Functions Node.js 20 runtime (production)
  • Firebase SDK version: firebase-admin 13.8.0 (also reproduced on 14.5.0)
  • Firebase Product: auth
  • Node.js version: 20.19.2
  • NPM version: 10.8.2
[REQUIRED] Step 3: Describe the problem
Steps to reproduce:

With a password policy in Require (ENFORCE) mode, auth().createUser() or updateUser() with a non-compliant password rejects with auth/internal-error, not a specific error code.

The server returns PASSWORD_DOES_NOT_MEET_REQUIREMENTS, but that code is missing from AUTH_SERVER_TO_CLIENT_CODE in src/auth/error.ts. FirebaseAuthError.fromServerError therefore falls back to INTERNAL_ERROR. Callers can't tell this user-input error from a real internal error without parsing the message. The client SDK already uses auth/password-does-not-meet-requirements for the same case.

  1. Enable a password policy in Require mode, e.g. minimum length 10.
  2. Call createUser with a password that doesn't meet it.

Actual: code is auth/internal-error, and the server code only appears in the message:

Missing password requirements: [Password must contain at least 10 characters, Password must contain a lower case character, Password must contain an upper case character] Raw server response: "{"error":{"code":400,"message":"PASSWORD_DOES_NOT_MEET_REQUIREMENTS : Missing password requirements: [...]","errors":[...]}}"

Expected: a specific code, e.g. auth/password-does-not-meet-requirements to match the client SDK, keeping the missing-requirements message.

Suggested fix: add PASSWORD_DOES_NOT_MEET_REQUIREMENTS to AUTH_SERVER_TO_CLIENT_CODE, with a matching AuthErrorCode entry, in src/auth/error.ts.

Relevant Code:
const { getAuth, FirebaseAuthError } = require("firebase-admin/auth");

// Against a project with a password policy in Require mode:
try {
  await getAuth().createUser({ email: "[email protected]", password: "weakpass" });
} catch (err) {
  console.log(err.code); // "auth/internal-error"
}

// Same mapping, without a project:
const err = FirebaseAuthError.fromServerError(
  "PASSWORD_DOES_NOT_MEET_REQUIREMENTS : Missing password requirements: [Password must contain at least 10 characters]"
);
console.log(err.code); // "auth/internal-error", expected "auth/password-does-not-meet-requirements"
Lingua principale
TypeScript
Stelle
1.8k
Fork
420
Merge medio
5g 6h
PR unite (30g)
11

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di firebase/firebase-admin-node

Tutte le issue di firebase/firebase-admin-node

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.