node.js - googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken 返回 CREDENTIAL_MISMATCH
问题描述
最终目标:使用本地 NodeJs 创建一个 Firebase 自定义令牌,将此类自定义令牌发布到 googleapis/.../verifyCustomToken 并取回一个 idToken,它允许我将新文档发布到 Firestore,如其他问题中所述
当前成就:我可以使用此 Cloud Function 成功创建 Custon 令牌并成功执行后续步骤(从 googleapis/.../verifyCustomToken 获取 idToken 并成功将文档发布到 Firestore)。但是我需要本地服务器上的相同(我们这次不打算使用 Cloud Function)。
当前问题:当我尝试将本地 NodeJs 生成的自定义令牌发布到 googleapis/.../verifyCustomToken 时遇到此问题:
{
"error": {
"code": 400,
"message": "CREDENTIAL_MISMATCH",
"errors": [
{
"message": "CREDENTIAL_MISMATCH",
"domain": "global",
"reason": "invalid"
}
]
}
}
这是整个 NodeJs 服务器:
const admin = require('firebase-admin');
exports.serviceAccount = {
"type": "service_account",
"project_id": "angular-firebase-auth0-3c084",
"private_key_id": "6ba2ba41e0bf3837841aa9772c7d880b7ce3be81",
"private_key": "-----BEGIN PRIVATE KEY-----\nMI... 9fYKA=\n-----END PRIVATE KEY-----\n".replace(/\\n/g, '\n'),
"client_email": "firebase-adminsdk-lu97a@angular-firebase-auth0-3c084.iam.gserviceaccount.com",
"client_id": "114324662014690107039",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://oauth2.googleapis.com/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/firebase-adminsdk-lu97a%40angular-firebase-auth0-3c084.iam.gserviceaccount.com"
}
admin.initializeApp({
credential: admin.credential.cert(exports.serviceAccount)
});
var uid = "NSBFu2YJNDgLQJCZ99dRJlP4DRo2"; //copied from https://console.firebase.google.com/project/firetestjimis/authentication/users
var claim = {
control: true
};
admin.auth().createCustomToken(uid)
.then(function (customToken) {
console.log(customToken)
})
.catch(function (error) {
console.log("Error creating custom token:", error);
});
我复制打印的令牌并尝试:
curl --location --request POST 'https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=AIzaSyDAd03oo5fPgV2l--oMWZ2Y23DCGihK3xs' \
--header 'Content-Type: application/json' \
--data-raw '{"token":"eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJodHRwczovL2lkZW50aXR5dG9vbGtpdC5nb29nbGVhcGlzLmNvbS9nb29nbGUuaWRlbnRpdHkuaWRlbnRpdHl0b29sa2l0LnYxLklkZW50aXR5VG9vbGtpdCIsImlhdCI6MTU4NzQ4NjI0NiwiZXhwIjoxNTg3NDg5ODQ2LCJpc3MiOiJmaXJlYmFzZS1hZG1pbnNkay1sdTk3YUBhbmd1bGFyLWZpcmViYXNlLWF1dGgwLTNjMDg0LmlhbS5nc2VydmljZWFjY291bnQuY29tIiwic3ViIjoiZmlyZWJhc2UtYWRtaW5zZGstbHU5N2FAYW5ndWxhci1maXJlYmFzZS1hdXRoMC0zYzA4NC5pYW0uZ3NlcnZpY2VhY2NvdW50LmNvbSIsInVpZCI6Ik5TQkZ1MllKTkRnTFFKQ1o5OWRSSmxQNERSbzIifQ.fSe8ONIHBgoeVg4OkTSemykq4RoFb5TOiHOq52zKiiXCfywmdGAtqZyAWfM_dz-knP4mbSyJM9N3T2A_GQ0fV6AGTlq3lalDaptQPfYX4B7MOiA6YODJSDXGyGVHbdF88MmtNzESszbivF7RoFTBanyawVa9dwy83-84_2nJHylqmq055oFurd-WkM-gnfjyRBvGzQmZp7l76dV1rzRiKg8_ctiO8SOwD84KriXQj6DL-LFze7wb6XJSCJ52epXH0FvjALsB4R1eqCDHAJ3COfEYWiE0Vn5LWhj6yFvtSG3vqLqXy79EDkoXVPw0IJNiBSE4e3gfmat12M9peJEoTw","returnSecureToken":true}'
然后导致 CREDENTIAL_MISMATCH。
如果相关,如果我从此 Cloud Funtion 生成自定义令牌,我可以成功发布以验证自定义令牌
import * as functions from 'firebase-functions';
import * as admin from "firebase-admin";
export const getCustomToken = functions.https.onRequest((request, response) => {
if (admin.apps.length < 1) { //Checks if app already initialized
admin.initializeApp();
}
const uid = "NSBFu2YJNDgLQJCZ99dRJlP4DRo2";
admin.auth().createCustomToken(uid)
.then(function (customToken) {
console.log(customToken.toString);
response.send(customToken);
})
.catch(function (error) {
console.log("Error creating custom token:", error);
});
});
解决方案
确保在 URL 中发送的 API 密钥与用于创建自定义令牌的服务帐户来自同一个项目。
推荐阅读
- html - 使 img 仅出现在 Jumbotron div 中
- java - CollapsingToolbar - 与正确锚定重叠
- django - Django 如何在 django 中使用 webhook 并将数据发送到 zapier?
- javascript - 如何替换html文件中的正文
- apache-spark - spark - 应用程序根据不同的执行程序内存返回不同的结果?
- asp.net - 如何通过 HttpWebRequest - POST 使用 VB.net 传递 JSON 数据?
- c# - 从字符串日期 C# 获取 PM 或 AM
- typo3 - 带有引导警报的 TYPO3 felogin
- php - 按顺序执行命令的脚本php
- r - 从年初的年周数获取一周的第一天的日期