-
Notifications
You must be signed in to change notification settings - Fork 14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Feature]: Verify id tokens #9
Comments
Hello @Lxstr , thank you for submitting an issue! A project committer will shortly review the issue. |
Hey @Lxstr. I actually need your opinion on how this should be done. As mentioned here Verify ID tokens using a third-party JWT library, should I procced with all the checks to verify it? Or do it simply by retrieving the public key for the |
I wasn't sure if we had to actually verify it, I thought could just call the api and use the response, but I really have not much of an idea of what is correct here. I am only coming from perspective of a serverside app. I managed to wrangle something from AI after some back an forth, could this be an option?
|
I haven't tested it yet, but by the looks of it, it seems like the v1 endpoint for Get Account Info which is used in |
Awesome, thanks for your hard work! Hopefully, this will be handy additional feature for people using the token passing feature. Although, in hindsight I'm not sure if using this as an extra layer in my case (server side) is truly needed so I'll maybe write about it and see if there's some feedback. |
Is your proposal related to a problem?
Describe the solution you'd like.
Describe alternatives you've considered.
https://firebase.google.com/docs/auth/admin/verify-id-tokens#web
Additional context.
Trying to get the expiry timestamp in order to check if i need to refresh the users idToken. Then I would set up requirement to pass idToken as extra security layer
The text was updated successfully, but these errors were encountered: