-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathfirebase_auth.js
More file actions
53 lines (44 loc) · 1.77 KB
/
firebase_auth.js
File metadata and controls
53 lines (44 loc) · 1.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
/* global Twilio, Runtime */
'use strict';
const firebaseAdmin = require('firebase-admin');
const fs = require('fs');
function handleError(response, statusCode, message) {
console.error(`Error: ${message}`);
response.setStatusCode(statusCode);
response.setBody({ error: { message } });
return response;
}
module.exports = async (context, event, callback) => {
const response = new Twilio.Response();
response.appendHeader('Content-Type', 'application/json');
const { path: serviceAccountFilePath } = Runtime.getAssets()['/firebase_service_account.json'];
let serviceAccountJson;
try {
// require doesn't work here so we need to use fs instead
const rawJson = fs.readFileSync(serviceAccountFilePath, 'utf8');
serviceAccountJson = JSON.parse(rawJson);
} catch (err) {
return callback(null, handleError(response, 500, 'Could not load service account JSON'));
}
// initialize firebase if not already done
if (!firebaseAdmin.apps.length) {
firebaseAdmin.initializeApp({
credential: firebaseAdmin.credential.cert(serviceAccountJson),
});
}
const authHeader = event.request?.headers?.authorization || '';
const idToken = authHeader.startsWith('Bearer ') ? authHeader.replace('Bearer ', '') : null;
if (!idToken) {
return callback(null, handleError(response, 401, 'Firebase ID token missing'));
}
try {
const decodedToken = await firebaseAdmin.auth().verifyIdToken(idToken);
const userEmail = decodedToken.email;
// only tmu accounts are allowed
if (!userEmail || !userEmail.endsWith('@torontomu.ca')) {
return callback(null, handleError(response, 403, 'Forbidden - only torontomu.ca is allowed'));
}
} catch (err) {
return callback(null, handleError(response, 401, 'Unauthorized - invalid token'));
}
};