Skip to content

Commit 40e96d2

Browse files
committed
raise exceptions.UnknownError if body is not a dict
1 parent 4e2f108 commit 40e96d2

2 files changed

Lines changed: 23 additions & 4 deletions

File tree

‎firebase_admin/app_check.py‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
import jwt
2020
from jwt import PyJWKClient, ExpiredSignatureError, InvalidTokenError, DecodeError
2121
from jwt import InvalidAudienceError, InvalidIssuerError, InvalidSignatureError
22-
from firebase_admin import _http_client, _utils
22+
from firebase_admin import _http_client, _utils, exceptions
2323

2424
_APP_CHECK_ATTRIBUTE = '_app_check'
2525

@@ -108,9 +108,13 @@ def verify_token(self, token: str, consume: bool = False) -> Dict[str, Any]:
108108
except requests.exceptions.RequestException as error:
109109
raise _utils.handle_platform_error_from_requests(error)
110110

111-
already_consumed = False
112-
if isinstance(body, dict):
113-
already_consumed = body.get('alreadyConsumed', False)
111+
if not isinstance(body, dict):
112+
raise exceptions.UnknownError(
113+
'Unexpected response from App Check service. '
114+
f'Expected a JSON object, but got {type(body).__name__}.'
115+
)
116+
117+
already_consumed = body.get('alreadyConsumed', False)
114118
verified_claims['already_consumed'] = bool(already_consumed)
115119

116120
return verified_claims

‎tests/test_app_check.py‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -339,3 +339,18 @@ def test_verify_token_with_consume_true_backend_error(self, mocker):
339339

340340
with pytest.raises(exceptions.FirebaseError):
341341
app_check.verify_token("encoded", app=app, consume=True)
342+
343+
@pytest.mark.parametrize('malformed_body', ['string_response', [1, 2], 123, None])
344+
def test_verify_token_with_consume_true_malformed_response_raises_error(
345+
self, mocker, malformed_body
346+
):
347+
mocker.patch("jwt.decode", return_value=JWT_PAYLOAD_SAMPLE)
348+
mocker.patch("jwt.PyJWKClient.get_signing_key_from_jwt", return_value=PyJWK(signing_key))
349+
mocker.patch("jwt.get_unverified_header", return_value=JWT_PAYLOAD_SAMPLE.get("headers"))
350+
app = firebase_admin.get_app()
351+
app_check_service = app_check._get_app_check_service(app)
352+
mocker.patch.object(app_check_service._http_client, "body", return_value=malformed_body)
353+
354+
with pytest.raises(exceptions.UnknownError) as excinfo:
355+
app_check.verify_token("encoded", app=app, consume=True)
356+
assert 'Unexpected response from App Check service' in str(excinfo.value)

0 commit comments

Comments
 (0)