|
| 1 | +// Copyright 2022 Google LLC |
| 2 | +// |
| 3 | +// Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | +// you may not use this file except in compliance with the License. |
| 5 | +// You may obtain a copy of the License at |
| 6 | +// |
| 7 | +// http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | +// |
| 9 | +// Unless required by applicable law or agreed to in writing, software |
| 10 | +// distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | +// See the License for the specific language governing permissions and |
| 13 | +// limitations under the License. |
| 14 | + |
| 15 | +import Foundation |
| 16 | + |
| 17 | +import FirebaseAppCheckInterop |
| 18 | +import FirebaseAuthInterop |
| 19 | +import FirebaseCore |
| 20 | +@_implementationOnly import FirebaseCoreExtension |
| 21 | + |
| 22 | +#if COCOAPODS |
| 23 | + import GTMSessionFetcher |
| 24 | +#else |
| 25 | + import GTMSessionFetcherCore |
| 26 | +#endif |
| 27 | + |
| 28 | +internal class StorageTokenAuthorizer: NSObject, GTMSessionFetcherAuthorizer { |
| 29 | + func authorizeRequest(_ request: NSMutableURLRequest?, |
| 30 | + completionHandler handler: @escaping (Error?) -> Void) { |
| 31 | + // Set version header on each request |
| 32 | + let versionString = "ios/\(FirebaseVersion())" |
| 33 | + request?.setValue(versionString, forHTTPHeaderField: "x-firebase-storage-version") |
| 34 | + |
| 35 | + // Set GMP ID on each request |
| 36 | + request?.setValue(googleAppID, forHTTPHeaderField: "x-firebase-gmpid") |
| 37 | + |
| 38 | + var tokenError: NSError? |
| 39 | + let callbackQueue = fetcherService.callbackQueue ?? DispatchQueue.main |
| 40 | + let fetchTokenGroup = DispatchGroup() |
| 41 | + if let auth = auth { |
| 42 | + fetchTokenGroup.enter() |
| 43 | + auth.getToken(forcingRefresh: false) { token, error in |
| 44 | + if let error = error as? NSError { |
| 45 | + var errorDictionary = error.userInfo |
| 46 | + errorDictionary["ResponseErrorDomain"] = error.domain |
| 47 | + errorDictionary["ResponseErrorCode"] = error.code |
| 48 | + errorDictionary[NSLocalizedDescriptionKey] = |
| 49 | + "User is not authenticated, please authenticate" + |
| 50 | + " using Firebase Authentication and try again." |
| 51 | + tokenError = NSError(domain: "FIRStorageErrorDomain", |
| 52 | + code: StorageErrorCode.unauthenticated.rawValue, |
| 53 | + userInfo: errorDictionary) |
| 54 | + } else if let token = token { |
| 55 | + let firebaseToken = "Firebase \(token)" |
| 56 | + request?.setValue(firebaseToken, forHTTPHeaderField: "Authorization") |
| 57 | + } |
| 58 | + fetchTokenGroup.leave() |
| 59 | + } |
| 60 | + } |
| 61 | + if let appCheck = appCheck { |
| 62 | + fetchTokenGroup.enter() |
| 63 | + appCheck.getToken(forcingRefresh: false) { tokenResult in |
| 64 | + request?.setValue(tokenResult.token, forHTTPHeaderField: "X-Firebase-AppCheck") |
| 65 | + |
| 66 | + if let error = tokenResult.error { |
| 67 | + // TODO: Define better way to use FIRLogger from Swift. |
| 68 | + FIRLogDebugSwift( |
| 69 | + "[FirebaseStorage]", |
| 70 | + "I-STR000001", |
| 71 | + "Failed to fetch AppCheck token. Error: \(error)" |
| 72 | + ) |
| 73 | + } |
| 74 | + fetchTokenGroup.leave() |
| 75 | + } |
| 76 | + } |
| 77 | + fetchTokenGroup.notify(queue: callbackQueue) { |
| 78 | + handler(tokenError) |
| 79 | + } |
| 80 | + } |
| 81 | + |
| 82 | + func authorizeRequest(_ request: NSMutableURLRequest?, delegate: Any, didFinish sel: Selector) { |
| 83 | + fatalError("Internal error: Should not call old authorizeRequest") |
| 84 | + } |
| 85 | + |
| 86 | + // Note that stopAuthorization, isAuthorizingRequest, and userEmail |
| 87 | + // aren't relevant with the Firebase App/Auth implementation of tokens, |
| 88 | + // and thus aren't implemented. Token refresh is handled transparently |
| 89 | + // for us, and we don't allow the auth request to be stopped. |
| 90 | + // Auth is also not required so the world doesn't stop. |
| 91 | + func stopAuthorization() {} |
| 92 | + |
| 93 | + func stopAuthorization(for request: URLRequest) {} |
| 94 | + |
| 95 | + func isAuthorizingRequest(_ request: URLRequest) -> Bool { |
| 96 | + return false |
| 97 | + } |
| 98 | + |
| 99 | + func isAuthorizedRequest(_ request: URLRequest) -> Bool { |
| 100 | + guard let authHeader = request.allHTTPHeaderFields?["Authorization"] else { |
| 101 | + return false |
| 102 | + } |
| 103 | + return authHeader.hasPrefix("Firebase") |
| 104 | + } |
| 105 | + |
| 106 | + var userEmail: String? |
| 107 | + |
| 108 | + internal let fetcherService: GTMSessionFetcherService |
| 109 | + private let googleAppID: String |
| 110 | + private let auth: AuthInterop? |
| 111 | + private let appCheck: AppCheckInterop? |
| 112 | + |
| 113 | + private let serialAuthArgsQueue = DispatchQueue(label: "com.google.firebasestorage.authorizer") |
| 114 | + |
| 115 | + init(googleAppID: String, |
| 116 | + fetcherService: GTMSessionFetcherService, |
| 117 | + authProvider: AuthInterop?, |
| 118 | + appCheck: AppCheckInterop?) { |
| 119 | + self.googleAppID = googleAppID |
| 120 | + self.fetcherService = fetcherService |
| 121 | + auth = authProvider |
| 122 | + self.appCheck = appCheck |
| 123 | + } |
| 124 | +} |
0 commit comments