Access Firebase Auth / Identity Platform server side? Is it OIDC/OAuth2.0 compliant?

255 views
Skip to first unread message

Iain Adams

unread,
May 3, 2020, 5:40:27 PM5/3/20
to Firebase Google Group
Hi,

Sorry - starting a separate thread so as not to derail Uktarsh's original question in https://groups.google.com/forum/#!topic/firebase-talk/4na1D11X42o. However, this is along the same lines.

I have a similar requirement (although not using Google). My first thought was to send the received IDP access and refresh token server side, but this doesn't feel very secure. I'd much prefer to initiate the authentication sequence server side (like standard OAuth - authorization code flow). This doesn't seem to be documented anywhere (calling Firebase Auth/Identity Platform server side) - which raises another question - is Firebase Auth an OIDC provider under the hood? Is there anyway to use standard OAuth/OIDC flows to retrieve tokens?

Thanks
Iain

Kato Richardson

unread,
May 4, 2020, 11:22:07 AM5/4/20
to Firebase Google Group
Firebase Auth and Google Cloud Identity Platform are not the same thing, despite some confusion in the way GCIP uses the Firebase Auth SDKs for its implementation. 

Firebase Auth is not an OIDC provider. You don't need to refresh the tokens; the SDK manages this. Firebase Auth is also not a server auth protocol.

GCIP docs are here. I don't know much about this protocol yet although it has OIDC functionality as far as I understand it.

☼, Kato

--
You received this message because you are subscribed to the Google Groups "Firebase Google Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to firebase-tal...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/firebase-talk/68feea49-34ae-49d7-abab-117b34ede79a%40googlegroups.com.


--

Kato Richardson | Developer Programs Eng | kato...@google.com | 775-235-8398

Reply all
Reply to author
Forward
0 new messages