Skip to content

Password policy violation is reported as auth/internal-error instead of a specific error code #3265

Description

@ripperdoc

[REQUIRED] Step 2: Describe your environment

  • Operating System version: macOS 15.7.7 (local), Cloud Functions Node.js 20 runtime (production)
  • Firebase SDK version: firebase-admin 13.8.0 (also reproduced on 14.5.0)
  • Firebase Product: auth
  • Node.js version: 20.19.2
  • NPM version: 10.8.2

[REQUIRED] Step 3: Describe the problem

Steps to reproduce:

With a password policy in Require (ENFORCE) mode, auth().createUser() or updateUser() with a non-compliant password rejects with auth/internal-error, not a specific error code.

The server returns PASSWORD_DOES_NOT_MEET_REQUIREMENTS, but that code is missing from AUTH_SERVER_TO_CLIENT_CODE in src/auth/error.ts. FirebaseAuthError.fromServerError therefore falls back to INTERNAL_ERROR. Callers can't tell this user-input error from a real internal error without parsing the message. The client SDK already uses auth/password-does-not-meet-requirements for the same case.

  1. Enable a password policy in Require mode, e.g. minimum length 10.
  2. Call createUser with a password that doesn't meet it.

Actual: code is auth/internal-error, and the server code only appears in the message:

Missing password requirements: [Password must contain at least 10 characters, Password must contain a lower case character, Password must contain an upper case character] Raw server response: "{"error":{"code":400,"message":"PASSWORD_DOES_NOT_MEET_REQUIREMENTS : Missing password requirements: [...]","errors":[...]}}"

Expected: a specific code, e.g. auth/password-does-not-meet-requirements to match the client SDK, keeping the missing-requirements message.

Suggested fix: add PASSWORD_DOES_NOT_MEET_REQUIREMENTS to AUTH_SERVER_TO_CLIENT_CODE, with a matching AuthErrorCode entry, in src/auth/error.ts.

Relevant Code:

const { getAuth, FirebaseAuthError } = require("firebase-admin/auth");

// Against a project with a password policy in Require mode:
try {
  await getAuth().createUser({ email: "user@example.com", password: "weakpass" });
} catch (err) {
  console.log(err.code); // "auth/internal-error"
}

// Same mapping, without a project:
const err = FirebaseAuthError.fromServerError(
  "PASSWORD_DOES_NOT_MEET_REQUIREMENTS : Missing password requirements: [Password must contain at least 10 characters]"
);
console.log(err.code); // "auth/internal-error", expected "auth/password-does-not-meet-requirements"

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions