app/lib/server-token-validator.ts (12 lines of code) (raw):
/**
* Copyright 2023 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
import {app} from '@/app/lib/firebase-server-initialization';
import {Tokens} from '@/app/types';
import {getAuth} from 'firebase-admin/auth';
import {getAppCheck} from 'firebase-admin/app-check';
export async function validateTokens(tokens: Tokens) {
const {userToken, appCheckToken} = tokens;
const [authUser] = await Promise.all([
getAuth(app).verifyIdToken(userToken),
getAppCheck(app).verifyToken(appCheckToken),
]);
return authUser;
};