AuthErrorUtils.swift 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614
  1. // Copyright 2023 Google LLC
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. import Foundation
  15. // MARK: - URL response error codes
  16. /// Error code that indicates that the client ID provided was invalid.
  17. private let kURLResponseErrorCodeInvalidClientID = "auth/invalid-oauth-client-id"
  18. /// Error code that indicates that a network request within the SFSafariViewController or WKWebView
  19. /// failed.
  20. private let kURLResponseErrorCodeNetworkRequestFailed = "auth/network-request-failed"
  21. /// Error code that indicates that an internal error occurred within the
  22. /// SFSafariViewController or WKWebView failed.
  23. private let kURLResponseErrorCodeInternalError = "auth/internal-error"
  24. private let kFIRAuthErrorMessageMalformedJWT =
  25. "Failed to parse JWT. Check the userInfo dictionary for the full token."
  26. @available(iOS 13, tvOS 13, macOS 10.15, macCatalyst 13, watchOS 7, *)
  27. class AuthErrorUtils {
  28. static let internalErrorDomain = "FIRAuthInternalErrorDomain"
  29. static let userInfoDeserializedResponseKey = "FIRAuthErrorUserInfoDeserializedResponseKey"
  30. static let userInfoDataKey = "FIRAuthErrorUserInfoDataKey"
  31. /// This marker indicates that the server error message contains a detail error message which
  32. /// should be used instead of the hardcoded client error message.
  33. private static let kServerErrorDetailMarker = " : "
  34. static func error(code: SharedErrorCode, userInfo: [String: Any]? = nil) -> Error {
  35. switch code {
  36. case let .public(publicCode):
  37. var errorUserInfo: [String: Any] = userInfo ?? [:]
  38. if errorUserInfo[NSLocalizedDescriptionKey] == nil {
  39. errorUserInfo[NSLocalizedDescriptionKey] = publicCode.errorDescription
  40. }
  41. if let localizedDescription = errorUserInfo[NSLocalizedDescriptionKey] as? String,
  42. localizedDescription == "" {
  43. errorUserInfo[NSLocalizedDescriptionKey] = publicCode.errorDescription
  44. }
  45. errorUserInfo[AuthErrors.userInfoNameKey] = publicCode.errorCodeString
  46. return NSError(
  47. domain: AuthErrors.domain,
  48. code: publicCode.rawValue,
  49. userInfo: errorUserInfo
  50. )
  51. case let .internal(internalCode):
  52. // This is an internal error. Wrap it in an internal error.
  53. let error = NSError(
  54. domain: internalErrorDomain,
  55. code: internalCode.rawValue,
  56. userInfo: userInfo
  57. )
  58. return self.error(code: .public(.internalError), underlyingError: error)
  59. }
  60. }
  61. static func error(code: SharedErrorCode, underlyingError: Error?) -> Error {
  62. var errorUserInfo: [String: Any]?
  63. if let underlyingError = underlyingError {
  64. errorUserInfo = [NSUnderlyingErrorKey: underlyingError]
  65. }
  66. return error(code: code, userInfo: errorUserInfo)
  67. }
  68. static func error(code: AuthErrorCode, underlyingError: Error?) -> Error {
  69. error(code: SharedErrorCode.public(code), underlyingError: underlyingError)
  70. }
  71. static func error(code: AuthErrorCode, userInfo: [String: Any]? = nil) -> Error {
  72. error(code: SharedErrorCode.public(code), userInfo: userInfo)
  73. }
  74. static func error(code: AuthErrorCode, message: String?) -> Error {
  75. let userInfo: [String: Any]?
  76. if let message {
  77. userInfo = [NSLocalizedDescriptionKey: message]
  78. } else {
  79. userInfo = nil
  80. }
  81. return error(code: SharedErrorCode.public(code), userInfo: userInfo)
  82. }
  83. static func userDisabledError(message: String?) -> Error {
  84. error(code: .userDisabled, message: message)
  85. }
  86. static func wrongPasswordError(message: String?) -> Error {
  87. error(code: .wrongPassword, message: message)
  88. }
  89. static func tooManyRequestsError(message: String?) -> Error {
  90. error(code: .tooManyRequests, message: message)
  91. }
  92. static func invalidCustomTokenError(message: String?) -> Error {
  93. error(code: .invalidCustomToken, message: message)
  94. }
  95. static func customTokenMismatchError(message: String?) -> Error {
  96. error(code: .customTokenMismatch, message: message)
  97. }
  98. static func invalidCredentialError(message: String?) -> Error {
  99. error(code: .invalidCredential, message: message)
  100. }
  101. static func requiresRecentLoginError(message: String?) -> Error {
  102. error(code: .requiresRecentLogin, message: message)
  103. }
  104. static func invalidUserTokenError(message: String?) -> Error {
  105. error(code: .invalidUserToken, message: message)
  106. }
  107. static func invalidEmailError(message: String?) -> Error {
  108. error(code: .invalidEmail, message: message)
  109. }
  110. static func providerAlreadyLinkedError() -> Error {
  111. error(code: .providerAlreadyLinked)
  112. }
  113. static func noSuchProviderError() -> Error {
  114. error(code: .noSuchProvider)
  115. }
  116. static func userTokenExpiredError(message: String?) -> Error {
  117. error(code: .userTokenExpired, message: message)
  118. }
  119. static func userNotFoundError(message: String?) -> Error {
  120. error(code: .userNotFound, message: message)
  121. }
  122. static func invalidAPIKeyError() -> Error {
  123. error(code: .invalidAPIKey)
  124. }
  125. static func userMismatchError() -> Error {
  126. error(code: .userMismatch)
  127. }
  128. static func operationNotAllowedError(message: String?) -> Error {
  129. error(code: .operationNotAllowed, message: message)
  130. }
  131. static func weakPasswordError(serverResponseReason reason: String?) -> Error {
  132. let userInfo: [String: Any]?
  133. if let reason, !reason.isEmpty {
  134. userInfo = [
  135. NSLocalizedFailureReasonErrorKey: reason,
  136. ]
  137. } else {
  138. userInfo = nil
  139. }
  140. return error(code: .weakPassword, userInfo: userInfo)
  141. }
  142. static func appNotAuthorizedError() -> Error {
  143. error(code: .appNotAuthorized)
  144. }
  145. static func expiredActionCodeError(message: String?) -> Error {
  146. error(code: .expiredActionCode, message: message)
  147. }
  148. static func invalidActionCodeError(message: String?) -> Error {
  149. error(code: .invalidActionCode, message: message)
  150. }
  151. static func invalidMessagePayloadError(message: String?) -> Error {
  152. error(code: .invalidMessagePayload, message: message)
  153. }
  154. static func invalidSenderError(message: String?) -> Error {
  155. error(code: .invalidSender, message: message)
  156. }
  157. static func invalidRecipientEmailError(message: String?) -> Error {
  158. error(code: .invalidRecipientEmail, message: message)
  159. }
  160. static func missingIosBundleIDError(message: String?) -> Error {
  161. error(code: .missingIosBundleID, message: message)
  162. }
  163. static func missingAndroidPackageNameError(message: String?) -> Error {
  164. error(code: .missingAndroidPackageName, message: message)
  165. }
  166. static func invalidRecaptchaTokenError() -> Error {
  167. error(code: .invalidRecaptchaToken)
  168. }
  169. static func invalidAuthenticatorResponse() -> Error {
  170. error(code: .invalidAuthenticatorResponse)
  171. }
  172. static func unauthorizedDomainError(message: String?) -> Error {
  173. error(code: .unauthorizedDomain, message: message)
  174. }
  175. static func invalidContinueURIError(message: String?) -> Error {
  176. error(code: .invalidContinueURI, message: message)
  177. }
  178. static func missingContinueURIError(message: String?) -> Error {
  179. error(code: .missingContinueURI, message: message)
  180. }
  181. static func missingEmailError(message: String?) -> Error {
  182. error(code: .missingEmail, message: message)
  183. }
  184. static func missingPhoneNumberError(message: String?) -> Error {
  185. error(code: .missingPhoneNumber, message: message)
  186. }
  187. static func invalidPhoneNumberError(message: String?) -> Error {
  188. error(code: .invalidPhoneNumber, message: message)
  189. }
  190. static func missingVerificationCodeError(message: String?) -> Error {
  191. error(code: .missingVerificationCode, message: message)
  192. }
  193. static func missingPasskeyEnrollment() -> Error {
  194. error(code: .missingPasskeyEnrollment)
  195. }
  196. static func invalidVerificationCodeError(message: String?) -> Error {
  197. error(code: .invalidVerificationCode, message: message)
  198. }
  199. static func missingVerificationIDError(message: String?) -> Error {
  200. error(code: .missingVerificationID, message: message)
  201. }
  202. static func invalidVerificationIDError(message: String?) -> Error {
  203. error(code: .invalidVerificationID, message: message)
  204. }
  205. static func sessionExpiredError(message: String?) -> Error {
  206. error(code: .sessionExpired, message: message)
  207. }
  208. static func missingAppCredential(message: String?) -> Error {
  209. error(code: .missingAppCredential, message: message)
  210. }
  211. static func invalidAppCredential(message: String?) -> Error {
  212. error(code: .invalidAppCredential, message: message)
  213. }
  214. static func quotaExceededError(message: String?) -> Error {
  215. error(code: .quotaExceeded, message: message)
  216. }
  217. static func missingAppTokenError(underlyingError: Error?) -> Error {
  218. error(code: .missingAppToken, underlyingError: underlyingError)
  219. }
  220. static func localPlayerNotAuthenticatedError() -> Error {
  221. error(code: .localPlayerNotAuthenticated)
  222. }
  223. static func gameKitNotLinkedError() -> Error {
  224. error(code: .gameKitNotLinked)
  225. }
  226. static func RPCRequestEncodingError(underlyingError: Error) -> Error {
  227. error(code: .internal(.RPCRequestEncodingError), underlyingError: underlyingError)
  228. }
  229. static func JSONSerializationErrorForUnencodableType() -> Error {
  230. error(code: .internal(.JSONSerializationError))
  231. }
  232. static func JSONSerializationError(underlyingError: Error) -> Error {
  233. error(code: .internal(.JSONSerializationError), underlyingError: underlyingError)
  234. }
  235. static func networkError(underlyingError: Error) -> Error {
  236. error(code: .networkError, underlyingError: underlyingError)
  237. }
  238. static func emailAlreadyInUseError(email: String?) -> Error {
  239. var userInfo: [String: Any]?
  240. if let email, !email.isEmpty {
  241. userInfo = [AuthErrors.userInfoEmailKey: email]
  242. }
  243. return error(code: .emailAlreadyInUse, userInfo: userInfo)
  244. }
  245. static func credentialAlreadyInUseError(message: String?,
  246. credential: AuthCredential?,
  247. email: String?) -> Error {
  248. var userInfo: [String: Any] = [:]
  249. if let credential {
  250. userInfo[AuthErrors.userInfoUpdatedCredentialKey] = credential
  251. }
  252. if let email, !email.isEmpty {
  253. userInfo[AuthErrors.userInfoEmailKey] = email
  254. }
  255. if !userInfo.isEmpty {
  256. return error(code: .credentialAlreadyInUse, userInfo: userInfo)
  257. }
  258. return error(code: .credentialAlreadyInUse, message: message)
  259. }
  260. static func webContextAlreadyPresentedError(message: String?) -> Error {
  261. error(code: .webContextAlreadyPresented, message: message)
  262. }
  263. static func webContextCancelledError(message: String?) -> Error {
  264. error(code: .webContextCancelled, message: message)
  265. }
  266. static func appVerificationUserInteractionFailure(reason: String?) -> Error {
  267. let userInfo: [String: Any]?
  268. if let reason, !reason.isEmpty {
  269. userInfo = [NSLocalizedFailureReasonErrorKey: reason]
  270. } else {
  271. userInfo = nil
  272. }
  273. return error(code: .appVerificationUserInteractionFailure, userInfo: userInfo)
  274. }
  275. static func webSignInUserInteractionFailure(reason: String?) -> Error {
  276. let userInfo: [String: Any]?
  277. if let reason, !reason.isEmpty {
  278. userInfo = [NSLocalizedFailureReasonErrorKey: reason]
  279. } else {
  280. userInfo = nil
  281. }
  282. return error(code: .webSignInUserInteractionFailure, userInfo: userInfo)
  283. }
  284. static func urlResponseError(code: String, message: String?) -> Error {
  285. let errorCode: AuthErrorCode
  286. switch code {
  287. case kURLResponseErrorCodeInvalidClientID:
  288. errorCode = .invalidClientID
  289. case kURLResponseErrorCodeNetworkRequestFailed:
  290. errorCode = .webNetworkRequestFailed
  291. case kURLResponseErrorCodeInternalError:
  292. errorCode = .webInternalError
  293. default:
  294. return AuthErrorUtils.webSignInUserInteractionFailure(reason: "[\(code)] - \(message ?? "")")
  295. }
  296. return error(code: errorCode, message: message)
  297. }
  298. static func nullUserError(message: String?) -> Error {
  299. error(code: .nullUser, message: message)
  300. }
  301. static func invalidProviderIDError(message: String?) -> Error {
  302. error(code: .invalidProviderID, message: message)
  303. }
  304. static func invalidHostingLinkDomainError(message: String?) -> Error {
  305. error(code: .invalidHostingLinkDomain, message: message)
  306. }
  307. static func missingOrInvalidNonceError(message: String?) -> Error {
  308. error(code: .missingOrInvalidNonce, message: message)
  309. }
  310. static func keychainError(function: String, status: OSStatus) -> Error {
  311. let message = SecCopyErrorMessageString(status, nil) as String? ?? ""
  312. let reason = "\(function) (\(status)) \(message)"
  313. return error(code: .keychainError, userInfo: [NSLocalizedFailureReasonErrorKey: reason])
  314. }
  315. static func tenantIDMismatchError() -> Error {
  316. error(code: .tenantIDMismatch)
  317. }
  318. static func unsupportedTenantOperationError() -> Error {
  319. error(code: .unsupportedTenantOperation)
  320. }
  321. static func notificationNotForwardedError() -> Error {
  322. error(code: .notificationNotForwarded)
  323. }
  324. static func appNotVerifiedError(message: String?) -> Error {
  325. error(code: .appNotVerified, message: message)
  326. }
  327. static func missingClientIdentifierError(message: String?) -> Error {
  328. error(code: .missingClientIdentifier, message: message)
  329. }
  330. static func missingClientType(message: String?) -> Error {
  331. error(code: .missingClientType, message: message)
  332. }
  333. static func captchaCheckFailedError(message: String?) -> Error {
  334. error(code: .captchaCheckFailed, message: message)
  335. }
  336. static func unexpectedResponse(data: Data?, underlyingError: Error?) -> Error {
  337. var userInfo: [String: Any] = [:]
  338. if let data {
  339. userInfo[userInfoDataKey] = data
  340. }
  341. if let underlyingError {
  342. userInfo[NSUnderlyingErrorKey] = underlyingError
  343. }
  344. return error(code: .internal(.unexpectedResponse), userInfo: userInfo)
  345. }
  346. static func unexpectedErrorResponse(data: Data?,
  347. underlyingError: Error?) -> Error {
  348. var userInfo: [String: Any] = [:]
  349. if let data {
  350. userInfo[userInfoDataKey] = data
  351. }
  352. if let underlyingError {
  353. userInfo[NSUnderlyingErrorKey] = underlyingError
  354. }
  355. return error(code: .internal(.unexpectedErrorResponse), userInfo: userInfo)
  356. }
  357. static func unexpectedErrorResponse(deserializedResponse: Any?) -> Error {
  358. var userInfo: [String: Any]?
  359. if let deserializedResponse {
  360. userInfo = [userInfoDeserializedResponseKey: deserializedResponse]
  361. }
  362. return error(code: .internal(.unexpectedErrorResponse), userInfo: userInfo)
  363. }
  364. static func unexpectedResponse(deserializedResponse: Any?) -> Error {
  365. var userInfo: [String: Any]?
  366. if let deserializedResponse {
  367. userInfo = [userInfoDeserializedResponseKey: deserializedResponse]
  368. }
  369. return error(code: .internal(.unexpectedResponse), userInfo: userInfo)
  370. }
  371. static func unexpectedResponse(deserializedResponse: Any?,
  372. underlyingError: Error?) -> Error {
  373. var userInfo: [String: Any] = [:]
  374. if let deserializedResponse {
  375. userInfo[userInfoDeserializedResponseKey] = deserializedResponse
  376. }
  377. if let underlyingError {
  378. userInfo[NSUnderlyingErrorKey] = underlyingError
  379. }
  380. return error(code: .internal(.unexpectedResponse), userInfo: userInfo)
  381. }
  382. static func unexpectedErrorResponse(deserializedResponse: Any?,
  383. underlyingError: Error?) -> Error {
  384. var userInfo: [String: Any] = [:]
  385. if let deserializedResponse {
  386. userInfo[userInfoDeserializedResponseKey] = deserializedResponse
  387. }
  388. if let underlyingError {
  389. userInfo[NSUnderlyingErrorKey] = underlyingError
  390. }
  391. return error(
  392. code: .internal(.unexpectedErrorResponse),
  393. userInfo: userInfo.isEmpty ? nil : userInfo
  394. )
  395. }
  396. static func malformedJWTError(token: String, underlyingError: Error?) -> Error {
  397. var userInfo: [String: Any] = [
  398. NSLocalizedDescriptionKey: kFIRAuthErrorMessageMalformedJWT,
  399. userInfoDataKey: token,
  400. ]
  401. if let underlyingError {
  402. userInfo[NSUnderlyingErrorKey] = underlyingError
  403. }
  404. return error(code: .malformedJWT, userInfo: userInfo)
  405. }
  406. static func RPCResponseDecodingError(deserializedResponse: Any?,
  407. underlyingError: Error?) -> Error {
  408. var userInfo: [String: Any] = [:]
  409. if let deserializedResponse {
  410. userInfo[userInfoDeserializedResponseKey] = deserializedResponse
  411. }
  412. if let underlyingError {
  413. userInfo[NSUnderlyingErrorKey] = underlyingError
  414. }
  415. return error(code: .internal(.RPCResponseDecodingError), userInfo: userInfo)
  416. }
  417. static func accountExistsWithDifferentCredentialError(email: String?,
  418. updatedCredential: AuthCredential?)
  419. -> Error {
  420. var userInfo: [String: Any] = [:]
  421. if let email {
  422. userInfo[AuthErrors.userInfoEmailKey] = email
  423. }
  424. if let updatedCredential {
  425. userInfo[AuthErrors.userInfoUpdatedCredentialKey] = updatedCredential
  426. }
  427. return error(code: .accountExistsWithDifferentCredential, userInfo: userInfo)
  428. }
  429. private static func extractJSONObjectFromString(from string: String) -> [String: Any]? {
  430. // 1. Find the start of the JSON object.
  431. guard let start = string.firstIndex(of: "{") else {
  432. return nil // No JSON object found
  433. }
  434. // 2. Find the end of the JSON object.
  435. // Start from the first curly brace `{`
  436. var curlyLevel = 0
  437. var endIndex: String.Index?
  438. for index in string.indices.suffix(from: start) {
  439. let char = string[index]
  440. if char == "{" {
  441. curlyLevel += 1
  442. } else if char == "}" {
  443. curlyLevel -= 1
  444. if curlyLevel == 0 {
  445. endIndex = index
  446. break
  447. }
  448. }
  449. }
  450. guard let end = endIndex else {
  451. return nil // Unbalanced curly braces
  452. }
  453. // 3. Extract the JSON string.
  454. let jsonString = String(string[start ... end])
  455. // 4. Convert JSON String to JSON Object
  456. guard let jsonData = jsonString.data(using: .utf8) else {
  457. return nil // Could not convert String to Data
  458. }
  459. do {
  460. if let jsonObject = try JSONSerialization
  461. .jsonObject(with: jsonData, options: []) as? [String: Any] {
  462. return jsonObject
  463. } else {
  464. return nil // JSON Object is not a dictionary
  465. }
  466. } catch {
  467. return nil // Failed to deserialize JSON
  468. }
  469. }
  470. static func blockingCloudFunctionServerResponse(message: String?) -> Error {
  471. guard let message else {
  472. return error(code: .blockingCloudFunctionError, message: message)
  473. }
  474. guard let jsonDict = extractJSONObjectFromString(from: message) else {
  475. return error(code: .blockingCloudFunctionError, message: message)
  476. }
  477. let errorDict = jsonDict["error"] as? [String: Any] ?? [:]
  478. let errorMessage = errorDict["message"] as? String
  479. return error(code: .blockingCloudFunctionError, message: errorMessage)
  480. }
  481. #if os(iOS)
  482. static func secondFactorRequiredError(pendingCredential: String?,
  483. hints: [MultiFactorInfo],
  484. auth: Auth)
  485. -> Error {
  486. var userInfo: [String: Any] = [:]
  487. if let pendingCredential = pendingCredential {
  488. let resolver = MultiFactorResolver(with: pendingCredential, hints: hints, auth: auth)
  489. userInfo[AuthErrors.userInfoMultiFactorResolverKey] = resolver
  490. }
  491. return error(code: .secondFactorRequired, userInfo: userInfo)
  492. }
  493. #endif // os(iOS)
  494. static func recaptchaSDKNotLinkedError() -> Error {
  495. // TODO(ObjC): point the link to GCIP doc once available.
  496. let message = "The reCAPTCHA SDK is not linked to your app. See " +
  497. "https://cloud.google.com/recaptcha-enterprise/docs/instrument-ios-apps"
  498. return error(code: .recaptchaSDKNotLinked, message: message)
  499. }
  500. static func recaptchaSiteKeyMissing() -> Error {
  501. // TODO(ObjC): point the link to GCIP doc once available.
  502. let message = "The site key for the reCAPTCHA SDK was not found. See " +
  503. "https://cloud.google.com/recaptcha-enterprise/docs/instrument-ios-apps"
  504. return error(code: .recaptchaSiteKeyMissing, message: message)
  505. }
  506. static func recaptchaActionCreationFailed() -> Error {
  507. // TODO(ObjC): point the link to GCIP doc once available.
  508. let message = "The reCAPTCHA SDK action class creation failed. See " +
  509. "https://cloud.google.com/recaptcha-enterprise/docs/instrument-ios-apps"
  510. return error(code: .recaptchaActionCreationFailed, message: message)
  511. }
  512. }