How do I verify the ID token with Firebase and Django Rest?

Viewed 871

I just can't wrap my head around how the authentication is done if I use Firebase auth and I wish to connect it to my django rest backend.

I use the getIdTokenResult provided by firebase as such:

 async login() {
            this.error = null;
            try {
                const response = await firebase.auth().signInWithEmailAndPassword(this.email, this.password);
                const token = await response.user.getIdTokenResult();

                /* 
                  No idea if this part below is correct 
                  Should I create a custom django view for this part?
                */

                 fetch("/account/firebase/", {
                     method: "POST",
                     headers: { 
                         "Content-Type": "application/json", 
                         "HTTP_AUTHORIZATION": token.token,
                     },
                     body: JSON.stringify({ username: this.email, password: this.password }),
                 }).then((response) => response.json().then((data) => console.log(data)));
            } catch (error) {
                this.error = error;
            }
        },

The only thing I find in the firebase docs is this lackluster two line snippet: https://firebase.google.com/docs/auth/admin/verify-id-tokens#web

where they write

decoded_token = auth.verify_id_token(id_token)
uid = decoded_token['uid']
# wtf, where does this go? 
# what do I do with this? Do I put it in a django View?

I found a guide here that connects django rest to firebase: https://www.oscaralsing.com/firebase-authentication-in-django/

But I still don't understand how its all tied together. When am I supposed to call this FirebaseAuthentication. Whenever I try to call the login function I just get a 403 CSRF verification failed. Request aborted.

This whole FirebaseAuthentication class provided by the guide I linked to above - should I add that as a path on the backend?

path("firebase/", FirebaseAuthentication, name="api-firebase"),

Which is the api endpoint my frontend calls?

0 Answers
Related