mirror of
https://github.com/vercel/chat.git
synced 2026-09-14 18:32:29 +08:00
c3b5a08e7e
## summary Pub/Sub push verification checked the token's `aud` and nothing else. [Google's guidance](https://docs.cloud.google.com/pubsub/docs/authenticate-push-subscriptions) is explicit that signature and audience verification are not sufficient on their own, and that the `email` and `email_verified` claims must be checked alongside them adds `pubsubServiceAccountEmail` (env `GOOGLE_CHAT_PUBSUB_SERVICE_ACCOUNT_EMAIL`), the identity in the subscription's push auth settings. a push is accepted only when `email_verified` is true and `email` matches exactly. when the option is unset, pushes are rejected rather than trusted on their audience alone direct webhooks are untouched, and the project-number path already bound to an exact issuer ### how it happened `verifyBearerToken` took the claim validator as an optional parameter, so a call site could simply omit it, and the Pub/Sub one did while the direct-webhook one did not. that is now required: ```diff - validatePayload?: (payload: { + validatePayload: (payload: { ``` both call sites pass one and the type system enforces it, so the omission cannot recur ## test plan - a token from a different service account is rejected - a token is rejected when no identity is configured - a token is rejected when `email_verified` is not true - a token with no `email` claim is rejected - a matching identity with a verified email is accepted - direct-webhook and project-number verification are unchanged docs cover the new option in the README and adapter page, including the push-subscription authentication step that produces the token