جدیدترین نسخه Google Identity Toolkit با نام Firebase Authentication منتشر شده است. از این پس، کار روی ویژگیها روی Identity Toolkit متوقف خواهد شد و تمام توسعه ویژگیهای جدید روی Firebase Authentication انجام خواهد شد. ما توسعهدهندگان Identity Toolkit را تشویق میکنیم که در اسرع وقت برای برنامههای خود به Firebase Authentication مهاجرت کنند. با این حال، Identity Toolkit همچنان به کار خود ادامه میدهد و بدون اعلام بیشتر منسوخ نخواهد شد.
ویژگیهای جدید
احراز هویت فایربیس در حال حاضر نسبت به ابزار هویت گوگل (Google Identity Toolkit) پیشرفتهای قابل توجهی در ویژگیهای خود دارد:
دسترسی به تمام فایربیس
فایربیس یک پلتفرم موبایل است که به شما کمک میکند تا به سرعت برنامههای با کیفیت بالا توسعه دهید، پایگاه کاربران خود را افزایش دهید و درآمد بیشتری کسب کنید. فایربیس از ویژگیهای مکملی تشکیل شده است که میتوانید آنها را با هم ترکیب و مطابقت دهید تا با نیازهای شما مطابقت داشته باشد و شامل زیرساختهایی برای موارد زیر است: تجزیه و تحلیل موبایل، پیامرسانی ابری ، پایگاه داده بلادرنگ ، ذخیرهسازی فایل ، میزبانی استاتیک ، پیکربندی از راه دور ، گزارش خرابی موبایل و آزمایش اندروید.
رابطهای کاربری بهروز شده
ما جریانهای رابط کاربری را بر اساس آخرین تحقیقات تجربه کاربری گوگل، به طور کامل بازسازی کردهایم. این شامل بازیابی رمز عبور، پیوند حساب کاربری، جریانهای ابهامزدایی حساب کاربری جدید/موجود میشود که اغلب زمان قابل توجهی برای کدنویسی و اشکالزدایی صرف میکنند. این برنامه ، قفل هوشمند برای رمزهای عبور در اندروید را ادغام میکند که به طور قابل توجهی تبدیل ورود و ثبت نام را برای برنامههای شرکتکننده بهبود بخشیده است. همچنین از تغییرات آسان تم برای مطابقت با برنامه شما پشتیبانی میکند و برای حداکثر قابلیت سفارشیسازی، نسخههای اندروید و iOS متنباز شدهاند.
راهاندازی سادهشده سرور
ما استفاده از احراز هویت فایربیس را برای توسعهدهندگان آسانتر کردهایم. با استفاده از Identity Toolkit، شاهد بودیم که بسیاری از توسعهدهندگان تصمیم گرفتند جریان بازیابی ایمیل را پیادهسازی نکنند که این امر باعث میشد کاربرانشان در صورت فراموش کردن رمز عبور، نتوانند حسابهای خود را بازیابی کنند. احراز هویت فایربیس میتواند پیامهای تأیید ایمیل، تنظیم مجدد رمز عبور و تغییر رمز عبور را برای کاربر ارسال کند و متن آن را میتوان به راحتی برای کاربران شما سفارشی کرد . علاوه بر این، دیگر نیازی به میزبانی ویجتهای رابط کاربری برای میزبانی تغییر مسیرها و تکمیل عملیات تغییر رمز عبور ندارید.
کنسول مدیریت جدید
فایربیس یک کنسول توسعهدهنده جدید دارد و بخش احراز هویت به شما امکان مشاهده، تغییر و حذف کاربران را میدهد. این میتواند کمک بزرگی در اشکالزدایی جریانهای ورود و ثبتنام شما باشد. این کنسول همچنین به شما امکان میدهد روشهای احراز هویت را پیکربندی کرده و قالبهای ایمیل را سفارشی کنید.
SDK های جدید
تمام APIهای سرور Identity Toolkit اکنون به صورت بومی با هر یک از کتابخانههای کلاینت ما (اندروید، iOS، وب) در دسترس هستند. توسعهدهندگان قادر خواهند بود بدون اتصال به یک رابط کاربری ثابت، کاربران قدیمی و جدید را وارد سیستم کرده و ثبتنام کنند، به ویژگیهای کاربر دسترسی پیدا کنند، حسابها را پیوند دهند، بهروزرسانی و حذف کنند، رمزهای عبور را بازنشانی کنند و موارد دیگر. در صورت تمایل، میتوانید کل جریان ورود و تجربه خود را به صورت دستی بر روی این API بسازید.
مدیریت نشست برای برنامههای تلفن همراه
با استفاده از Identity Toolkit، برنامهها وضعیت جلسه خود را بر اساس رویداد احراز هویت اولیه از Identity Toolkit ایجاد میکردند. Firebase Auth از یک سرویس backend استفاده میکند که یک توکن refresh را که از رویداد احراز هویت ایجاد شده است، میگیرد و آن را با توکنهای دسترسی یک ساعته برای اندروید، iOS و جاوا اسکریپت مبادله میکند. هنگامی که کاربر رمز عبور خود را تغییر میدهد، توکنهای refresh دیگر قادر به تولید توکنهای دسترسی جدید نخواهند بود و در نتیجه دسترسی تا زمانی که کاربر در آن دستگاه احراز هویت مجدد کند، غیرفعال میشود.
احراز هویت ناشناس و گیتهاب
احراز هویت فایربیس از دو نوع احراز هویت جدید پشتیبانی میکند: گیتهاب و ناشناس. ورود ناشناس میتواند برای ایجاد یک شناسه کاربری منحصر به فرد بدون نیاز به طی کردن هرگونه فرآیند ورود یا ثبتنام توسط کاربر استفاده شود. با یک کاربر ناشناس، اکنون میتوانید فراخوانیهای API احراز هویت شده را مانند یک کاربر معمولی انجام دهید. وقتی کاربر تصمیم به ثبتنام برای یک حساب کاربری میگیرد، تمام فعالیتها با همان شناسه کاربری ذخیره میشوند. این برای موقعیتهایی مانند سبد خرید سمت سرور یا هر برنامهای که میخواهید کاربر را قبل از ارسال آنها به جریان ثبتنام، درگیر کنید، عالی است.
تفاوتهای ویژگی
برخی از ویژگیهای Identity Toolkit در حال حاضر در Firebase Authentication موجود نیستند، در حالی که سایر ویژگیها دوباره طراحی شدهاند و به طور متفاوتی کار میکنند. اگر این ویژگیها برای برنامه شما مهم هستند، میتوانید فوراً مهاجرت نکنید. در بسیاری از موارد، این ویژگیها ممکن است برای برنامه شما مهم نباشند یا ممکن است گزینههای جایگزینی وجود داشته باشد که به شما امکان میدهد مهاجرت را ادامه دهید.
تفاوتهای سمت سرور
سرویس اصلی Identity Toolkit با APIهای REST زیربنایی، منطق اعتبارسنجی حساب و پایگاه داده اصلی کاربر، تنها بهروزرسانیهای جزئی را پشت سر گذاشته است. اما برخی از ویژگیها و نحوه ادغام احراز هویت Firebase در سرویس شما تغییر کرده است.
ارائه دهندگان هویت
پیپال و AOL پشتیبانی نمیشوند. کاربرانی که حساب کاربری از این IDPها دارند، همچنان میتوانند با استفاده از فرآیند بازیابی رمز عبور وارد برنامه شما شوند و برای حساب خود رمز عبور تعیین کنند.
کتابخانههای سرور
در حال حاضر، SDK های مدیریت Firebase برای جاوا، Node.js، پایتون، Go و C# در دسترس هستند.
ایمیلهای مدیریت حساب
پیامهای بازنشانی رمز عبور، تأیید ایمیل و تغییر ایمیل میتوانند توسط Firebase یا از طریق سرور ایمیل خود توسعهدهنده انجام شوند. در حال حاضر، قالبهای ایمیل Firebase فقط امکان سفارشیسازی محدودی را ارائه میدهند.
تایید تغییر آدرس ایمیل
در Identity Toolkit، وقتی کاربری تصمیم به تغییر آدرس ایمیل خود میگیرد، ایمیلی به آدرس جدید ارسال میشود که حاوی لینکی برای ادامه روند تغییر آدرس ایمیل است.
فایربیس با ارسال یک ایمیل لغو به آدرس ایمیل قدیمی به همراه لینکی برای بازگرداندن تغییر، تغییر آدرس ایمیل را تأیید میکند.
اجرای طرح آوارگی داخلی
Identity Toolkit قابلیتی داشت که به تدریج ارائهدهندگان هویت را به سیستم ورود شما اضافه میکرد تا بتوانید تأثیر آن را بر درخواستهای پشتیبانی خود آزمایش کنید. این ویژگی در Firebase Authentication حذف شده است.
اختلافات طرف مشتری
در فایربیس، ویژگیهای ارائه شده توسط ابزار Google Identity Toolkit به دو بخش تقسیم میشوند:
SDK های احراز هویت فایربیس
در احراز هویت فایربیس، قابلیتهای ارائه شده توسط REST API مربوط به Identity Toolkit در SDKهای کلاینت موجود برای اندروید، iOS و جاوا اسکریپت بستهبندی شدهاند. شما میتوانید از SDK برای ورود و ثبتنام کاربران؛ دسترسی به اطلاعات پروفایل کاربر؛ اتصال، بهروزرسانی و حذف حسابها؛ و تنظیم مجدد رمزهای عبور با استفاده از SDK کلاینت به جای ارتباط با سرویس بکاند از طریق فراخوانیهای REST استفاده کنید.
احراز هویت FirebaseUI
تمام جریانهای رابط کاربری که ورود، ثبتنام، بازیابی رمز عبور و پیوند حساب را مدیریت میکنند، با استفاده از SDKهای احراز هویت Frebase بازسازی شدهاند. این SDKها به صورت متنباز برای iOS و اندروید در دسترس هستند تا شما را قادر سازند جریانها را به طور کامل سفارشی کنید، به روشهایی که با Identity Toolkit امکانپذیر نیست.
تفاوتهای اضافی عبارتند از:
جلسات و مهاجرت
از آنجا که جلسات در Identity Toolkit و Firebase Authentication به طور متفاوتی مدیریت میشوند، جلسات فعلی کاربران شما پس از ارتقاء SDK خاتمه مییابد و کاربران شما باید دوباره وارد سیستم شوند.
قبل از اینکه شروع کنی
قبل از اینکه بتوانید از Identity Toolkit به Firebase Authentication مهاجرت کنید، باید
کنسول فایربیس را باز کنید، روی وارد کردن پروژه گوگل کلیک کنید و پروژه Identity Toolkit خود را انتخاب کنید.
برای باز کردن صفحه IAM & Admin، settings > مجوزها کلیک کنید.
صفحه حسابهای سرویس (Service accounts) را باز کنید. در اینجا میتوانید حساب سرویسی را که قبلاً برای Identity Toolkit پیکربندی کردهاید، مشاهده کنید.
در کنار حساب سرویس، روی more_vert > Create key کلیک کنید. سپس، در کادر محاورهای Create private key ، نوع کلید را روی JSON تنظیم کنید و روی Create کلیک کنید. یک فایل JSON حاوی اطلاعات حساب سرویس شما دانلود میشود. برای مقداردهی اولیه SDK در مرحله بعدی به آن نیاز خواهید داشت.
به کنسول فایربیس برگردید. در بخش Auth، صفحه Email Templates را باز کنید. در این صفحه، قالبهای ایمیل برنامه خود را سفارشی کنید.
در Identity Toolkit، وقتی کاربران رمز عبور را تغییر میدادند، آدرس ایمیل خود را تغییر میدادند و آدرس ایمیل خود را تأیید میکردند، شما باید یک کد OOB از سرور Identity Toolkit دریافت میکردید و سپس کد را از طریق ایمیل برای کاربران ارسال میکردید. Firebase ایمیلها را بر اساس قالبهایی که پیکربندی میکنید، بدون نیاز به هیچ اقدام اضافی ارسال میکند.
اختیاری : اگر نیاز به دسترسی به سرویسهای Firebase روی سرور خود دارید، Firebase SDK را نصب کنید.
میتوانید ماژول Firebase Node.js را با
npmنصب کنید:$ npm init $ npm install --save firebase-adminدر کد خود، میتوانید با استفاده از دستور زیر به Firebase دسترسی پیدا کنید:
var admin = require('firebase-admin'); var app = admin.initializeApp({ credential: admin.credential.cert('path/to/serviceAccountCredentials.json') });
در مرحله بعد، مراحل مهاجرت را برای پلتفرم برنامه خود تکمیل کنید: اندروید ، iOS ، وب .
سرورها و جاوا اسکریپت
تغییرات قابل توجه
تعدادی تفاوت دیگر در پیادهسازی وب Firebase از Identity Toolkit وجود دارد.
مدیریت جلسه وب
پیش از این، وقتی کاربری با استفاده از ویجت Identity Toolkit احراز هویت میشد، یک کوکی برای کاربر تنظیم میشد که برای راهاندازی جلسه (session) استفاده میشد. این کوکی دو هفته طول عمر داشت و برای این استفاده میشد که کاربر بتواند از ویجت مدیریت حساب برای تغییر رمز عبور و آدرس ایمیل استفاده کند. برخی سایتها از این کوکی برای احراز هویت تمام درخواستهای صفحات دیگر در سایت استفاده میکردند. برخی دیگر از سایتها از این کوکی برای ایجاد کوکیهای خود از طریق سیستم مدیریت کوکی چارچوب خود استفاده میکردند.
کیتهای توسعه نرمافزار (SDK) کلاینت فایربیس اکنون توکنهای شناسه فایربیس را مدیریت میکنند و با بکاند احراز هویت فایربیس همکاری میکنند تا جلسه را بهروز نگه دارند. بکاند، جلسات را زمانی که تغییرات مهم حساب (مانند تغییر رمز عبور کاربر) رخ میدهد، منقضی میکند. توکنهای شناسه فایربیس بهطور خودکار بهعنوان کوکی در کلاینت وب تنظیم نمیشوند و فقط یک ساعت طول عمر دارند. مگر اینکه بخواهید جلسات فقط یک ساعته داشته باشید، توکنهای شناسه فایربیس برای استفاده بهعنوان کوکی جهت اعتبارسنجی تمام درخواستهای صفحه شما مناسب نیستند. در عوض، باید یک شنونده برای زمانی که کاربر وارد سیستم میشود، دریافت توکن شناسه فایربیس ، اعتبارسنجی توکن و ایجاد کوکی خود از طریق سیستم مدیریت کوکی چارچوب خود تنظیم کنید.
شما باید طول عمر جلسه کوکی خود را بر اساس نیازهای امنیتی برنامه خود تنظیم کنید.
جریان ورود به سیستم وب
پیش از این، کاربران هنگام ورود به سیستم به
accountchooser.comهدایت میشدند تا بدانند کاربر از چه شناسهای میخواهد استفاده کند. روند کار رابط کاربری احراز هویت Firebase اکنون با فهرستی از روشهای ورود به سیستم آغاز میشود، از جمله گزینه ایمیل که برای وب بهaccountchooser.comمیرود و از API hintRequest در اندروید استفاده میکند. علاوه بر این، آدرسهای ایمیل دیگر در رابط کاربری Firebase مورد نیاز نیستند. این امر پشتیبانی از کاربران ناشناس، کاربران احراز هویت سفارشی یا کاربران ارائهدهندگانی را که در آنها آدرسهای ایمیل مورد نیاز نیست، آسانتر میکند.ویجت مدیریت حساب
این ویجت یک رابط کاربری برای کاربران فراهم میکند تا آدرسهای ایمیل، رمز عبور یا اتصال حسابهای خود را از ارائهدهندگان هویت قطع کنند. این ویجت در حال حاضر در دست توسعه است.
دکمه/ویجت ورود
ویجتهایی مانند دکمه ورود و کارت کاربری دیگر ارائه نمیشوند. آنها را میتوان به راحتی با استفاده از API احراز هویت Firebase ساخت.
بدون signOutUrl
شما باید
firebase.auth.signOut()را فراخوانی کرده و فراخوانی برگشتی را مدیریت کنید.بدون آدرس اقدام oob
ارسال ایمیل اکنون توسط Firebase انجام میشود و در کنسول Firebase پیکربندی شده است.
سفارشی سازی CSS
FirebaseUI از استایلبندی Material Design Lite استفاده میکند که به صورت پویا انیمیشنهای Material Design را اضافه میکند.
مرحله ۱: تغییر کد سرور
اگر سرور شما برای مدیریت جلسات کاربران وب به توکن Identity Toolkit (معتبر به مدت دو هفته) متکی است، باید سرور را به گونهای تغییر دهید که از کوکی جلسه مخصوص به خود استفاده کند.
- یک نقطه پایانی برای اعتبارسنجی توکن Firebase ID و تنظیم کوکی جلسه برای کاربر پیادهسازی کنید. برنامه کلاینت، توکن Firebase ID را به این نقطه پایانی ارسال میکند.
- اگر درخواست ورودی حاوی کوکی جلسه خودتان باشد، میتوانید کاربر را احراز هویت شده در نظر بگیرید. در غیر این صورت، درخواست را احراز هویت نشده در نظر بگیرید.
- اگر نمیخواهید هیچ یک از کاربرانتان جلسات ورود به سیستم فعلی خود را از دست بدهند، باید دو هفته صبر کنید تا تمام توکنهای Identity Toolkit منقضی شوند، یا اعتبارسنجی توکن دوگانه را برای برنامه وب خود همانطور که در مرحله 3 توضیح داده شده است، انجام دهید.
در مرحله بعد، از آنجا که توکنهای Firebase با توکنهای Identity Toolkit متفاوت هستند، باید منطق اعتبارسنجی توکن خود را بهروزرسانی کنید. کیت توسعه نرمافزار Firebase Server را روی سرور خود نصب کنید؛ یا اگر از زبانی استفاده میکنید که توسط کیت توسعه نرمافزار Firebase Server پشتیبانی نمیشود، یک کتابخانه اعتبارسنجی توکن JWT برای محیط خود دانلود کنید و توکن را به درستی اعتبارسنجی کنید .
وقتی برای اولین بار بهروزرسانیهای فوق را انجام میدهید، ممکن است هنوز مسیرهای کدی داشته باشید که به توکنهای Identity Toolkit متکی هستند. اگر برنامههای iOS یا Android دارید، کاربران باید برای کار کردن مسیرهای کد جدید، برنامه را به نسخه جدید ارتقا دهند. اگر نمیخواهید کاربران خود را مجبور به بهروزرسانی برنامه خود کنید، میتوانید منطق اعتبارسنجی سرور اضافی اضافه کنید که توکن را بررسی میکند و تعیین میکند که آیا برای اعتبارسنجی توکن باید از Firebase SDK یا Identity Toolkit SDK استفاده کند. اگر فقط یک برنامه وب دارید، تمام درخواستهای احراز هویت جدید به Firebase منتقل میشوند و بنابراین، فقط باید از روشهای تأیید توکن Firebase استفاده کنید.
به مرجع API وب فایربیس مراجعه کنید.
مرحله ۲: HTML خود را بهروزرسانی کنید
کد مقداردهی اولیه Firebase را به برنامه خود اضافه کنید:
- پروژه خود را در کنسول Firebase باز کنید.
- در صفحه مرور کلی، روی «افزودن برنامه» کلیک کنید، سپس روی «افزودن فایربیس به برنامه وب خود» کلیک کنید. قطعه کدی که فایربیس را مقداردهی اولیه میکند نمایش داده میشود.
- قطعه کد مقداردهی اولیه را کپی کرده و در صفحه وب خود جایگذاری کنید.
FirebaseUI Auth را به برنامه خود اضافه کنید:
<script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script> <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" /> <!-- ******************************************************************************************* * TODO(DEVELOPER): Paste the initialization snippet from: * Firebase Console > Overview > Add Firebase to your web app. * ***************************************************************************************** --> <script type="text/javascript"> // FirebaseUI config. var uiConfig = { 'signInSuccessUrl': '<url-to-redirect-to-on-success>', 'signInOptions': [ // Leave the lines as is for the providers you want to offer your users. firebase.auth.GoogleAuthProvider.PROVIDER_ID, firebase.auth.FacebookAuthProvider.PROVIDER_ID, firebase.auth.TwitterAuthProvider.PROVIDER_ID, firebase.auth.GithubAuthProvider.PROVIDER_ID, firebase.auth.EmailAuthProvider.PROVIDER_ID ], // Terms of service url. 'tosUrl': '<your-tos-url>', }; // Initialize the FirebaseUI Widget using Firebase. var ui = new firebaseui.auth.AuthUI(firebase.auth()); // The start method will wait until the DOM is loaded. ui.start('#firebaseui-auth-container', uiConfig); </script>SDK مربوط به Identity Toolkit را از برنامه خود حذف کنید.
اگر برای مدیریت جلسه به توکن ID کیت ابزار هویت (Identity Toolkit ID token) متکی بودهاید، باید تغییرات زیر را در سمت کلاینت اعمال کنید:
پس از ورود موفقیتآمیز به Firebase، با فراخوانی
firebase.auth().currentUser.getToken()یک توکن Firebase ID دریافت کنید.توکن Firebase ID را به سرور backend ارسال کنید، آن را اعتبارسنجی کنید و کوکی جلسه خود را صادر کنید.
هنگام انجام عملیات حساس یا ارسال درخواستهای ویرایش احراز هویت شده به سرور خود، صرفاً به کوکی جلسه (session cookie) تکیه نکنید. شما باید محافظت بیشتری در برابر جعل درخواست بین سایتی (CSRF) ارائه دهید.
اگر چارچوب شما محافظت در برابر CSRF را ارائه نمیدهد، یک راه برای جلوگیری از حمله این است که با استفاده از
getToken()یک توکن Firebase ID برای کاربر وارد شده دریافت کنید و توکن را با هر درخواست اضافه کنید (کوکی جلسه نیز به طور پیشفرض ارسال میشود). سپس آن توکن را علاوه بر بررسی کوکی جلسه که چارچوب backend شما انجام داده است، با استفاده از SDK سرور Firebase اعتبارسنجی میکنید. این کار موفقیت حملات CSRF را دشوارتر میکند، زیرا توکن Firebase ID فقط با استفاده از ذخیرهسازی وب ذخیره میشود و هرگز در کوکی نیست.توکنهای Identity Toolkit به مدت دو هفته اعتبار دارند. شما میتوانید به صدور توکنهایی که دو هفته اعتبار دارند ادامه دهید، یا ممکن است بخواهید بر اساس الزامات امنیتی برنامه خود، مدت زمان آن را طولانیتر یا کوتاهتر کنید. وقتی کاربر از سیستم خارج میشود، کوکی جلسه را پاک کنید.
مرحله ۳: بهروزرسانی آدرسهای اینترنتی تغییر مسیر IDP
در کنسول Firebase، بخش Authentication را باز کنید و روی تب Sign-in Method کلیک کنید.
برای هر ارائهدهنده ورود به سیستم فدرال که از آن پشتیبانی میکنید، موارد زیر را انجام دهید:
- روی نام ارائهدهندهی ورود به سیستم کلیک کنید.
- آدرس اینترنتی تغییر مسیر OAuth را کپی کنید.
- در کنسول توسعهدهندگان ارائهدهندهی ورود به سیستم، آدرس اینترنتی تغییر مسیر OAuth را بهروزرسانی کنید.
اندروید
مرحله ۱: اضافه کردن فایربیس به برنامه
کنسول فایربیس را باز کنید و پروژه Identity Toolkit خود را که قبلاً وارد کردهاید، انتخاب کنید.
در صفحه مرور کلی، روی «افزودن برنامه» کلیک کنید و سپس روی «افزودن فایربیس به برنامه اندروید خود» کلیک کنید. در کادر محاورهای «افزودن فایربیس»، نام بسته برنامه و اثر انگشت گواهی امضای آن را وارد کنید و روی «افزودن برنامه» کلیک کنید. سپس فایل پیکربندی
google-services.jsonدر رایانه شما دانلود میشود.فایل پیکربندی را در دایرکتوری ریشه ماژول برنامه اندروید خود کپی کنید. این فایل پیکربندی شامل اطلاعات پروژه و کلاینت Google OAuth است.
در فایل
build.gradleسطح پروژه خود (<var>your-project</var>/build.gradle)، نام بسته برنامه خود را در بخشdefaultConfigمشخص کنید:defaultConfig { ….. applicationId "com.your-app" }همچنین در فایل
build.gradleسطح پروژه خود، یک وابستگی برای گنجاندن افزونه google-services اضافه کنید:buildscript { dependencies { // Add this line classpath 'com.google.gms:google-services:3.0.0' } }در فایل app-level
build.gradleبرنامهتان (<var>my-project</var>/<var>app-module</var>/build.gradle)، خط زیر را به انتهای آن اضافه کنید تا افزونه google-services فعال شود:// Add to the bottom of the file apply plugin: 'com.google.gms.google-services'افزونهی google-services از فایل
google-services.jsonبرای پیکربندی برنامهی شما جهت استفاده از Firebase استفاده میکند.همچنین در فایل
build.gradleسطح App، وابستگی Firebase Authentication را اضافه کنید:compile 'com.google.firebase:firebase-auth:24.2.0' compile 'com.google.android.gms:play-services-auth:21.6.0'
مرحله ۲: حذف SDK مربوط به Identity Toolkit
- پیکربندی Identity Toolkit را از فایل
AndroidManifest.xmlحذف کنید. این اطلاعات در فایلgoogle-service.jsonقرار دارد و توسط افزونه google-services بارگذاری میشود. - SDK مربوط به Identity Toolkit را از برنامه خود حذف کنید.
مرحله ۳: FirebaseUI را به برنامه خود اضافه کنید
FirebaseUI Auth را به برنامه خود اضافه کنید.
در برنامه خود، فراخوانیهای مربوط به Identity Toolkit SDK را با فراخوانیهای مربوط به FirebaseUI جایگزین کنید.
آیاواس
مرحله ۱: اضافه کردن فایربیس به برنامه
با اجرای دستورات زیر، Firebase SDK را به برنامه خود اضافه کنید:
$ cd your-project directory $ pod init $ pod 'Firebase'کنسول فایربیس را باز کنید و پروژه Identity Toolkit خود را که قبلاً وارد کردهاید، انتخاب کنید.
در صفحه مرور کلی، روی افزودن برنامه کلیک کنید و سپس روی افزودن Firebase به برنامه iOS خود کلیک کنید. در کادر محاورهای افزودن Firebase، شناسه بسته نرمافزاری و شناسه فروشگاه برنامه خود را وارد کنید و سپس روی افزودن برنامه کلیک کنید. سپس فایل پیکربندی
GoogleService-Info.plistدر رایانه شما دانلود میشود. اگر چندین شناسه بسته نرمافزاری در پروژه خود دارید، هر شناسه بسته نرمافزاری باید در کنسول Firebase متصل شود تا بتواند فایلGoogleService-Info.plistمخصوص به خود را داشته باشد.فایل پیکربندی را در ریشه پروژه Xcode خود کپی کنید و آن را به همه targetها اضافه کنید.
مرحله ۲: حذف SDK مربوط به Identity Toolkit
-
GoogleIdentityToolkitاز Podfile برنامه خود حذف کنید. - دستور
pod installرا اجرا کنید.
مرحله ۳: FirebaseUI را به برنامه خود اضافه کنید
FirebaseUI Auth را به برنامه خود اضافه کنید.
در برنامه خود، فراخوانیهای مربوط به Identity Toolkit SDK را با فراخوانیهای مربوط به FirebaseUI جایگزین کنید.
جدیدترین نسخه Google Identity Toolkit با نام Firebase Authentication منتشر شده است. از این پس، کار روی ویژگیها روی Identity Toolkit متوقف خواهد شد و تمام توسعه ویژگیهای جدید روی Firebase Authentication انجام خواهد شد. ما توسعهدهندگان Identity Toolkit را تشویق میکنیم که در اسرع وقت برای برنامههای خود به Firebase Authentication مهاجرت کنند. با این حال، Identity Toolkit همچنان به کار خود ادامه میدهد و بدون اعلام بیشتر منسوخ نخواهد شد.
ویژگیهای جدید
احراز هویت فایربیس در حال حاضر نسبت به ابزار هویت گوگل (Google Identity Toolkit) پیشرفتهای قابل توجهی در ویژگیهای خود دارد:
دسترسی به تمام فایربیس
فایربیس یک پلتفرم موبایل است که به شما کمک میکند تا به سرعت برنامههای با کیفیت بالا توسعه دهید، پایگاه کاربران خود را افزایش دهید و درآمد بیشتری کسب کنید. فایربیس از ویژگیهای مکملی تشکیل شده است که میتوانید آنها را با هم ترکیب و مطابقت دهید تا با نیازهای شما مطابقت داشته باشد و شامل زیرساختهایی برای موارد زیر است: تجزیه و تحلیل موبایل، پیامرسانی ابری ، پایگاه داده بلادرنگ ، ذخیرهسازی فایل ، میزبانی استاتیک ، پیکربندی از راه دور ، گزارش خرابی موبایل و آزمایش اندروید.
رابطهای کاربری بهروز شده
ما جریانهای رابط کاربری را بر اساس آخرین تحقیقات تجربه کاربری گوگل، به طور کامل بازسازی کردهایم. این شامل بازیابی رمز عبور، پیوند حساب کاربری، جریانهای ابهامزدایی حساب کاربری جدید/موجود میشود که اغلب زمان قابل توجهی برای کدنویسی و اشکالزدایی صرف میکنند. این برنامه ، قفل هوشمند برای رمزهای عبور در اندروید را ادغام میکند که به طور قابل توجهی تبدیل ورود و ثبت نام را برای برنامههای شرکتکننده بهبود بخشیده است. همچنین از تغییرات آسان تم برای مطابقت با برنامه شما پشتیبانی میکند و برای حداکثر قابلیت سفارشیسازی، نسخههای اندروید و iOS متنباز شدهاند.
راهاندازی سادهشده سرور
ما استفاده از احراز هویت فایربیس را برای توسعهدهندگان آسانتر کردهایم. با استفاده از Identity Toolkit، شاهد بودیم که بسیاری از توسعهدهندگان تصمیم گرفتند جریان بازیابی ایمیل را پیادهسازی نکنند که این امر باعث میشد کاربرانشان در صورت فراموش کردن رمز عبور، نتوانند حسابهای خود را بازیابی کنند. احراز هویت فایربیس میتواند پیامهای تأیید ایمیل، تنظیم مجدد رمز عبور و تغییر رمز عبور را برای کاربر ارسال کند و متن آن را میتوان به راحتی برای کاربران شما سفارشی کرد . علاوه بر این، دیگر نیازی به میزبانی ویجتهای رابط کاربری برای میزبانی تغییر مسیرها و تکمیل عملیات تغییر رمز عبور ندارید.
کنسول مدیریت جدید
فایربیس یک کنسول توسعهدهنده جدید دارد و بخش احراز هویت به شما امکان مشاهده، تغییر و حذف کاربران را میدهد. این میتواند کمک بزرگی در اشکالزدایی جریانهای ورود و ثبتنام شما باشد. این کنسول همچنین به شما امکان میدهد روشهای احراز هویت را پیکربندی کرده و قالبهای ایمیل را سفارشی کنید.
SDK های جدید
تمام APIهای سرور Identity Toolkit اکنون به صورت بومی با هر یک از کتابخانههای کلاینت ما (اندروید، iOS، وب) در دسترس هستند. توسعهدهندگان قادر خواهند بود بدون اتصال به یک رابط کاربری ثابت، کاربران قدیمی و جدید را وارد سیستم کرده و ثبتنام کنند، به ویژگیهای کاربر دسترسی پیدا کنند، حسابها را پیوند دهند، بهروزرسانی و حذف کنند، رمزهای عبور را بازنشانی کنند و موارد دیگر. در صورت تمایل، میتوانید کل جریان ورود و تجربه خود را به صورت دستی بر روی این API بسازید.
مدیریت نشست برای برنامههای تلفن همراه
با استفاده از Identity Toolkit، برنامهها وضعیت جلسه خود را بر اساس رویداد احراز هویت اولیه از Identity Toolkit ایجاد میکردند. Firebase Auth از یک سرویس backend استفاده میکند که یک توکن refresh را که از رویداد احراز هویت ایجاد شده است، میگیرد و آن را با توکنهای دسترسی یک ساعته برای اندروید، iOS و جاوا اسکریپت مبادله میکند. هنگامی که کاربر رمز عبور خود را تغییر میدهد، توکنهای refresh دیگر قادر به تولید توکنهای دسترسی جدید نخواهند بود و در نتیجه دسترسی تا زمانی که کاربر در آن دستگاه احراز هویت مجدد کند، غیرفعال میشود.
احراز هویت ناشناس و گیتهاب
احراز هویت فایربیس از دو نوع احراز هویت جدید پشتیبانی میکند: گیتهاب و ناشناس. ورود ناشناس میتواند برای ایجاد یک شناسه کاربری منحصر به فرد بدون نیاز به طی کردن هرگونه فرآیند ورود یا ثبتنام توسط کاربر استفاده شود. با یک کاربر ناشناس، اکنون میتوانید فراخوانیهای API احراز هویت شده را مانند یک کاربر معمولی انجام دهید. وقتی کاربر تصمیم به ثبتنام برای یک حساب کاربری میگیرد، تمام فعالیتها با همان شناسه کاربری ذخیره میشوند. این برای موقعیتهایی مانند سبد خرید سمت سرور یا هر برنامهای که میخواهید کاربر را قبل از ارسال آنها به جریان ثبتنام، درگیر کنید، عالی است.
تفاوتهای ویژگی
برخی از ویژگیهای Identity Toolkit در حال حاضر در Firebase Authentication موجود نیستند، در حالی که سایر ویژگیها دوباره طراحی شدهاند و به طور متفاوتی کار میکنند. اگر این ویژگیها برای برنامه شما مهم هستند، میتوانید فوراً مهاجرت نکنید. در بسیاری از موارد، این ویژگیها ممکن است برای برنامه شما مهم نباشند یا ممکن است گزینههای جایگزینی وجود داشته باشد که به شما امکان میدهد مهاجرت را ادامه دهید.
تفاوتهای سمت سرور
سرویس اصلی Identity Toolkit با APIهای REST زیربنایی، منطق اعتبارسنجی حساب و پایگاه داده اصلی کاربر، تنها بهروزرسانیهای جزئی را پشت سر گذاشته است. اما برخی از ویژگیها و نحوه ادغام احراز هویت Firebase در سرویس شما تغییر کرده است.
ارائه دهندگان هویت
پیپال و AOL پشتیبانی نمیشوند. کاربرانی که حساب کاربری از این IDPها دارند، همچنان میتوانند با استفاده از فرآیند بازیابی رمز عبور وارد برنامه شما شوند و برای حساب خود رمز عبور تعیین کنند.
کتابخانههای سرور
در حال حاضر، SDK های مدیریت Firebase برای جاوا، Node.js، پایتون، Go و C# در دسترس هستند.
ایمیلهای مدیریت حساب
پیامهای بازنشانی رمز عبور، تأیید ایمیل و تغییر ایمیل میتوانند توسط Firebase یا از طریق سرور ایمیل خود توسعهدهنده انجام شوند. در حال حاضر، قالبهای ایمیل Firebase فقط امکان سفارشیسازی محدودی را ارائه میدهند.
تایید تغییر آدرس ایمیل
در Identity Toolkit، وقتی کاربری تصمیم به تغییر آدرس ایمیل خود میگیرد، ایمیلی به آدرس جدید ارسال میشود که حاوی لینکی برای ادامه روند تغییر آدرس ایمیل است.
فایربیس با ارسال یک ایمیل لغو به آدرس ایمیل قدیمی به همراه لینکی برای بازگرداندن تغییر، تغییر آدرس ایمیل را تأیید میکند.
اجرای طرح آوارگی داخلی
Identity Toolkit قابلیتی داشت که به تدریج ارائهدهندگان هویت را به سیستم ورود شما اضافه میکرد تا بتوانید تأثیر آن را بر درخواستهای پشتیبانی خود آزمایش کنید. این ویژگی در Firebase Authentication حذف شده است.
اختلافات طرف مشتری
در فایربیس، ویژگیهای ارائه شده توسط ابزار Google Identity Toolkit به دو بخش تقسیم میشوند:
SDK های احراز هویت فایربیس
در احراز هویت فایربیس، قابلیتهای ارائه شده توسط REST API مربوط به Identity Toolkit در SDKهای کلاینت موجود برای اندروید، iOS و جاوا اسکریپت بستهبندی شدهاند. شما میتوانید از SDK برای ورود و ثبتنام کاربران؛ دسترسی به اطلاعات پروفایل کاربر؛ اتصال، بهروزرسانی و حذف حسابها؛ و تنظیم مجدد رمزهای عبور با استفاده از SDK کلاینت به جای ارتباط با سرویس بکاند از طریق فراخوانیهای REST استفاده کنید.
احراز هویت FirebaseUI
تمام جریانهای رابط کاربری که ورود، ثبتنام، بازیابی رمز عبور و پیوند حساب را مدیریت میکنند، با استفاده از SDKهای احراز هویت Frebase بازسازی شدهاند. این SDKها به صورت متنباز برای iOS و اندروید در دسترس هستند تا شما را قادر سازند جریانها را به طور کامل سفارشی کنید، به روشهایی که با Identity Toolkit امکانپذیر نیست.
تفاوتهای اضافی عبارتند از:
جلسات و مهاجرت
از آنجا که جلسات در Identity Toolkit و Firebase Authentication به طور متفاوتی مدیریت میشوند، جلسات فعلی کاربران شما پس از ارتقاء SDK خاتمه مییابد و کاربران شما باید دوباره وارد سیستم شوند.
قبل از اینکه شروع کنی
قبل از اینکه بتوانید از Identity Toolkit به Firebase Authentication مهاجرت کنید، باید
کنسول فایربیس را باز کنید، روی وارد کردن پروژه گوگل کلیک کنید و پروژه Identity Toolkit خود را انتخاب کنید.
برای باز کردن صفحه IAM & Admin، settings > مجوزها کلیک کنید.
صفحه حسابهای سرویس (Service accounts) را باز کنید. در اینجا میتوانید حساب سرویسی را که قبلاً برای Identity Toolkit پیکربندی کردهاید، مشاهده کنید.
در کنار حساب سرویس، روی more_vert > Create key کلیک کنید. سپس، در کادر محاورهای Create private key ، نوع کلید را روی JSON تنظیم کنید و روی Create کلیک کنید. یک فایل JSON حاوی اطلاعات حساب سرویس شما دانلود میشود. برای مقداردهی اولیه SDK در مرحله بعدی به آن نیاز خواهید داشت.
به کنسول فایربیس برگردید. در بخش Auth، صفحه Email Templates را باز کنید. در این صفحه، قالبهای ایمیل برنامه خود را سفارشی کنید.
در Identity Toolkit، وقتی کاربران رمز عبور را تغییر میدادند، آدرس ایمیل خود را تغییر میدادند و آدرس ایمیل خود را تأیید میکردند، شما باید یک کد OOB از سرور Identity Toolkit دریافت میکردید و سپس کد را از طریق ایمیل برای کاربران ارسال میکردید. Firebase ایمیلها را بر اساس قالبهایی که پیکربندی میکنید، بدون نیاز به هیچ اقدام اضافی ارسال میکند.
اختیاری : اگر نیاز به دسترسی به سرویسهای Firebase روی سرور خود دارید، Firebase SDK را نصب کنید.
میتوانید ماژول Firebase Node.js را با
npmنصب کنید:$ npm init $ npm install --save firebase-adminدر کد خود، میتوانید با استفاده از دستور زیر به Firebase دسترسی پیدا کنید:
var admin = require('firebase-admin'); var app = admin.initializeApp({ credential: admin.credential.cert('path/to/serviceAccountCredentials.json') });
در مرحله بعد، مراحل مهاجرت را برای پلتفرم برنامه خود تکمیل کنید: اندروید ، iOS ، وب .
سرورها و جاوا اسکریپت
تغییرات قابل توجه
تعدادی تفاوت دیگر در پیادهسازی وب Firebase از Identity Toolkit وجود دارد.
مدیریت جلسه وب
پیش از این، وقتی کاربری با استفاده از ویجت Identity Toolkit احراز هویت میشد، یک کوکی برای کاربر تنظیم میشد که برای راهاندازی جلسه (session) استفاده میشد. این کوکی دو هفته طول عمر داشت و برای این استفاده میشد که کاربر بتواند از ویجت مدیریت حساب برای تغییر رمز عبور و آدرس ایمیل استفاده کند. برخی سایتها از این کوکی برای احراز هویت تمام درخواستهای صفحات دیگر در سایت استفاده میکردند. برخی دیگر از سایتها از این کوکی برای ایجاد کوکیهای خود از طریق سیستم مدیریت کوکی چارچوب خود استفاده میکردند.
کیتهای توسعه نرمافزار (SDK) کلاینت فایربیس اکنون توکنهای شناسه فایربیس را مدیریت میکنند و با بکاند احراز هویت فایربیس همکاری میکنند تا جلسه را بهروز نگه دارند. بکاند، جلسات را زمانی که تغییرات مهم حساب (مانند تغییر رمز عبور کاربر) رخ میدهد، منقضی میکند. توکنهای شناسه فایربیس بهطور خودکار بهعنوان کوکی در کلاینت وب تنظیم نمیشوند و فقط یک ساعت طول عمر دارند. مگر اینکه بخواهید جلسات فقط یک ساعته داشته باشید، توکنهای شناسه فایربیس برای استفاده بهعنوان کوکی جهت اعتبارسنجی تمام درخواستهای صفحه شما مناسب نیستند. در عوض، باید یک شنونده برای زمانی که کاربر وارد سیستم میشود، دریافت توکن شناسه فایربیس ، اعتبارسنجی توکن و ایجاد کوکی خود از طریق سیستم مدیریت کوکی چارچوب خود تنظیم کنید.
شما باید طول عمر جلسه کوکی خود را بر اساس نیازهای امنیتی برنامه خود تنظیم کنید.
جریان ورود به سیستم وب
پیش از این، کاربران هنگام ورود به سیستم به
accountchooser.comهدایت میشدند تا بدانند کاربر از چه شناسهای میخواهد استفاده کند. روند کار رابط کاربری احراز هویت Firebase اکنون با فهرستی از روشهای ورود به سیستم آغاز میشود، از جمله گزینه ایمیل که برای وب بهaccountchooser.comمیرود و از API hintRequest در اندروید استفاده میکند. علاوه بر این، آدرسهای ایمیل دیگر در رابط کاربری Firebase مورد نیاز نیستند. این امر پشتیبانی از کاربران ناشناس، کاربران احراز هویت سفارشی یا کاربران ارائهدهندگانی را که در آنها آدرسهای ایمیل مورد نیاز نیست، آسانتر میکند.ویجت مدیریت حساب
این ویجت یک رابط کاربری برای کاربران فراهم میکند تا آدرسهای ایمیل، رمز عبور یا اتصال حسابهای خود را از ارائهدهندگان هویت قطع کنند. این ویجت در حال حاضر در دست توسعه است.
دکمه/ویجت ورود
ویجتهایی مانند دکمه ورود و کارت کاربری دیگر ارائه نمیشوند. آنها را میتوان به راحتی با استفاده از API احراز هویت Firebase ساخت.
بدون signOutUrl
شما باید
firebase.auth.signOut()را فراخوانی کرده و فراخوانی برگشتی را مدیریت کنید.بدون آدرس اقدام oob
ارسال ایمیل اکنون توسط Firebase انجام میشود و در کنسول Firebase پیکربندی شده است.
سفارشی سازی CSS
FirebaseUI از استایلبندی Material Design Lite استفاده میکند که به صورت پویا انیمیشنهای Material Design را اضافه میکند.
مرحله ۱: تغییر کد سرور
اگر سرور شما برای مدیریت جلسات کاربران وب به توکن Identity Toolkit (معتبر به مدت دو هفته) متکی است، باید سرور را به گونهای تغییر دهید که از کوکی جلسه مخصوص به خود استفاده کند.
- یک نقطه پایانی برای اعتبارسنجی توکن Firebase ID و تنظیم کوکی جلسه برای کاربر پیادهسازی کنید. برنامه کلاینت، توکن Firebase ID را به این نقطه پایانی ارسال میکند.
- اگر درخواست ورودی حاوی کوکی جلسه خودتان باشد، میتوانید کاربر را احراز هویت شده در نظر بگیرید. در غیر این صورت، درخواست را احراز هویت نشده در نظر بگیرید.
- اگر نمیخواهید هیچ یک از کاربرانتان جلسات ورود به سیستم فعلی خود را از دست بدهند، باید دو هفته صبر کنید تا تمام توکنهای Identity Toolkit منقضی شوند، یا اعتبارسنجی توکن دوگانه را برای برنامه وب خود همانطور که در مرحله 3 توضیح داده شده است، انجام دهید.
در مرحله بعد، از آنجا که توکنهای Firebase با توکنهای Identity Toolkit متفاوت هستند، باید منطق اعتبارسنجی توکن خود را بهروزرسانی کنید. کیت توسعه نرمافزار Firebase Server را روی سرور خود نصب کنید؛ یا اگر از زبانی استفاده میکنید که توسط کیت توسعه نرمافزار Firebase Server پشتیبانی نمیشود، یک کتابخانه اعتبارسنجی توکن JWT برای محیط خود دانلود کنید و توکن را به درستی اعتبارسنجی کنید .
وقتی برای اولین بار بهروزرسانیهای فوق را انجام میدهید، ممکن است هنوز مسیرهای کدی داشته باشید که به توکنهای Identity Toolkit متکی هستند. اگر برنامههای iOS یا Android دارید، کاربران باید برای کار کردن مسیرهای کد جدید، برنامه را به نسخه جدید ارتقا دهند. اگر نمیخواهید کاربران خود را مجبور به بهروزرسانی برنامه خود کنید، میتوانید منطق اعتبارسنجی سرور اضافی اضافه کنید که توکن را بررسی میکند و تعیین میکند که آیا برای اعتبارسنجی توکن باید از Firebase SDK یا Identity Toolkit SDK استفاده کند. اگر فقط یک برنامه وب دارید، تمام درخواستهای احراز هویت جدید به Firebase منتقل میشوند و بنابراین، فقط باید از روشهای تأیید توکن Firebase استفاده کنید.
به مرجع API وب فایربیس مراجعه کنید.
مرحله ۲: HTML خود را بهروزرسانی کنید
Add the Firebase initialization code to your app:
- Open your project in the Firebase console .
- On the Overview page, click Add App , then click Add Firebase to your web app . A code snippet that initializes Firebase is displayed.
- Copy and paste the initialization snippet into your web page.
Add FirebaseUI Auth to your app:
<script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script> <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" /> <!-- ******************************************************************************************* * TODO(DEVELOPER): Paste the initialization snippet from: * Firebase Console > Overview > Add Firebase to your web app. * ***************************************************************************************** --> <script type="text/javascript"> // FirebaseUI config. var uiConfig = { 'signInSuccessUrl': '<url-to-redirect-to-on-success>', 'signInOptions': [ // Leave the lines as is for the providers you want to offer your users. firebase.auth.GoogleAuthProvider.PROVIDER_ID, firebase.auth.FacebookAuthProvider.PROVIDER_ID, firebase.auth.TwitterAuthProvider.PROVIDER_ID, firebase.auth.GithubAuthProvider.PROVIDER_ID, firebase.auth.EmailAuthProvider.PROVIDER_ID ], // Terms of service url. 'tosUrl': '<your-tos-url>', }; // Initialize the FirebaseUI Widget using Firebase. var ui = new firebaseui.auth.AuthUI(firebase.auth()); // The start method will wait until the DOM is loaded. ui.start('#firebaseui-auth-container', uiConfig); </script>Remove the Identity Toolkit SDK from your app.
If you relied on the Identity Toolkit ID token for session management, you must make the following changes on the client side:
After successfully signing in with Firebase, get a Firebase ID token by calling
firebase.auth().currentUser.getToken().Send the Firebase ID token to the backend server, validate it, and issue your own session cookie.
Do not rely solely on the session cookie when performing sensitive operations or sending authenticated edit requests to your server. You will need to provide additional cross-site request forgery (CSRF) protection.
If your framework does not provide CSRF protection, one way to prevent an attack would be to get a Firebase ID token for the signed-in user with
getToken()and include the token with each request (the session cookie will also be sent by default). You would then validate that token using the Firebase server SDK in addition to the session cookie check, which your backend framework completed. This will make it harder for CSRF attacks to succeed, as the Firebase ID token is only stored using web storage and never in a cookie.Identity Toolkit tokens are valid for two weeks. You may want to continue issuing tokens that last two weeks, or you might want to make it longer or shorter based on the security requirements of your app. When a user signs out, clear the session cookie.
Step 3: Update IDP redirect URLs
In the Firebase console, open the Authentication section and click the Sign-in Method tab.
For each federated sign-in provider you support, do the following:
- Click the name of the sign-in provider.
- Copy the OAuth redirect URI.
- In the sign-in provider's developer console, update the OAuth redirect URI.
اندروید
Step 1: Add Firebase to your app
Open the Firebase console , and select your Identity Toolkit project, which you already imported.
On the Overview page, click Add App , and then click Add Firebase to your Android app . In the Add Firebase dialog, provide your app's package name and signing certificate fingerprint and click Add App . The
google-services.jsonconfiguration file is then downloaded to your computer.Copy the configuration file to your Android app module root directory. This configuration file contains project and Google OAuth client information.
In your Project-level
build.gradlefile (<var>your-project</var>/build.gradle), specify your app's package name in thedefaultConfigsection:defaultConfig { ….. applicationId "com.your-app" }Also in your Project-level
build.gradlefile, add a dependency to include the google-services plugin:buildscript { dependencies { // Add this line classpath 'com.google.gms:google-services:3.0.0' } }In your app's App-level
build.gradlefile (<var>my-project</var>/<var>app-module</var>/build.gradle), add the following line to the bottom to enable the google-services plugin:// Add to the bottom of the file apply plugin: 'com.google.gms.google-services'The google-services plugin uses the
google-services.jsonfile to configure your application to use Firebase.Also in the App-level
build.gradlefile, add the Firebase Authentication dependency:compile 'com.google.firebase:firebase-auth:24.2.0' compile 'com.google.android.gms:play-services-auth:21.6.0'
Step 2: Remove the Identity Toolkit SDK
- Remove the Identity Toolkit configuration from the
AndroidManifest.xmlfile. This information is included in thegoogle-service.jsonfile and loaded by the google-services plugin. - Remove the Identity Toolkit SDK from your app.
Step 3: Add FirebaseUI to your app
Add FirebaseUI Auth to your app.
In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.
آیاواس
Step 1: Add Firebase to your app
Add the Firebase SDK to your app by running the following commands:
$ cd your-project directory $ pod init $ pod 'Firebase'Open the Firebase console , and select your Identity Toolkit project, which you already imported.
On the Overview page, click Add App , and then click Add Firebase to your iOS app . In the Add Firebase dialog, provide your app's bundle ID and App Store ID, and then click Add App . The
GoogleService-Info.plistconfiguration file is then downloaded to your computer. If you have multiple bundle IDs in your project, each bundle ID must be connected in the Firebase console so it can have its ownGoogleService-Info.plistfile.Copy the configuration file to the root of your Xcode project and add it to all targets.
Step 2: Remove the Identity Toolkit SDK
- Remove
GoogleIdentityToolkitfrom your app's Podfile. - Run the
pod installcommand.
Step 3: Add FirebaseUI to your app
Add FirebaseUI Auth to your app.
In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.
The newest version of Google Identity Toolkit has been released as Firebase Authentication . Going forward, feature work on Identity Toolkit will be frozen and all new feature development will be done on Firebase Authentication. We encourage Identity Toolkit developers to move to Firebase Authentication as soon as is practical for their applications; however, Identity Toolkit continues to work and will not be deprecated without a further announcement.
ویژگیهای جدید
Firebase Authentication already has some significant feature enhancements over Google Identity Toolkit:
Access to all of Firebase
Firebase is a mobile platform that helps you quickly develop high-quality apps, grow your user base, and earn more money. Firebase is made up of complementary features that you can mix-and-match to fit your needs and includes infrastructure for: mobile analytics , cloud messaging , realtime database , file storage , static hosting , remote configuration , mobile crash reporting and Android testing .
Updated UIs
We have completely rebuilt the UI flows based on Google's latest UX research. This includes password recovery, account linking, new/existing account disambiguation flows that often take significant time to code and debug. It integrates Smart Lock for Passwords on Android, which has significantly improved sign-in and sign-up conversion for participating apps . It also supports easy theme modifications to match your application and, for maximum customizability, the Android and iOS versions have been open sourced.
Simplified server setup
We have made it easier for developers to use Firebase Authentication. With Identity Toolkit, we saw that many developers chose not to implement the email recovery flow which made it impossible for their users to recover their accounts if they forgot their password. Firebase Authentication can send email verification, password reset, and changed password messages to the user and the text can be easily customized for your users. Additionally, you no longer need to host the UI widgets for hosting redirects and completing password change operations.
New admin console
Firebase has a new developer console and the Authentication section allows you to view, modify and delete your users. This can be a great help in debugging your sign-in and sign-up flows. The console also allows you to configure authentication methods and customize email templates.
New SDKs
All of Identity Toolkit's server APIs are now available natively with each of our client libraries (Android, iOS, web). Developers will be able to sign in and sign up old and new users, access user properties, link, update and delete accounts, reset passwords, and more without being tied to a fixed UI. If you prefer, you can manually build your own entire sign in flow and experience on top of this API.
Session management for mobile apps
With Identity Toolkit, apps created their own session state based on the initial authentication event from Identity Toolkit. Firebase Auth uses a backend service that takes a refresh token, minted from the authentication event, and exchanges it for hour-long access tokens for Android, iOS and JavaScript. When a user changes their password, refresh tokens will no longer be able to generate new access tokens, thereby disabling access until the user reauthenticates on that device.
Anonymous and GitHub authentication
Firebase Authentication supports two new authentication types: GitHub and anonymous. Anonymous sign-in can be used to create a unique user ID without requiring the user to go through any sign-in or sign-up process. With an anonymous user, you can now make authenticated API calls, like you would with a regular user. When the user decides to sign up for an account, all activity is preserved with the same user ID. This is great for situations like a server side shopping cart or any application where you want to engage the user before sending them through a sign-up flow.
Feature Differences
Some Identity Toolkit features are not currently available in Firebase Authentication, while other features have been redesigned and work differently. You might choose not to migrate immediately if these features are important to your app. In many cases, these features might not be important for your app or there might be easy fallbacks which will enable you to proceed with migration.
Server side differences
The core Identity Toolkit service with its underlying REST APIs, account validation logic, and primary user database have undergone only minor updates. But some features and the manner in which you integrate Firebase Authentication into your service has changed.
ارائه دهندگان هویت
Paypal and AOL are not supported. Users with accounts from these IDPs can still sign in to your application with the password recovery flow and set up a password for their account.
Server libraries
Currently, there are Firebase admin SDKs available for Java, Node.js, Python, Go and C#.
Account management emails
Password reset, email verification, and email change messages can be performed by Firebase or from the developer's own mail server. Currently, Firebase email templates offer only limited customization.
Email address change confirmation
In Identity Toolkit, when a user decides to change their email address, it sends an email to the new address that has a link to continue the email address change flow.
Firebase confirms the email address change by sending a revocation email to the old email address with a link to revert the change.
IDP rollout
Identity Toolkit had an ability to add identity providers to your sign-in system gradually, so that you could experiment with the impact on your support requests. This feature was removed in Firebase Authentication.
Client side differences
In Firebase, the features provided by Google Identity Toolkit are split into two components:
Firebase Authentication SDKs
In Firebase Authentication, the functionality provided by Identity Toolkit's REST API has been packaged in client SDKs available for Android, iOS, and JavaScript. You can use the SDK to sign in and sign up users; access user profile information; link, update and delete accounts; and reset passwords using the client SDK instead of communicating with the back end service via REST calls.
FirebaseUI Auth
All of the UI flows that manage sign-in, sign-up, password recovery, and account linking have been rebuilt using the Frebase Authentication SDKs. They are available as open source SDKs for iOS and Android to enable you to completely customize the flows in ways not possible with Identity Toolkit.
Additional differences include:
Sessions and migration
Because sessions are managed differently in Identity Toolkit and Firebase Authentication, your users' existing sessions will be terminated upon upgrading the SDK, and your users will have to sign in again.
قبل از اینکه شروع کنی
Before you can migrate from Identity Toolkit to Firebase Authentication, you must
Open the Firebase console , click Import Google Project , and select your Identity Toolkit project.
Click settings > Permissions to open the IAM & Admin page.
Open the Service accounts page. Here you can see the service account you previously configured for Identity Toolkit.
Next to the service account, click more_vert > Create key . Then, in the Create private key dialog, set the Key type to JSON and click Create . A JSON file containing your service account's credentials is downloaded for you. You'll need this to initialize the SDK in the next step.
Go back to the Firebase console . In the Auth section, open the Email Templates page. On this page, customize your app's email templates.
In Identity Toolkit, when users reset passwords, changed email addresses and verified email their email addresses, you needed to get an OOB code from the Identity Toolkit server, and then send the code to users through email. Firebase sends emails based on the templates you configure with no additional actions required.
Optional : If you need to access Firebase services on your server, install the Firebase SDK.
You can install the Firebase Node.js module with
npm:$ npm init $ npm install --save firebase-adminIn your code, you can access Firebase using:
var admin = require('firebase-admin'); var app = admin.initializeApp({ credential: admin.credential.cert('path/to/serviceAccountCredentials.json') });
Next, complete the migration steps for your app's platform: Android , iOS , web .
Servers and JavaScript
Notable changes
There are a number of additional differences in the web implementation of Firebase from Identity Toolkit.
Web session management
Previously, when a user authenticated using the Identity Toolkit widget , a cookie was set for the user which was used to bootstrap the session . This cookie had a two week lifetime and was used to allow the user to use the account management widget to change password and email address. Some sites used this cookie to authenticate all other page requests on the site. Other sites used the cookie to create their own cookies via their framework's cookie management system.
Firebase client SDKs now manage Firebase ID tokens and work with Firebase Authentication's backend to keep the session fresh. The backend expires sessions when important account changes (like user password changes) have occurred. Firebase ID tokens are not automatically set as cookies on the web client and have only an hour lifetime. Unless you want sessions of only an hour, Firebase ID tokens are not appropriate to be used as the cookie to validate all of your page requests. Instead, you will need to set up a listener for when the user logs in, get the Firebase ID token , validate the token , and create your own cookie via your framework's cookie management system.
You will need to set the session lifetime of your cookie based on the security needs of your application.
Web sign-in flow
Previously, users were redirected to
accountchooser.comwhen sign-in was initiated to learn what identifier the user wanted to use. Firebase Auth UI's flow now begins with a list of sign-in methods, including an email option which goes toaccountchooser.comfor web and uses the hintRequest API on Android. In addition, email addresses are no longer required in the Firebase UI. This will make it easier to support anonymous users, custom auth users or users from providers where email addresses are not required.Account management widget
This widget provides a UI for users to change email addresses, change password ors unlink their accounts from identity providers. It is currently under development.
Sign-in button/widget
Widgets like the sign-in button and user card are no longer provided. They can be built very easily using the Firebase Authentication API.
No signOutUrl
You will need to call
firebase.auth.signOut()and handle the callback.No oobActionUrl
Email sending is now handled by Firebase and is configured in the Firebase console.
CSS customization
FirebaseUI uses Material Design Lite styling, which dynamically adds Material Design animations.
Step 1: Change Server Code
If your server relies on the Identity Toolkit token (valid for two weeks) to manage web user sessions, you need to convert the server to use its own session cookie.
- Implement an endpoint for validating the Firebase ID token and setting the session cookie for the user. The client app sends the Firebase ID token to this endpoint.
- If the incoming request contains your own session cookie, you can consider the user authenticated. Otherwise, treat the request as unauthenticated.
- If you do not want any of your users to lose their existing logged-in sessions, you should wait for two weeks for all Identity Toolkit tokens to expire, or also do the dual token validation for your web application as described below in step 3.
Next, because the Firebase tokens are different than Identity Toolkit tokens, you must update your token validation logic. Install the Firebase Server SDK to your server; or, if you use a language not supported by the Firebase Server SDK, download a JWT token validation library for your environment and properly validate the token .
When you first make the above updates, you might still have code paths that rely on Identity Toolkit tokens. If you have iOS or Android applications, users will need to upgrade to the new version of the app in order to have the new code paths work. If you don't want to force your users to update your app, you can add additional server validation logic that examines the token and determines whether it needs to use the Firebase SDK or the Identity Toolkit SDK to validate the token. If you only have a web application, all new authentication requests will be shifted over to Firebase and, therefore, you only need to use the Firebase token verification methods.
See the Firebase Web API Reference .
Step 2: Update your HTML
Add the Firebase initialization code to your app:
- Open your project in the Firebase console .
- On the Overview page, click Add App , then click Add Firebase to your web app . A code snippet that initializes Firebase is displayed.
- Copy and paste the initialization snippet into your web page.
Add FirebaseUI Auth to your app:
<script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script> <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" /> <!-- ******************************************************************************************* * TODO(DEVELOPER): Paste the initialization snippet from: * Firebase Console > Overview > Add Firebase to your web app. * ***************************************************************************************** --> <script type="text/javascript"> // FirebaseUI config. var uiConfig = { 'signInSuccessUrl': '<url-to-redirect-to-on-success>', 'signInOptions': [ // Leave the lines as is for the providers you want to offer your users. firebase.auth.GoogleAuthProvider.PROVIDER_ID, firebase.auth.FacebookAuthProvider.PROVIDER_ID, firebase.auth.TwitterAuthProvider.PROVIDER_ID, firebase.auth.GithubAuthProvider.PROVIDER_ID, firebase.auth.EmailAuthProvider.PROVIDER_ID ], // Terms of service url. 'tosUrl': '<your-tos-url>', }; // Initialize the FirebaseUI Widget using Firebase. var ui = new firebaseui.auth.AuthUI(firebase.auth()); // The start method will wait until the DOM is loaded. ui.start('#firebaseui-auth-container', uiConfig); </script>Remove the Identity Toolkit SDK from your app.
If you relied on the Identity Toolkit ID token for session management, you must make the following changes on the client side:
After successfully signing in with Firebase, get a Firebase ID token by calling
firebase.auth().currentUser.getToken().Send the Firebase ID token to the backend server, validate it, and issue your own session cookie.
Do not rely solely on the session cookie when performing sensitive operations or sending authenticated edit requests to your server. You will need to provide additional cross-site request forgery (CSRF) protection.
If your framework does not provide CSRF protection, one way to prevent an attack would be to get a Firebase ID token for the signed-in user with
getToken()and include the token with each request (the session cookie will also be sent by default). You would then validate that token using the Firebase server SDK in addition to the session cookie check, which your backend framework completed. This will make it harder for CSRF attacks to succeed, as the Firebase ID token is only stored using web storage and never in a cookie.Identity Toolkit tokens are valid for two weeks. You may want to continue issuing tokens that last two weeks, or you might want to make it longer or shorter based on the security requirements of your app. When a user signs out, clear the session cookie.
Step 3: Update IDP redirect URLs
In the Firebase console, open the Authentication section and click the Sign-in Method tab.
For each federated sign-in provider you support, do the following:
- Click the name of the sign-in provider.
- Copy the OAuth redirect URI.
- In the sign-in provider's developer console, update the OAuth redirect URI.
اندروید
Step 1: Add Firebase to your app
Open the Firebase console , and select your Identity Toolkit project, which you already imported.
On the Overview page, click Add App , and then click Add Firebase to your Android app . In the Add Firebase dialog, provide your app's package name and signing certificate fingerprint and click Add App . The
google-services.jsonconfiguration file is then downloaded to your computer.Copy the configuration file to your Android app module root directory. This configuration file contains project and Google OAuth client information.
In your Project-level
build.gradlefile (<var>your-project</var>/build.gradle), specify your app's package name in thedefaultConfigsection:defaultConfig { ….. applicationId "com.your-app" }Also in your Project-level
build.gradlefile, add a dependency to include the google-services plugin:buildscript { dependencies { // Add this line classpath 'com.google.gms:google-services:3.0.0' } }In your app's App-level
build.gradlefile (<var>my-project</var>/<var>app-module</var>/build.gradle), add the following line to the bottom to enable the google-services plugin:// Add to the bottom of the file apply plugin: 'com.google.gms.google-services'The google-services plugin uses the
google-services.jsonfile to configure your application to use Firebase.Also in the App-level
build.gradlefile, add the Firebase Authentication dependency:compile 'com.google.firebase:firebase-auth:24.2.0' compile 'com.google.android.gms:play-services-auth:21.6.0'
Step 2: Remove the Identity Toolkit SDK
- Remove the Identity Toolkit configuration from the
AndroidManifest.xmlfile. This information is included in thegoogle-service.jsonfile and loaded by the google-services plugin. - Remove the Identity Toolkit SDK from your app.
Step 3: Add FirebaseUI to your app
Add FirebaseUI Auth to your app.
In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.
آیاواس
Step 1: Add Firebase to your app
Add the Firebase SDK to your app by running the following commands:
$ cd your-project directory $ pod init $ pod 'Firebase'Open the Firebase console , and select your Identity Toolkit project, which you already imported.
On the Overview page, click Add App , and then click Add Firebase to your iOS app . In the Add Firebase dialog, provide your app's bundle ID and App Store ID, and then click Add App . The
GoogleService-Info.plistconfiguration file is then downloaded to your computer. If you have multiple bundle IDs in your project, each bundle ID must be connected in the Firebase console so it can have its ownGoogleService-Info.plistfile.Copy the configuration file to the root of your Xcode project and add it to all targets.
Step 2: Remove the Identity Toolkit SDK
- Remove
GoogleIdentityToolkitfrom your app's Podfile. - Run the
pod installcommand.
Step 3: Add FirebaseUI to your app
Add FirebaseUI Auth to your app.
In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.
The newest version of Google Identity Toolkit has been released as Firebase Authentication . Going forward, feature work on Identity Toolkit will be frozen and all new feature development will be done on Firebase Authentication. We encourage Identity Toolkit developers to move to Firebase Authentication as soon as is practical for their applications; however, Identity Toolkit continues to work and will not be deprecated without a further announcement.
ویژگیهای جدید
Firebase Authentication already has some significant feature enhancements over Google Identity Toolkit:
Access to all of Firebase
Firebase is a mobile platform that helps you quickly develop high-quality apps, grow your user base, and earn more money. Firebase is made up of complementary features that you can mix-and-match to fit your needs and includes infrastructure for: mobile analytics , cloud messaging , realtime database , file storage , static hosting , remote configuration , mobile crash reporting and Android testing .
Updated UIs
We have completely rebuilt the UI flows based on Google's latest UX research. This includes password recovery, account linking, new/existing account disambiguation flows that often take significant time to code and debug. It integrates Smart Lock for Passwords on Android, which has significantly improved sign-in and sign-up conversion for participating apps . It also supports easy theme modifications to match your application and, for maximum customizability, the Android and iOS versions have been open sourced.
Simplified server setup
We have made it easier for developers to use Firebase Authentication. With Identity Toolkit, we saw that many developers chose not to implement the email recovery flow which made it impossible for their users to recover their accounts if they forgot their password. Firebase Authentication can send email verification, password reset, and changed password messages to the user and the text can be easily customized for your users. Additionally, you no longer need to host the UI widgets for hosting redirects and completing password change operations.
New admin console
Firebase has a new developer console and the Authentication section allows you to view, modify and delete your users. This can be a great help in debugging your sign-in and sign-up flows. The console also allows you to configure authentication methods and customize email templates.
New SDKs
All of Identity Toolkit's server APIs are now available natively with each of our client libraries (Android, iOS, web). Developers will be able to sign in and sign up old and new users, access user properties, link, update and delete accounts, reset passwords, and more without being tied to a fixed UI. If you prefer, you can manually build your own entire sign in flow and experience on top of this API.
Session management for mobile apps
With Identity Toolkit, apps created their own session state based on the initial authentication event from Identity Toolkit. Firebase Auth uses a backend service that takes a refresh token, minted from the authentication event, and exchanges it for hour-long access tokens for Android, iOS and JavaScript. When a user changes their password, refresh tokens will no longer be able to generate new access tokens, thereby disabling access until the user reauthenticates on that device.
Anonymous and GitHub authentication
Firebase Authentication supports two new authentication types: GitHub and anonymous. Anonymous sign-in can be used to create a unique user ID without requiring the user to go through any sign-in or sign-up process. With an anonymous user, you can now make authenticated API calls, like you would with a regular user. When the user decides to sign up for an account, all activity is preserved with the same user ID. This is great for situations like a server side shopping cart or any application where you want to engage the user before sending them through a sign-up flow.
Feature Differences
Some Identity Toolkit features are not currently available in Firebase Authentication, while other features have been redesigned and work differently. You might choose not to migrate immediately if these features are important to your app. In many cases, these features might not be important for your app or there might be easy fallbacks which will enable you to proceed with migration.
Server side differences
The core Identity Toolkit service with its underlying REST APIs, account validation logic, and primary user database have undergone only minor updates. But some features and the manner in which you integrate Firebase Authentication into your service has changed.
ارائه دهندگان هویت
Paypal and AOL are not supported. Users with accounts from these IDPs can still sign in to your application with the password recovery flow and set up a password for their account.
Server libraries
Currently, there are Firebase admin SDKs available for Java, Node.js, Python, Go and C#.
Account management emails
Password reset, email verification, and email change messages can be performed by Firebase or from the developer's own mail server. Currently, Firebase email templates offer only limited customization.
Email address change confirmation
In Identity Toolkit, when a user decides to change their email address, it sends an email to the new address that has a link to continue the email address change flow.
Firebase confirms the email address change by sending a revocation email to the old email address with a link to revert the change.
IDP rollout
Identity Toolkit had an ability to add identity providers to your sign-in system gradually, so that you could experiment with the impact on your support requests. This feature was removed in Firebase Authentication.
Client side differences
In Firebase, the features provided by Google Identity Toolkit are split into two components:
Firebase Authentication SDKs
In Firebase Authentication, the functionality provided by Identity Toolkit's REST API has been packaged in client SDKs available for Android, iOS, and JavaScript. You can use the SDK to sign in and sign up users; access user profile information; link, update and delete accounts; and reset passwords using the client SDK instead of communicating with the back end service via REST calls.
FirebaseUI Auth
All of the UI flows that manage sign-in, sign-up, password recovery, and account linking have been rebuilt using the Frebase Authentication SDKs. They are available as open source SDKs for iOS and Android to enable you to completely customize the flows in ways not possible with Identity Toolkit.
Additional differences include:
Sessions and migration
Because sessions are managed differently in Identity Toolkit and Firebase Authentication, your users' existing sessions will be terminated upon upgrading the SDK, and your users will have to sign in again.
قبل از اینکه شروع کنی
Before you can migrate from Identity Toolkit to Firebase Authentication, you must
Open the Firebase console , click Import Google Project , and select your Identity Toolkit project.
Click settings > Permissions to open the IAM & Admin page.
Open the Service accounts page. Here you can see the service account you previously configured for Identity Toolkit.
Next to the service account, click more_vert > Create key . Then, in the Create private key dialog, set the Key type to JSON and click Create . A JSON file containing your service account's credentials is downloaded for you. You'll need this to initialize the SDK in the next step.
Go back to the Firebase console . In the Auth section, open the Email Templates page. On this page, customize your app's email templates.
In Identity Toolkit, when users reset passwords, changed email addresses and verified email their email addresses, you needed to get an OOB code from the Identity Toolkit server, and then send the code to users through email. Firebase sends emails based on the templates you configure with no additional actions required.
Optional : If you need to access Firebase services on your server, install the Firebase SDK.
You can install the Firebase Node.js module with
npm:$ npm init $ npm install --save firebase-adminIn your code, you can access Firebase using:
var admin = require('firebase-admin'); var app = admin.initializeApp({ credential: admin.credential.cert('path/to/serviceAccountCredentials.json') });
Next, complete the migration steps for your app's platform: Android , iOS , web .
Servers and JavaScript
Notable changes
There are a number of additional differences in the web implementation of Firebase from Identity Toolkit.
Web session management
Previously, when a user authenticated using the Identity Toolkit widget , a cookie was set for the user which was used to bootstrap the session . This cookie had a two week lifetime and was used to allow the user to use the account management widget to change password and email address. Some sites used this cookie to authenticate all other page requests on the site. Other sites used the cookie to create their own cookies via their framework's cookie management system.
Firebase client SDKs now manage Firebase ID tokens and work with Firebase Authentication's backend to keep the session fresh. The backend expires sessions when important account changes (like user password changes) have occurred. Firebase ID tokens are not automatically set as cookies on the web client and have only an hour lifetime. Unless you want sessions of only an hour, Firebase ID tokens are not appropriate to be used as the cookie to validate all of your page requests. Instead, you will need to set up a listener for when the user logs in, get the Firebase ID token , validate the token , and create your own cookie via your framework's cookie management system.
You will need to set the session lifetime of your cookie based on the security needs of your application.
Web sign-in flow
Previously, users were redirected to
accountchooser.comwhen sign-in was initiated to learn what identifier the user wanted to use. Firebase Auth UI's flow now begins with a list of sign-in methods, including an email option which goes toaccountchooser.comfor web and uses the hintRequest API on Android. In addition, email addresses are no longer required in the Firebase UI. This will make it easier to support anonymous users, custom auth users or users from providers where email addresses are not required.Account management widget
This widget provides a UI for users to change email addresses, change password ors unlink their accounts from identity providers. It is currently under development.
Sign-in button/widget
Widgets like the sign-in button and user card are no longer provided. They can be built very easily using the Firebase Authentication API.
No signOutUrl
You will need to call
firebase.auth.signOut()and handle the callback.No oobActionUrl
Email sending is now handled by Firebase and is configured in the Firebase console.
CSS customization
FirebaseUI uses Material Design Lite styling, which dynamically adds Material Design animations.
Step 1: Change Server Code
If your server relies on the Identity Toolkit token (valid for two weeks) to manage web user sessions, you need to convert the server to use its own session cookie.
- Implement an endpoint for validating the Firebase ID token and setting the session cookie for the user. The client app sends the Firebase ID token to this endpoint.
- If the incoming request contains your own session cookie, you can consider the user authenticated. Otherwise, treat the request as unauthenticated.
- If you do not want any of your users to lose their existing logged-in sessions, you should wait for two weeks for all Identity Toolkit tokens to expire, or also do the dual token validation for your web application as described below in step 3.
Next, because the Firebase tokens are different than Identity Toolkit tokens, you must update your token validation logic. Install the Firebase Server SDK to your server; or, if you use a language not supported by the Firebase Server SDK, download a JWT token validation library for your environment and properly validate the token .
When you first make the above updates, you might still have code paths that rely on Identity Toolkit tokens. If you have iOS or Android applications, users will need to upgrade to the new version of the app in order to have the new code paths work. If you don't want to force your users to update your app, you can add additional server validation logic that examines the token and determines whether it needs to use the Firebase SDK or the Identity Toolkit SDK to validate the token. If you only have a web application, all new authentication requests will be shifted over to Firebase and, therefore, you only need to use the Firebase token verification methods.
See the Firebase Web API Reference .
Step 2: Update your HTML
Add the Firebase initialization code to your app:
- Open your project in the Firebase console .
- On the Overview page, click Add App , then click Add Firebase to your web app . A code snippet that initializes Firebase is displayed.
- Copy and paste the initialization snippet into your web page.
Add FirebaseUI Auth to your app:
<script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script> <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" /> <!-- ******************************************************************************************* * TODO(DEVELOPER): Paste the initialization snippet from: * Firebase Console > Overview > Add Firebase to your web app. * ***************************************************************************************** --> <script type="text/javascript"> // FirebaseUI config. var uiConfig = { 'signInSuccessUrl': '<url-to-redirect-to-on-success>', 'signInOptions': [ // Leave the lines as is for the providers you want to offer your users. firebase.auth.GoogleAuthProvider.PROVIDER_ID, firebase.auth.FacebookAuthProvider.PROVIDER_ID, firebase.auth.TwitterAuthProvider.PROVIDER_ID, firebase.auth.GithubAuthProvider.PROVIDER_ID, firebase.auth.EmailAuthProvider.PROVIDER_ID ], // Terms of service url. 'tosUrl': '<your-tos-url>', }; // Initialize the FirebaseUI Widget using Firebase. var ui = new firebaseui.auth.AuthUI(firebase.auth()); // The start method will wait until the DOM is loaded. ui.start('#firebaseui-auth-container', uiConfig); </script>Remove the Identity Toolkit SDK from your app.
If you relied on the Identity Toolkit ID token for session management, you must make the following changes on the client side:
After successfully signing in with Firebase, get a Firebase ID token by calling
firebase.auth().currentUser.getToken().Send the Firebase ID token to the backend server, validate it, and issue your own session cookie.
Do not rely solely on the session cookie when performing sensitive operations or sending authenticated edit requests to your server. You will need to provide additional cross-site request forgery (CSRF) protection.
If your framework does not provide CSRF protection, one way to prevent an attack would be to get a Firebase ID token for the signed-in user with
getToken()and include the token with each request (the session cookie will also be sent by default). You would then validate that token using the Firebase server SDK in addition to the session cookie check, which your backend framework completed. This will make it harder for CSRF attacks to succeed, as the Firebase ID token is only stored using web storage and never in a cookie.Identity Toolkit tokens are valid for two weeks. You may want to continue issuing tokens that last two weeks, or you might want to make it longer or shorter based on the security requirements of your app. When a user signs out, clear the session cookie.
Step 3: Update IDP redirect URLs
In the Firebase console, open the Authentication section and click the Sign-in Method tab.
For each federated sign-in provider you support, do the following:
- Click the name of the sign-in provider.
- Copy the OAuth redirect URI.
- In the sign-in provider's developer console, update the OAuth redirect URI.
اندروید
Step 1: Add Firebase to your app
Open the Firebase console , and select your Identity Toolkit project, which you already imported.
On the Overview page, click Add App , and then click Add Firebase to your Android app . In the Add Firebase dialog, provide your app's package name and signing certificate fingerprint and click Add App . The
google-services.jsonconfiguration file is then downloaded to your computer.Copy the configuration file to your Android app module root directory. This configuration file contains project and Google OAuth client information.
In your Project-level
build.gradlefile (<var>your-project</var>/build.gradle), specify your app's package name in thedefaultConfigsection:defaultConfig { ….. applicationId "com.your-app" }Also in your Project-level
build.gradlefile, add a dependency to include the google-services plugin:buildscript { dependencies { // Add this line classpath 'com.google.gms:google-services:3.0.0' } }In your app's App-level
build.gradlefile (<var>my-project</var>/<var>app-module</var>/build.gradle), add the following line to the bottom to enable the google-services plugin:// Add to the bottom of the file apply plugin: 'com.google.gms.google-services'The google-services plugin uses the
google-services.jsonfile to configure your application to use Firebase.Also in the App-level
build.gradlefile, add the Firebase Authentication dependency:compile 'com.google.firebase:firebase-auth:24.2.0' compile 'com.google.android.gms:play-services-auth:21.6.0'
Step 2: Remove the Identity Toolkit SDK
- Remove the Identity Toolkit configuration from the
AndroidManifest.xmlfile. This information is included in thegoogle-service.jsonfile and loaded by the google-services plugin. - Remove the Identity Toolkit SDK from your app.
Step 3: Add FirebaseUI to your app
Add FirebaseUI Auth to your app.
In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.
آیاواس
Step 1: Add Firebase to your app
Add the Firebase SDK to your app by running the following commands:
$ cd your-project directory $ pod init $ pod 'Firebase'Open the Firebase console , and select your Identity Toolkit project, which you already imported.
On the Overview page, click Add App , and then click Add Firebase to your iOS app . In the Add Firebase dialog, provide your app's bundle ID and App Store ID, and then click Add App . The
GoogleService-Info.plistconfiguration file is then downloaded to your computer. If you have multiple bundle IDs in your project, each bundle ID must be connected in the Firebase console so it can have its ownGoogleService-Info.plistfile.Copy the configuration file to the root of your Xcode project and add it to all targets.
Step 2: Remove the Identity Toolkit SDK
- Remove
GoogleIdentityToolkitfrom your app's Podfile. - Run the
pod installcommand.
Step 3: Add FirebaseUI to your app
Add FirebaseUI Auth to your app.
In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.