از Google Identity Toolkit به Firebase Authentication مهاجرت کنید

جدیدترین نسخه Google Identity Toolkit با نام Firebase Authentication منتشر شده است. از این پس، کار روی ویژگی‌ها روی Identity Toolkit متوقف خواهد شد و تمام توسعه ویژگی‌های جدید روی Firebase Authentication انجام خواهد شد. ما توسعه‌دهندگان Identity Toolkit را تشویق می‌کنیم که در اسرع وقت برای برنامه‌های خود به Firebase Authentication مهاجرت کنند. با این حال، Identity Toolkit همچنان به کار خود ادامه می‌دهد و بدون اعلام بیشتر منسوخ نخواهد شد.

ویژگی‌های جدید

احراز هویت فایربیس در حال حاضر نسبت به ابزار هویت گوگل (Google Identity Toolkit) پیشرفت‌های قابل توجهی در ویژگی‌های خود دارد:

  • دسترسی به تمام فایربیس

    فایربیس یک پلتفرم موبایل است که به شما کمک می‌کند تا به سرعت برنامه‌های با کیفیت بالا توسعه دهید، پایگاه کاربران خود را افزایش دهید و درآمد بیشتری کسب کنید. فایربیس از ویژگی‌های مکملی تشکیل شده است که می‌توانید آن‌ها را با هم ترکیب و مطابقت دهید تا با نیازهای شما مطابقت داشته باشد و شامل زیرساخت‌هایی برای موارد زیر است: تجزیه و تحلیل موبایل، پیام‌رسانی ابری ، پایگاه داده بلادرنگ ، ذخیره‌سازی فایل ، میزبانی استاتیک ، پیکربندی از راه دور ، گزارش خرابی موبایل و آزمایش اندروید.

  • رابط‌های کاربری به‌روز شده

    ما جریان‌های رابط کاربری را بر اساس آخرین تحقیقات تجربه کاربری گوگل، به طور کامل بازسازی کرده‌ایم. این شامل بازیابی رمز عبور، پیوند حساب کاربری، جریان‌های ابهام‌زدایی حساب کاربری جدید/موجود می‌شود که اغلب زمان قابل توجهی برای کدنویسی و اشکال‌زدایی صرف می‌کنند. این برنامه ، قفل هوشمند برای رمزهای عبور در اندروید را ادغام می‌کند که به طور قابل توجهی تبدیل ورود و ثبت نام را برای برنامه‌های شرکت‌کننده بهبود بخشیده است. همچنین از تغییرات آسان تم برای مطابقت با برنامه شما پشتیبانی می‌کند و برای حداکثر قابلیت سفارشی‌سازی، نسخه‌های اندروید و iOS متن‌باز شده‌اند.

  • راه‌اندازی ساده‌شده سرور

    ما استفاده از احراز هویت فایربیس را برای توسعه‌دهندگان آسان‌تر کرده‌ایم. با استفاده از Identity Toolkit، شاهد بودیم که بسیاری از توسعه‌دهندگان تصمیم گرفتند جریان بازیابی ایمیل را پیاده‌سازی نکنند که این امر باعث می‌شد کاربرانشان در صورت فراموش کردن رمز عبور، نتوانند حساب‌های خود را بازیابی کنند. احراز هویت فایربیس می‌تواند پیام‌های تأیید ایمیل، تنظیم مجدد رمز عبور و تغییر رمز عبور را برای کاربر ارسال کند و متن آن را می‌توان به راحتی برای کاربران شما سفارشی کرد . علاوه بر این، دیگر نیازی به میزبانی ویجت‌های رابط کاربری برای میزبانی تغییر مسیرها و تکمیل عملیات تغییر رمز عبور ندارید.

  • کنسول مدیریت جدید

    فایربیس یک کنسول توسعه‌دهنده جدید دارد و بخش احراز هویت به شما امکان مشاهده، تغییر و حذف کاربران را می‌دهد. این می‌تواند کمک بزرگی در اشکال‌زدایی جریان‌های ورود و ثبت‌نام شما باشد. این کنسول همچنین به شما امکان می‌دهد روش‌های احراز هویت را پیکربندی کرده و قالب‌های ایمیل را سفارشی کنید.

  • SDK های جدید

    تمام APIهای سرور Identity Toolkit اکنون به صورت بومی با هر یک از کتابخانه‌های کلاینت ما (اندروید، iOS، وب) در دسترس هستند. توسعه‌دهندگان قادر خواهند بود بدون اتصال به یک رابط کاربری ثابت، کاربران قدیمی و جدید را وارد سیستم کرده و ثبت‌نام کنند، به ویژگی‌های کاربر دسترسی پیدا کنند، حساب‌ها را پیوند دهند، به‌روزرسانی و حذف کنند، رمزهای عبور را بازنشانی کنند و موارد دیگر. در صورت تمایل، می‌توانید کل جریان ورود و تجربه خود را به صورت دستی بر روی این API بسازید.

  • مدیریت نشست برای برنامه‌های تلفن همراه

    با استفاده از Identity Toolkit، برنامه‌ها وضعیت جلسه خود را بر اساس رویداد احراز هویت اولیه از Identity Toolkit ایجاد می‌کردند. Firebase Auth از یک سرویس backend استفاده می‌کند که یک توکن refresh را که از رویداد احراز هویت ایجاد شده است، می‌گیرد و آن را با توکن‌های دسترسی یک ساعته برای اندروید، iOS و جاوا اسکریپت مبادله می‌کند. هنگامی که کاربر رمز عبور خود را تغییر می‌دهد، توکن‌های refresh دیگر قادر به تولید توکن‌های دسترسی جدید نخواهند بود و در نتیجه دسترسی تا زمانی که کاربر در آن دستگاه احراز هویت مجدد کند، غیرفعال می‌شود.

  • احراز هویت ناشناس و گیت‌هاب

    احراز هویت فایربیس از دو نوع احراز هویت جدید پشتیبانی می‌کند: گیت‌هاب و ناشناس. ورود ناشناس می‌تواند برای ایجاد یک شناسه کاربری منحصر به فرد بدون نیاز به طی کردن هرگونه فرآیند ورود یا ثبت‌نام توسط کاربر استفاده شود. با یک کاربر ناشناس، اکنون می‌توانید فراخوانی‌های API احراز هویت شده را مانند یک کاربر معمولی انجام دهید. وقتی کاربر تصمیم به ثبت‌نام برای یک حساب کاربری می‌گیرد، تمام فعالیت‌ها با همان شناسه کاربری ذخیره می‌شوند. این برای موقعیت‌هایی مانند سبد خرید سمت سرور یا هر برنامه‌ای که می‌خواهید کاربر را قبل از ارسال آنها به جریان ثبت‌نام، درگیر کنید، عالی است.

تفاوت‌های ویژگی

برخی از ویژگی‌های Identity Toolkit در حال حاضر در Firebase Authentication موجود نیستند، در حالی که سایر ویژگی‌ها دوباره طراحی شده‌اند و به طور متفاوتی کار می‌کنند. اگر این ویژگی‌ها برای برنامه شما مهم هستند، می‌توانید فوراً مهاجرت نکنید. در بسیاری از موارد، این ویژگی‌ها ممکن است برای برنامه شما مهم نباشند یا ممکن است گزینه‌های جایگزینی وجود داشته باشد که به شما امکان می‌دهد مهاجرت را ادامه دهید.

تفاوت‌های سمت سرور

سرویس اصلی Identity Toolkit با APIهای REST زیربنایی، منطق اعتبارسنجی حساب و پایگاه داده اصلی کاربر، تنها به‌روزرسانی‌های جزئی را پشت سر گذاشته است. اما برخی از ویژگی‌ها و نحوه ادغام احراز هویت Firebase در سرویس شما تغییر کرده است.

  • ارائه دهندگان هویت

    پی‌پال و AOL پشتیبانی نمی‌شوند. کاربرانی که حساب کاربری از این IDPها دارند، همچنان می‌توانند با استفاده از فرآیند بازیابی رمز عبور وارد برنامه شما شوند و برای حساب خود رمز عبور تعیین کنند.

  • کتابخانه‌های سرور

    در حال حاضر، SDK های مدیریت Firebase برای جاوا، Node.js، پایتون، Go و C# در دسترس هستند.

  • ایمیل‌های مدیریت حساب

    پیام‌های بازنشانی رمز عبور، تأیید ایمیل و تغییر ایمیل می‌توانند توسط Firebase یا از طریق سرور ایمیل خود توسعه‌دهنده انجام شوند. در حال حاضر، قالب‌های ایمیل Firebase فقط امکان سفارشی‌سازی محدودی را ارائه می‌دهند.

  • تایید تغییر آدرس ایمیل

    در Identity Toolkit، وقتی کاربری تصمیم به تغییر آدرس ایمیل خود می‌گیرد، ایمیلی به آدرس جدید ارسال می‌شود که حاوی لینکی برای ادامه روند تغییر آدرس ایمیل است.

    فایربیس با ارسال یک ایمیل لغو به آدرس ایمیل قدیمی به همراه لینکی برای بازگرداندن تغییر، تغییر آدرس ایمیل را تأیید می‌کند.

  • اجرای طرح آوارگی داخلی

    Identity Toolkit قابلیتی داشت که به تدریج ارائه‌دهندگان هویت را به سیستم ورود شما اضافه می‌کرد تا بتوانید تأثیر آن را بر درخواست‌های پشتیبانی خود آزمایش کنید. این ویژگی در Firebase Authentication حذف شده است.

اختلافات طرف مشتری

در فایربیس، ویژگی‌های ارائه شده توسط ابزار Google Identity Toolkit به دو بخش تقسیم می‌شوند:

  • SDK های احراز هویت فایربیس

    در احراز هویت فایربیس، قابلیت‌های ارائه شده توسط REST API مربوط به Identity Toolkit در SDKهای کلاینت موجود برای اندروید، iOS و جاوا اسکریپت بسته‌بندی شده‌اند. شما می‌توانید از SDK برای ورود و ثبت‌نام کاربران؛ دسترسی به اطلاعات پروفایل کاربر؛ اتصال، به‌روزرسانی و حذف حساب‌ها؛ و تنظیم مجدد رمزهای عبور با استفاده از SDK کلاینت به جای ارتباط با سرویس بک‌اند از طریق فراخوانی‌های REST استفاده کنید.

  • احراز هویت FirebaseUI

    تمام جریان‌های رابط کاربری که ورود، ثبت‌نام، بازیابی رمز عبور و پیوند حساب را مدیریت می‌کنند، با استفاده از SDKهای احراز هویت Frebase بازسازی شده‌اند. این SDKها به صورت متن‌باز برای iOS و اندروید در دسترس هستند تا شما را قادر سازند جریان‌ها را به طور کامل سفارشی کنید، به روش‌هایی که با Identity Toolkit امکان‌پذیر نیست.

تفاوت‌های اضافی عبارتند از:

  • جلسات و مهاجرت

    از آنجا که جلسات در Identity Toolkit و Firebase Authentication به طور متفاوتی مدیریت می‌شوند، جلسات فعلی کاربران شما پس از ارتقاء SDK خاتمه می‌یابد و کاربران شما باید دوباره وارد سیستم شوند.

قبل از اینکه شروع کنی

قبل از اینکه بتوانید از Identity Toolkit به Firebase Authentication مهاجرت کنید، باید

  1. کنسول فایربیس را باز کنید، روی وارد کردن پروژه گوگل کلیک کنید و پروژه Identity Toolkit خود را انتخاب کنید.

  2. برای باز کردن صفحه IAM & Admin، > مجوزها کلیک کنید.

  3. صفحه حساب‌های سرویس (Service accounts) را باز کنید. در اینجا می‌توانید حساب سرویسی را که قبلاً برای Identity Toolkit پیکربندی کرده‌اید، مشاهده کنید.

  4. در کنار حساب سرویس، روی > Create key کلیک کنید. سپس، در کادر محاوره‌ای Create private key ، نوع کلید را روی JSON تنظیم کنید و روی Create کلیک کنید. یک فایل JSON حاوی اطلاعات حساب سرویس شما دانلود می‌شود. برای مقداردهی اولیه SDK در مرحله بعدی به آن نیاز خواهید داشت.

  5. به کنسول فایربیس برگردید. در بخش Auth، صفحه Email Templates را باز کنید. در این صفحه، قالب‌های ایمیل برنامه خود را سفارشی کنید.

    در Identity Toolkit، وقتی کاربران رمز عبور را تغییر می‌دادند، آدرس ایمیل خود را تغییر می‌دادند و آدرس ایمیل خود را تأیید می‌کردند، شما باید یک کد OOB از سرور Identity Toolkit دریافت می‌کردید و سپس کد را از طریق ایمیل برای کاربران ارسال می‌کردید. Firebase ایمیل‌ها را بر اساس قالب‌هایی که پیکربندی می‌کنید، بدون نیاز به هیچ اقدام اضافی ارسال می‌کند.

  6. اختیاری : اگر نیاز به دسترسی به سرویس‌های Firebase روی سرور خود دارید، Firebase SDK را نصب کنید.

    1. می‌توانید ماژول Firebase Node.js را با npm نصب کنید:

      $ npm init
      $ npm install --save firebase-admin
      
    2. در کد خود، می‌توانید با استفاده از دستور زیر به Firebase دسترسی پیدا کنید:

      var admin = require('firebase-admin');
      var app = admin.initializeApp({
        credential: admin.credential.cert('path/to/serviceAccountCredentials.json')
      });
      

در مرحله بعد، مراحل مهاجرت را برای پلتفرم برنامه خود تکمیل کنید: اندروید ، iOS ، وب .

سرورها و جاوا اسکریپت

تغییرات قابل توجه

تعدادی تفاوت دیگر در پیاده‌سازی وب Firebase از Identity Toolkit وجود دارد.

  • مدیریت جلسه وب

    پیش از این، وقتی کاربری با استفاده از ویجت Identity Toolkit احراز هویت می‌شد، یک کوکی برای کاربر تنظیم می‌شد که برای راه‌اندازی جلسه (session) استفاده می‌شد. این کوکی دو هفته طول عمر داشت و برای این استفاده می‌شد که کاربر بتواند از ویجت مدیریت حساب برای تغییر رمز عبور و آدرس ایمیل استفاده کند. برخی سایت‌ها از این کوکی برای احراز هویت تمام درخواست‌های صفحات دیگر در سایت استفاده می‌کردند. برخی دیگر از سایت‌ها از این کوکی برای ایجاد کوکی‌های خود از طریق سیستم مدیریت کوکی چارچوب خود استفاده می‌کردند.

    کیت‌های توسعه نرم‌افزار (SDK) کلاینت فایربیس اکنون توکن‌های شناسه فایربیس را مدیریت می‌کنند و با بک‌اند احراز هویت فایربیس همکاری می‌کنند تا جلسه را به‌روز نگه دارند. بک‌اند، جلسات را زمانی که تغییرات مهم حساب (مانند تغییر رمز عبور کاربر) رخ می‌دهد، منقضی می‌کند. توکن‌های شناسه فایربیس به‌طور خودکار به‌عنوان کوکی در کلاینت وب تنظیم نمی‌شوند و فقط یک ساعت طول عمر دارند. مگر اینکه بخواهید جلسات فقط یک ساعته داشته باشید، توکن‌های شناسه فایربیس برای استفاده به‌عنوان کوکی جهت اعتبارسنجی تمام درخواست‌های صفحه شما مناسب نیستند. در عوض، باید یک شنونده برای زمانی که کاربر وارد سیستم می‌شود، دریافت توکن شناسه فایربیس ، اعتبارسنجی توکن و ایجاد کوکی خود از طریق سیستم مدیریت کوکی چارچوب خود تنظیم کنید.

    شما باید طول عمر جلسه کوکی خود را بر اساس نیازهای امنیتی برنامه خود تنظیم کنید.

  • جریان ورود به سیستم وب

    پیش از این، کاربران هنگام ورود به سیستم به accountchooser.com هدایت می‌شدند تا بدانند کاربر از چه شناسه‌ای می‌خواهد استفاده کند. روند کار رابط کاربری احراز هویت Firebase اکنون با فهرستی از روش‌های ورود به سیستم آغاز می‌شود، از جمله گزینه ایمیل که برای وب به accountchooser.com می‌رود و از API hintRequest در اندروید استفاده می‌کند. علاوه بر این، آدرس‌های ایمیل دیگر در رابط کاربری Firebase مورد نیاز نیستند. این امر پشتیبانی از کاربران ناشناس، کاربران احراز هویت سفارشی یا کاربران ارائه‌دهندگانی را که در آنها آدرس‌های ایمیل مورد نیاز نیست، آسان‌تر می‌کند.

  • ویجت مدیریت حساب

    این ویجت یک رابط کاربری برای کاربران فراهم می‌کند تا آدرس‌های ایمیل، رمز عبور یا اتصال حساب‌های خود را از ارائه‌دهندگان هویت قطع کنند. این ویجت در حال حاضر در دست توسعه است.

  • دکمه/ویجت ورود

    ویجت‌هایی مانند دکمه ورود و کارت کاربری دیگر ارائه نمی‌شوند. آن‌ها را می‌توان به راحتی با استفاده از API احراز هویت Firebase ساخت.

  • بدون signOutUrl

    شما باید firebase.auth.signOut() را فراخوانی کرده و فراخوانی برگشتی را مدیریت کنید.

  • بدون آدرس اقدام oob

    ارسال ایمیل اکنون توسط Firebase انجام می‌شود و در کنسول Firebase پیکربندی شده است.

  • سفارشی سازی CSS

    FirebaseUI از استایل‌بندی Material Design Lite استفاده می‌کند که به صورت پویا انیمیشن‌های Material Design را اضافه می‌کند.

مرحله ۱: تغییر کد سرور

  1. اگر سرور شما برای مدیریت جلسات کاربران وب به توکن Identity Toolkit (معتبر به مدت دو هفته) متکی است، باید سرور را به گونه‌ای تغییر دهید که از کوکی جلسه مخصوص به خود استفاده کند.

    1. یک نقطه پایانی برای اعتبارسنجی توکن Firebase ID و تنظیم کوکی جلسه برای کاربر پیاده‌سازی کنید. برنامه کلاینت، توکن Firebase ID را به این نقطه پایانی ارسال می‌کند.
    2. اگر درخواست ورودی حاوی کوکی جلسه خودتان باشد، می‌توانید کاربر را احراز هویت شده در نظر بگیرید. در غیر این صورت، درخواست را احراز هویت نشده در نظر بگیرید.
    3. اگر نمی‌خواهید هیچ یک از کاربرانتان جلسات ورود به سیستم فعلی خود را از دست بدهند، باید دو هفته صبر کنید تا تمام توکن‌های Identity Toolkit منقضی شوند، یا اعتبارسنجی توکن دوگانه را برای برنامه وب خود همانطور که در مرحله 3 توضیح داده شده است، انجام دهید.
  2. در مرحله بعد، از آنجا که توکن‌های Firebase با توکن‌های Identity Toolkit متفاوت هستند، باید منطق اعتبارسنجی توکن خود را به‌روزرسانی کنید. کیت توسعه نرم‌افزار Firebase Server را روی سرور خود نصب کنید؛ یا اگر از زبانی استفاده می‌کنید که توسط کیت توسعه نرم‌افزار Firebase Server پشتیبانی نمی‌شود، یک کتابخانه اعتبارسنجی توکن JWT برای محیط خود دانلود کنید و توکن را به درستی اعتبارسنجی کنید .

  3. وقتی برای اولین بار به‌روزرسانی‌های فوق را انجام می‌دهید، ممکن است هنوز مسیرهای کدی داشته باشید که به توکن‌های Identity Toolkit متکی هستند. اگر برنامه‌های iOS یا Android دارید، کاربران باید برای کار کردن مسیرهای کد جدید، برنامه را به نسخه جدید ارتقا دهند. اگر نمی‌خواهید کاربران خود را مجبور به به‌روزرسانی برنامه خود کنید، می‌توانید منطق اعتبارسنجی سرور اضافی اضافه کنید که توکن را بررسی می‌کند و تعیین می‌کند که آیا برای اعتبارسنجی توکن باید از Firebase SDK یا Identity Toolkit SDK استفاده کند. اگر فقط یک برنامه وب دارید، تمام درخواست‌های احراز هویت جدید به Firebase منتقل می‌شوند و بنابراین، فقط باید از روش‌های تأیید توکن Firebase استفاده کنید.

به مرجع API وب فایربیس مراجعه کنید.

مرحله ۲: HTML خود را به‌روزرسانی کنید

  1. کد مقداردهی اولیه Firebase را به برنامه خود اضافه کنید:

    1. پروژه خود را در کنسول Firebase باز کنید.
    2. در صفحه مرور کلی، روی «افزودن برنامه» کلیک کنید، سپس روی «افزودن فایربیس به برنامه وب خود» کلیک کنید. قطعه کدی که فایربیس را مقداردهی اولیه می‌کند نمایش داده می‌شود.
    3. قطعه کد مقداردهی اولیه را کپی کرده و در صفحه وب خود جایگذاری کنید.
  2. FirebaseUI Auth را به برنامه خود اضافه کنید:

    <script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script>
    <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" />
    <!-- *******************************************************************************************
       * TODO(DEVELOPER): Paste the initialization snippet from:
       * Firebase Console > Overview > Add Firebase to your web app. *
       ***************************************************************************************** -->
    <script type="text/javascript">
      // FirebaseUI config.
      var uiConfig = {
        'signInSuccessUrl': '<url-to-redirect-to-on-success>',
        'signInOptions': [
          // Leave the lines as is for the providers you want to offer your users.
          firebase.auth.GoogleAuthProvider.PROVIDER_ID,
          firebase.auth.FacebookAuthProvider.PROVIDER_ID,
          firebase.auth.TwitterAuthProvider.PROVIDER_ID,
          firebase.auth.GithubAuthProvider.PROVIDER_ID,
          firebase.auth.EmailAuthProvider.PROVIDER_ID
        ],
        // Terms of service url.
        'tosUrl': '<your-tos-url>',
      };
    
      // Initialize the FirebaseUI Widget using Firebase.
      var ui = new firebaseui.auth.AuthUI(firebase.auth());
      // The start method will wait until the DOM is loaded.
      ui.start('#firebaseui-auth-container', uiConfig);
    </script>
    
  3. SDK مربوط به Identity Toolkit را از برنامه خود حذف کنید.

  4. اگر برای مدیریت جلسه به توکن ID کیت ابزار هویت (Identity Toolkit ID token) متکی بوده‌اید، باید تغییرات زیر را در سمت کلاینت اعمال کنید:

    1. پس از ورود موفقیت‌آمیز به Firebase، با فراخوانی firebase.auth().currentUser.getToken() یک توکن Firebase ID دریافت کنید.

    2. توکن Firebase ID را به سرور backend ارسال کنید، آن را اعتبارسنجی کنید و کوکی جلسه خود را صادر کنید.

      هنگام انجام عملیات حساس یا ارسال درخواست‌های ویرایش احراز هویت شده به سرور خود، صرفاً به کوکی جلسه (session cookie) تکیه نکنید. شما باید محافظت بیشتری در برابر جعل درخواست بین سایتی (CSRF) ارائه دهید.

      اگر چارچوب شما محافظت در برابر CSRF را ارائه نمی‌دهد، یک راه برای جلوگیری از حمله این است که با استفاده از getToken() یک توکن Firebase ID برای کاربر وارد شده دریافت کنید و توکن را با هر درخواست اضافه کنید (کوکی جلسه نیز به طور پیش‌فرض ارسال می‌شود). سپس آن توکن را علاوه بر بررسی کوکی جلسه که چارچوب backend شما انجام داده است، با استفاده از SDK سرور Firebase اعتبارسنجی می‌کنید. این کار موفقیت حملات CSRF را دشوارتر می‌کند، زیرا توکن Firebase ID فقط با استفاده از ذخیره‌سازی وب ذخیره می‌شود و هرگز در کوکی نیست.

    3. توکن‌های Identity Toolkit به مدت دو هفته اعتبار دارند. شما می‌توانید به صدور توکن‌هایی که دو هفته اعتبار دارند ادامه دهید، یا ممکن است بخواهید بر اساس الزامات امنیتی برنامه خود، مدت زمان آن را طولانی‌تر یا کوتاه‌تر کنید. وقتی کاربر از سیستم خارج می‌شود، کوکی جلسه را پاک کنید.

مرحله ۳: به‌روزرسانی آدرس‌های اینترنتی تغییر مسیر IDP

  1. در کنسول Firebase، بخش Authentication را باز کنید و روی تب Sign-in Method کلیک کنید.

  2. برای هر ارائه‌دهنده ورود به سیستم فدرال که از آن پشتیبانی می‌کنید، موارد زیر را انجام دهید:

    1. روی نام ارائه‌دهنده‌ی ورود به سیستم کلیک کنید.
    2. آدرس اینترنتی تغییر مسیر OAuth را کپی کنید.
    3. در کنسول توسعه‌دهندگان ارائه‌دهنده‌ی ورود به سیستم، آدرس اینترنتی تغییر مسیر OAuth را به‌روزرسانی کنید.

اندروید

مرحله ۱: اضافه کردن فایربیس به برنامه

  1. کنسول فایربیس را باز کنید و پروژه Identity Toolkit خود را که قبلاً وارد کرده‌اید، انتخاب کنید.

  2. در صفحه مرور کلی، روی «افزودن برنامه» کلیک کنید و سپس روی «افزودن فایربیس به برنامه اندروید خود» کلیک کنید. در کادر محاوره‌ای «افزودن فایربیس»، نام بسته برنامه و اثر انگشت گواهی امضای آن را وارد کنید و روی «افزودن برنامه» کلیک کنید. سپس فایل پیکربندی google-services.json در رایانه شما دانلود می‌شود.

  3. فایل پیکربندی را در دایرکتوری ریشه ماژول برنامه اندروید خود کپی کنید. این فایل پیکربندی شامل اطلاعات پروژه و کلاینت Google OAuth است.

  4. در فایل build.gradle سطح پروژه خود ( <var>your-project</var>/build.gradle )، نام بسته برنامه خود را در بخش defaultConfig مشخص کنید:

    defaultConfig {
       …..
      applicationId "com.your-app"
    }
    
  5. همچنین در فایل build.gradle سطح پروژه خود، یک وابستگی برای گنجاندن افزونه google-services اضافه کنید:

    buildscript {
     dependencies {
       // Add this line
       classpath 'com.google.gms:google-services:3.0.0'
     }
    }
    
  6. در فایل app-level build.gradle برنامه‌تان ( <var>my-project</var>/<var>app-module</var>/build.gradle )، خط زیر را به انتهای آن اضافه کنید تا افزونه google-services فعال شود:

    // Add to the bottom of the file
    apply plugin: 'com.google.gms.google-services'
    

    افزونه‌ی google-services از فایل google-services.json برای پیکربندی برنامه‌ی شما جهت استفاده از Firebase استفاده می‌کند.

  7. همچنین در فایل build.gradle سطح App، وابستگی Firebase Authentication را اضافه کنید:

    compile 'com.google.firebase:firebase-auth:24.2.0'
    compile 'com.google.android.gms:play-services-auth:21.6.0'
    

مرحله ۲: حذف SDK مربوط به Identity Toolkit

  1. پیکربندی Identity Toolkit را از فایل AndroidManifest.xml حذف کنید. این اطلاعات در فایل google-service.json قرار دارد و توسط افزونه google-services بارگذاری می‌شود.
  2. SDK مربوط به Identity Toolkit را از برنامه خود حذف کنید.

مرحله ۳: FirebaseUI را به برنامه خود اضافه کنید

  1. FirebaseUI Auth را به برنامه خود اضافه کنید.

  2. در برنامه خود، فراخوانی‌های مربوط به Identity Toolkit SDK را با فراخوانی‌های مربوط به FirebaseUI جایگزین کنید.

آی‌او‌اس

مرحله ۱: اضافه کردن فایربیس به برنامه

  1. با اجرای دستورات زیر، Firebase SDK را به برنامه خود اضافه کنید:

    $ cd your-project directory
    $ pod init
    $ pod 'Firebase'
    
  2. کنسول فایربیس را باز کنید و پروژه Identity Toolkit خود را که قبلاً وارد کرده‌اید، انتخاب کنید.

  3. در صفحه مرور کلی، روی افزودن برنامه کلیک کنید و سپس روی افزودن Firebase به برنامه iOS خود کلیک کنید. در کادر محاوره‌ای افزودن Firebase، شناسه بسته نرم‌افزاری و شناسه فروشگاه برنامه خود را وارد کنید و سپس روی افزودن برنامه کلیک کنید. سپس فایل پیکربندی GoogleService-Info.plist در رایانه شما دانلود می‌شود. اگر چندین شناسه بسته نرم‌افزاری در پروژه خود دارید، هر شناسه بسته نرم‌افزاری باید در کنسول Firebase متصل شود تا بتواند فایل GoogleService-Info.plist مخصوص به خود را داشته باشد.

  4. فایل پیکربندی را در ریشه پروژه Xcode خود کپی کنید و آن را به همه targetها اضافه کنید.

مرحله ۲: حذف SDK مربوط به Identity Toolkit

  1. GoogleIdentityToolkit از Podfile برنامه خود حذف کنید.
  2. دستور pod install را اجرا کنید.

مرحله ۳: FirebaseUI را به برنامه خود اضافه کنید

  1. FirebaseUI Auth را به برنامه خود اضافه کنید.

  2. در برنامه خود، فراخوانی‌های مربوط به Identity Toolkit SDK را با فراخوانی‌های مربوط به FirebaseUI جایگزین کنید.

،

جدیدترین نسخه Google Identity Toolkit با نام Firebase Authentication منتشر شده است. از این پس، کار روی ویژگی‌ها روی Identity Toolkit متوقف خواهد شد و تمام توسعه ویژگی‌های جدید روی Firebase Authentication انجام خواهد شد. ما توسعه‌دهندگان Identity Toolkit را تشویق می‌کنیم که در اسرع وقت برای برنامه‌های خود به Firebase Authentication مهاجرت کنند. با این حال، Identity Toolkit همچنان به کار خود ادامه می‌دهد و بدون اعلام بیشتر منسوخ نخواهد شد.

ویژگی‌های جدید

احراز هویت فایربیس در حال حاضر نسبت به ابزار هویت گوگل (Google Identity Toolkit) پیشرفت‌های قابل توجهی در ویژگی‌های خود دارد:

  • دسترسی به تمام فایربیس

    فایربیس یک پلتفرم موبایل است که به شما کمک می‌کند تا به سرعت برنامه‌های با کیفیت بالا توسعه دهید، پایگاه کاربران خود را افزایش دهید و درآمد بیشتری کسب کنید. فایربیس از ویژگی‌های مکملی تشکیل شده است که می‌توانید آن‌ها را با هم ترکیب و مطابقت دهید تا با نیازهای شما مطابقت داشته باشد و شامل زیرساخت‌هایی برای موارد زیر است: تجزیه و تحلیل موبایل، پیام‌رسانی ابری ، پایگاه داده بلادرنگ ، ذخیره‌سازی فایل ، میزبانی استاتیک ، پیکربندی از راه دور ، گزارش خرابی موبایل و آزمایش اندروید.

  • رابط‌های کاربری به‌روز شده

    ما جریان‌های رابط کاربری را بر اساس آخرین تحقیقات تجربه کاربری گوگل، به طور کامل بازسازی کرده‌ایم. این شامل بازیابی رمز عبور، پیوند حساب کاربری، جریان‌های ابهام‌زدایی حساب کاربری جدید/موجود می‌شود که اغلب زمان قابل توجهی برای کدنویسی و اشکال‌زدایی صرف می‌کنند. این برنامه ، قفل هوشمند برای رمزهای عبور در اندروید را ادغام می‌کند که به طور قابل توجهی تبدیل ورود و ثبت نام را برای برنامه‌های شرکت‌کننده بهبود بخشیده است. همچنین از تغییرات آسان تم برای مطابقت با برنامه شما پشتیبانی می‌کند و برای حداکثر قابلیت سفارشی‌سازی، نسخه‌های اندروید و iOS متن‌باز شده‌اند.

  • راه‌اندازی ساده‌شده سرور

    ما استفاده از احراز هویت فایربیس را برای توسعه‌دهندگان آسان‌تر کرده‌ایم. با استفاده از Identity Toolkit، شاهد بودیم که بسیاری از توسعه‌دهندگان تصمیم گرفتند جریان بازیابی ایمیل را پیاده‌سازی نکنند که این امر باعث می‌شد کاربرانشان در صورت فراموش کردن رمز عبور، نتوانند حساب‌های خود را بازیابی کنند. احراز هویت فایربیس می‌تواند پیام‌های تأیید ایمیل، تنظیم مجدد رمز عبور و تغییر رمز عبور را برای کاربر ارسال کند و متن آن را می‌توان به راحتی برای کاربران شما سفارشی کرد . علاوه بر این، دیگر نیازی به میزبانی ویجت‌های رابط کاربری برای میزبانی تغییر مسیرها و تکمیل عملیات تغییر رمز عبور ندارید.

  • کنسول مدیریت جدید

    فایربیس یک کنسول توسعه‌دهنده جدید دارد و بخش احراز هویت به شما امکان مشاهده، تغییر و حذف کاربران را می‌دهد. این می‌تواند کمک بزرگی در اشکال‌زدایی جریان‌های ورود و ثبت‌نام شما باشد. این کنسول همچنین به شما امکان می‌دهد روش‌های احراز هویت را پیکربندی کرده و قالب‌های ایمیل را سفارشی کنید.

  • SDK های جدید

    تمام APIهای سرور Identity Toolkit اکنون به صورت بومی با هر یک از کتابخانه‌های کلاینت ما (اندروید، iOS، وب) در دسترس هستند. توسعه‌دهندگان قادر خواهند بود بدون اتصال به یک رابط کاربری ثابت، کاربران قدیمی و جدید را وارد سیستم کرده و ثبت‌نام کنند، به ویژگی‌های کاربر دسترسی پیدا کنند، حساب‌ها را پیوند دهند، به‌روزرسانی و حذف کنند، رمزهای عبور را بازنشانی کنند و موارد دیگر. در صورت تمایل، می‌توانید کل جریان ورود و تجربه خود را به صورت دستی بر روی این API بسازید.

  • مدیریت نشست برای برنامه‌های تلفن همراه

    با استفاده از Identity Toolkit، برنامه‌ها وضعیت جلسه خود را بر اساس رویداد احراز هویت اولیه از Identity Toolkit ایجاد می‌کردند. Firebase Auth از یک سرویس backend استفاده می‌کند که یک توکن refresh را که از رویداد احراز هویت ایجاد شده است، می‌گیرد و آن را با توکن‌های دسترسی یک ساعته برای اندروید، iOS و جاوا اسکریپت مبادله می‌کند. هنگامی که کاربر رمز عبور خود را تغییر می‌دهد، توکن‌های refresh دیگر قادر به تولید توکن‌های دسترسی جدید نخواهند بود و در نتیجه دسترسی تا زمانی که کاربر در آن دستگاه احراز هویت مجدد کند، غیرفعال می‌شود.

  • احراز هویت ناشناس و گیت‌هاب

    احراز هویت فایربیس از دو نوع احراز هویت جدید پشتیبانی می‌کند: گیت‌هاب و ناشناس. ورود ناشناس می‌تواند برای ایجاد یک شناسه کاربری منحصر به فرد بدون نیاز به طی کردن هرگونه فرآیند ورود یا ثبت‌نام توسط کاربر استفاده شود. با یک کاربر ناشناس، اکنون می‌توانید فراخوانی‌های API احراز هویت شده را مانند یک کاربر معمولی انجام دهید. وقتی کاربر تصمیم به ثبت‌نام برای یک حساب کاربری می‌گیرد، تمام فعالیت‌ها با همان شناسه کاربری ذخیره می‌شوند. این برای موقعیت‌هایی مانند سبد خرید سمت سرور یا هر برنامه‌ای که می‌خواهید کاربر را قبل از ارسال آنها به جریان ثبت‌نام، درگیر کنید، عالی است.

تفاوت‌های ویژگی

برخی از ویژگی‌های Identity Toolkit در حال حاضر در Firebase Authentication موجود نیستند، در حالی که سایر ویژگی‌ها دوباره طراحی شده‌اند و به طور متفاوتی کار می‌کنند. اگر این ویژگی‌ها برای برنامه شما مهم هستند، می‌توانید فوراً مهاجرت نکنید. در بسیاری از موارد، این ویژگی‌ها ممکن است برای برنامه شما مهم نباشند یا ممکن است گزینه‌های جایگزینی وجود داشته باشد که به شما امکان می‌دهد مهاجرت را ادامه دهید.

تفاوت‌های سمت سرور

سرویس اصلی Identity Toolkit با APIهای REST زیربنایی، منطق اعتبارسنجی حساب و پایگاه داده اصلی کاربر، تنها به‌روزرسانی‌های جزئی را پشت سر گذاشته است. اما برخی از ویژگی‌ها و نحوه ادغام احراز هویت Firebase در سرویس شما تغییر کرده است.

  • ارائه دهندگان هویت

    پی‌پال و AOL پشتیبانی نمی‌شوند. کاربرانی که حساب کاربری از این IDPها دارند، همچنان می‌توانند با استفاده از فرآیند بازیابی رمز عبور وارد برنامه شما شوند و برای حساب خود رمز عبور تعیین کنند.

  • کتابخانه‌های سرور

    در حال حاضر، SDK های مدیریت Firebase برای جاوا، Node.js، پایتون، Go و C# در دسترس هستند.

  • ایمیل‌های مدیریت حساب

    پیام‌های بازنشانی رمز عبور، تأیید ایمیل و تغییر ایمیل می‌توانند توسط Firebase یا از طریق سرور ایمیل خود توسعه‌دهنده انجام شوند. در حال حاضر، قالب‌های ایمیل Firebase فقط امکان سفارشی‌سازی محدودی را ارائه می‌دهند.

  • تایید تغییر آدرس ایمیل

    در Identity Toolkit، وقتی کاربری تصمیم به تغییر آدرس ایمیل خود می‌گیرد، ایمیلی به آدرس جدید ارسال می‌شود که حاوی لینکی برای ادامه روند تغییر آدرس ایمیل است.

    فایربیس با ارسال یک ایمیل لغو به آدرس ایمیل قدیمی به همراه لینکی برای بازگرداندن تغییر، تغییر آدرس ایمیل را تأیید می‌کند.

  • اجرای طرح آوارگی داخلی

    Identity Toolkit قابلیتی داشت که به تدریج ارائه‌دهندگان هویت را به سیستم ورود شما اضافه می‌کرد تا بتوانید تأثیر آن را بر درخواست‌های پشتیبانی خود آزمایش کنید. این ویژگی در Firebase Authentication حذف شده است.

اختلافات طرف مشتری

در فایربیس، ویژگی‌های ارائه شده توسط ابزار Google Identity Toolkit به دو بخش تقسیم می‌شوند:

  • SDK های احراز هویت فایربیس

    در احراز هویت فایربیس، قابلیت‌های ارائه شده توسط REST API مربوط به Identity Toolkit در SDKهای کلاینت موجود برای اندروید، iOS و جاوا اسکریپت بسته‌بندی شده‌اند. شما می‌توانید از SDK برای ورود و ثبت‌نام کاربران؛ دسترسی به اطلاعات پروفایل کاربر؛ اتصال، به‌روزرسانی و حذف حساب‌ها؛ و تنظیم مجدد رمزهای عبور با استفاده از SDK کلاینت به جای ارتباط با سرویس بک‌اند از طریق فراخوانی‌های REST استفاده کنید.

  • احراز هویت FirebaseUI

    تمام جریان‌های رابط کاربری که ورود، ثبت‌نام، بازیابی رمز عبور و پیوند حساب را مدیریت می‌کنند، با استفاده از SDKهای احراز هویت Frebase بازسازی شده‌اند. این SDKها به صورت متن‌باز برای iOS و اندروید در دسترس هستند تا شما را قادر سازند جریان‌ها را به طور کامل سفارشی کنید، به روش‌هایی که با Identity Toolkit امکان‌پذیر نیست.

تفاوت‌های اضافی عبارتند از:

  • جلسات و مهاجرت

    از آنجا که جلسات در Identity Toolkit و Firebase Authentication به طور متفاوتی مدیریت می‌شوند، جلسات فعلی کاربران شما پس از ارتقاء SDK خاتمه می‌یابد و کاربران شما باید دوباره وارد سیستم شوند.

قبل از اینکه شروع کنی

قبل از اینکه بتوانید از Identity Toolkit به Firebase Authentication مهاجرت کنید، باید

  1. کنسول فایربیس را باز کنید، روی وارد کردن پروژه گوگل کلیک کنید و پروژه Identity Toolkit خود را انتخاب کنید.

  2. برای باز کردن صفحه IAM & Admin، > مجوزها کلیک کنید.

  3. صفحه حساب‌های سرویس (Service accounts) را باز کنید. در اینجا می‌توانید حساب سرویسی را که قبلاً برای Identity Toolkit پیکربندی کرده‌اید، مشاهده کنید.

  4. در کنار حساب سرویس، روی > Create key کلیک کنید. سپس، در کادر محاوره‌ای Create private key ، نوع کلید را روی JSON تنظیم کنید و روی Create کلیک کنید. یک فایل JSON حاوی اطلاعات حساب سرویس شما دانلود می‌شود. برای مقداردهی اولیه SDK در مرحله بعدی به آن نیاز خواهید داشت.

  5. به کنسول فایربیس برگردید. در بخش Auth، صفحه Email Templates را باز کنید. در این صفحه، قالب‌های ایمیل برنامه خود را سفارشی کنید.

    در Identity Toolkit، وقتی کاربران رمز عبور را تغییر می‌دادند، آدرس ایمیل خود را تغییر می‌دادند و آدرس ایمیل خود را تأیید می‌کردند، شما باید یک کد OOB از سرور Identity Toolkit دریافت می‌کردید و سپس کد را از طریق ایمیل برای کاربران ارسال می‌کردید. Firebase ایمیل‌ها را بر اساس قالب‌هایی که پیکربندی می‌کنید، بدون نیاز به هیچ اقدام اضافی ارسال می‌کند.

  6. اختیاری : اگر نیاز به دسترسی به سرویس‌های Firebase روی سرور خود دارید، Firebase SDK را نصب کنید.

    1. می‌توانید ماژول Firebase Node.js را با npm نصب کنید:

      $ npm init
      $ npm install --save firebase-admin
      
    2. در کد خود، می‌توانید با استفاده از دستور زیر به Firebase دسترسی پیدا کنید:

      var admin = require('firebase-admin');
      var app = admin.initializeApp({
        credential: admin.credential.cert('path/to/serviceAccountCredentials.json')
      });
      

در مرحله بعد، مراحل مهاجرت را برای پلتفرم برنامه خود تکمیل کنید: اندروید ، iOS ، وب .

سرورها و جاوا اسکریپت

تغییرات قابل توجه

تعدادی تفاوت دیگر در پیاده‌سازی وب Firebase از Identity Toolkit وجود دارد.

  • مدیریت جلسه وب

    پیش از این، وقتی کاربری با استفاده از ویجت Identity Toolkit احراز هویت می‌شد، یک کوکی برای کاربر تنظیم می‌شد که برای راه‌اندازی جلسه (session) استفاده می‌شد. این کوکی دو هفته طول عمر داشت و برای این استفاده می‌شد که کاربر بتواند از ویجت مدیریت حساب برای تغییر رمز عبور و آدرس ایمیل استفاده کند. برخی سایت‌ها از این کوکی برای احراز هویت تمام درخواست‌های صفحات دیگر در سایت استفاده می‌کردند. برخی دیگر از سایت‌ها از این کوکی برای ایجاد کوکی‌های خود از طریق سیستم مدیریت کوکی چارچوب خود استفاده می‌کردند.

    کیت‌های توسعه نرم‌افزار (SDK) کلاینت فایربیس اکنون توکن‌های شناسه فایربیس را مدیریت می‌کنند و با بک‌اند احراز هویت فایربیس همکاری می‌کنند تا جلسه را به‌روز نگه دارند. بک‌اند، جلسات را زمانی که تغییرات مهم حساب (مانند تغییر رمز عبور کاربر) رخ می‌دهد، منقضی می‌کند. توکن‌های شناسه فایربیس به‌طور خودکار به‌عنوان کوکی در کلاینت وب تنظیم نمی‌شوند و فقط یک ساعت طول عمر دارند. مگر اینکه بخواهید جلسات فقط یک ساعته داشته باشید، توکن‌های شناسه فایربیس برای استفاده به‌عنوان کوکی جهت اعتبارسنجی تمام درخواست‌های صفحه شما مناسب نیستند. در عوض، باید یک شنونده برای زمانی که کاربر وارد سیستم می‌شود، دریافت توکن شناسه فایربیس ، اعتبارسنجی توکن و ایجاد کوکی خود از طریق سیستم مدیریت کوکی چارچوب خود تنظیم کنید.

    شما باید طول عمر جلسه کوکی خود را بر اساس نیازهای امنیتی برنامه خود تنظیم کنید.

  • جریان ورود به سیستم وب

    پیش از این، کاربران هنگام ورود به سیستم به accountchooser.com هدایت می‌شدند تا بدانند کاربر از چه شناسه‌ای می‌خواهد استفاده کند. روند کار رابط کاربری احراز هویت Firebase اکنون با فهرستی از روش‌های ورود به سیستم آغاز می‌شود، از جمله گزینه ایمیل که برای وب به accountchooser.com می‌رود و از API hintRequest در اندروید استفاده می‌کند. علاوه بر این، آدرس‌های ایمیل دیگر در رابط کاربری Firebase مورد نیاز نیستند. این امر پشتیبانی از کاربران ناشناس، کاربران احراز هویت سفارشی یا کاربران ارائه‌دهندگانی را که در آنها آدرس‌های ایمیل مورد نیاز نیست، آسان‌تر می‌کند.

  • ویجت مدیریت حساب

    این ویجت یک رابط کاربری برای کاربران فراهم می‌کند تا آدرس‌های ایمیل، رمز عبور یا اتصال حساب‌های خود را از ارائه‌دهندگان هویت قطع کنند. این ویجت در حال حاضر در دست توسعه است.

  • دکمه/ویجت ورود

    ویجت‌هایی مانند دکمه ورود و کارت کاربری دیگر ارائه نمی‌شوند. آن‌ها را می‌توان به راحتی با استفاده از API احراز هویت Firebase ساخت.

  • بدون signOutUrl

    شما باید firebase.auth.signOut() را فراخوانی کرده و فراخوانی برگشتی را مدیریت کنید.

  • بدون آدرس اقدام oob

    ارسال ایمیل اکنون توسط Firebase انجام می‌شود و در کنسول Firebase پیکربندی شده است.

  • سفارشی سازی CSS

    FirebaseUI از استایل‌بندی Material Design Lite استفاده می‌کند که به صورت پویا انیمیشن‌های Material Design را اضافه می‌کند.

مرحله ۱: تغییر کد سرور

  1. اگر سرور شما برای مدیریت جلسات کاربران وب به توکن Identity Toolkit (معتبر به مدت دو هفته) متکی است، باید سرور را به گونه‌ای تغییر دهید که از کوکی جلسه مخصوص به خود استفاده کند.

    1. یک نقطه پایانی برای اعتبارسنجی توکن Firebase ID و تنظیم کوکی جلسه برای کاربر پیاده‌سازی کنید. برنامه کلاینت، توکن Firebase ID را به این نقطه پایانی ارسال می‌کند.
    2. اگر درخواست ورودی حاوی کوکی جلسه خودتان باشد، می‌توانید کاربر را احراز هویت شده در نظر بگیرید. در غیر این صورت، درخواست را احراز هویت نشده در نظر بگیرید.
    3. اگر نمی‌خواهید هیچ یک از کاربرانتان جلسات ورود به سیستم فعلی خود را از دست بدهند، باید دو هفته صبر کنید تا تمام توکن‌های Identity Toolkit منقضی شوند، یا اعتبارسنجی توکن دوگانه را برای برنامه وب خود همانطور که در مرحله 3 توضیح داده شده است، انجام دهید.
  2. در مرحله بعد، از آنجا که توکن‌های Firebase با توکن‌های Identity Toolkit متفاوت هستند، باید منطق اعتبارسنجی توکن خود را به‌روزرسانی کنید. کیت توسعه نرم‌افزار Firebase Server را روی سرور خود نصب کنید؛ یا اگر از زبانی استفاده می‌کنید که توسط کیت توسعه نرم‌افزار Firebase Server پشتیبانی نمی‌شود، یک کتابخانه اعتبارسنجی توکن JWT برای محیط خود دانلود کنید و توکن را به درستی اعتبارسنجی کنید .

  3. وقتی برای اولین بار به‌روزرسانی‌های فوق را انجام می‌دهید، ممکن است هنوز مسیرهای کدی داشته باشید که به توکن‌های Identity Toolkit متکی هستند. اگر برنامه‌های iOS یا Android دارید، کاربران باید برای کار کردن مسیرهای کد جدید، برنامه را به نسخه جدید ارتقا دهند. اگر نمی‌خواهید کاربران خود را مجبور به به‌روزرسانی برنامه خود کنید، می‌توانید منطق اعتبارسنجی سرور اضافی اضافه کنید که توکن را بررسی می‌کند و تعیین می‌کند که آیا برای اعتبارسنجی توکن باید از Firebase SDK یا Identity Toolkit SDK استفاده کند. اگر فقط یک برنامه وب دارید، تمام درخواست‌های احراز هویت جدید به Firebase منتقل می‌شوند و بنابراین، فقط باید از روش‌های تأیید توکن Firebase استفاده کنید.

به مرجع API وب فایربیس مراجعه کنید.

مرحله ۲: HTML خود را به‌روزرسانی کنید

  1. Add the Firebase initialization code to your app:

    1. Open your project in the Firebase console .
    2. On the Overview page, click Add App , then click Add Firebase to your web app . A code snippet that initializes Firebase is displayed.
    3. Copy and paste the initialization snippet into your web page.
  2. Add FirebaseUI Auth to your app:

    <script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script>
    <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" />
    <!-- *******************************************************************************************
       * TODO(DEVELOPER): Paste the initialization snippet from:
       * Firebase Console > Overview > Add Firebase to your web app. *
       ***************************************************************************************** -->
    <script type="text/javascript">
      // FirebaseUI config.
      var uiConfig = {
        'signInSuccessUrl': '<url-to-redirect-to-on-success>',
        'signInOptions': [
          // Leave the lines as is for the providers you want to offer your users.
          firebase.auth.GoogleAuthProvider.PROVIDER_ID,
          firebase.auth.FacebookAuthProvider.PROVIDER_ID,
          firebase.auth.TwitterAuthProvider.PROVIDER_ID,
          firebase.auth.GithubAuthProvider.PROVIDER_ID,
          firebase.auth.EmailAuthProvider.PROVIDER_ID
        ],
        // Terms of service url.
        'tosUrl': '<your-tos-url>',
      };
    
      // Initialize the FirebaseUI Widget using Firebase.
      var ui = new firebaseui.auth.AuthUI(firebase.auth());
      // The start method will wait until the DOM is loaded.
      ui.start('#firebaseui-auth-container', uiConfig);
    </script>
    
  3. Remove the Identity Toolkit SDK from your app.

  4. If you relied on the Identity Toolkit ID token for session management, you must make the following changes on the client side:

    1. After successfully signing in with Firebase, get a Firebase ID token by calling firebase.auth().currentUser.getToken() .

    2. Send the Firebase ID token to the backend server, validate it, and issue your own session cookie.

      Do not rely solely on the session cookie when performing sensitive operations or sending authenticated edit requests to your server. You will need to provide additional cross-site request forgery (CSRF) protection.

      If your framework does not provide CSRF protection, one way to prevent an attack would be to get a Firebase ID token for the signed-in user with getToken() and include the token with each request (the session cookie will also be sent by default). You would then validate that token using the Firebase server SDK in addition to the session cookie check, which your backend framework completed. This will make it harder for CSRF attacks to succeed, as the Firebase ID token is only stored using web storage and never in a cookie.

    3. Identity Toolkit tokens are valid for two weeks. You may want to continue issuing tokens that last two weeks, or you might want to make it longer or shorter based on the security requirements of your app. When a user signs out, clear the session cookie.

Step 3: Update IDP redirect URLs

  1. In the Firebase console, open the Authentication section and click the Sign-in Method tab.

  2. For each federated sign-in provider you support, do the following:

    1. Click the name of the sign-in provider.
    2. Copy the OAuth redirect URI.
    3. In the sign-in provider's developer console, update the OAuth redirect URI.

اندروید

Step 1: Add Firebase to your app

  1. Open the Firebase console , and select your Identity Toolkit project, which you already imported.

  2. On the Overview page, click Add App , and then click Add Firebase to your Android app . In the Add Firebase dialog, provide your app's package name and signing certificate fingerprint and click Add App . The google-services.json configuration file is then downloaded to your computer.

  3. Copy the configuration file to your Android app module root directory. This configuration file contains project and Google OAuth client information.

  4. In your Project-level build.gradle file ( <var>your-project</var>/build.gradle ), specify your app's package name in the defaultConfig section:

    defaultConfig {
       …..
      applicationId "com.your-app"
    }
    
  5. Also in your Project-level build.gradle file, add a dependency to include the google-services plugin:

    buildscript {
     dependencies {
       // Add this line
       classpath 'com.google.gms:google-services:3.0.0'
     }
    }
    
  6. In your app's App-level build.gradle file ( <var>my-project</var>/<var>app-module</var>/build.gradle ), add the following line to the bottom to enable the google-services plugin:

    // Add to the bottom of the file
    apply plugin: 'com.google.gms.google-services'
    

    The google-services plugin uses the google-services.json file to configure your application to use Firebase.

  7. Also in the App-level build.gradle file, add the Firebase Authentication dependency:

    compile 'com.google.firebase:firebase-auth:24.2.0'
    compile 'com.google.android.gms:play-services-auth:21.6.0'
    

Step 2: Remove the Identity Toolkit SDK

  1. Remove the Identity Toolkit configuration from the AndroidManifest.xml file. This information is included in the google-service.json file and loaded by the google-services plugin.
  2. Remove the Identity Toolkit SDK from your app.

Step 3: Add FirebaseUI to your app

  1. Add FirebaseUI Auth to your app.

  2. In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.

آی‌او‌اس

Step 1: Add Firebase to your app

  1. Add the Firebase SDK to your app by running the following commands:

    $ cd your-project directory
    $ pod init
    $ pod 'Firebase'
    
  2. Open the Firebase console , and select your Identity Toolkit project, which you already imported.

  3. On the Overview page, click Add App , and then click Add Firebase to your iOS app . In the Add Firebase dialog, provide your app's bundle ID and App Store ID, and then click Add App . The GoogleService-Info.plist configuration file is then downloaded to your computer. If you have multiple bundle IDs in your project, each bundle ID must be connected in the Firebase console so it can have its own GoogleService-Info.plist file.

  4. Copy the configuration file to the root of your Xcode project and add it to all targets.

Step 2: Remove the Identity Toolkit SDK

  1. Remove GoogleIdentityToolkit from your app's Podfile.
  2. Run the pod install command.

Step 3: Add FirebaseUI to your app

  1. Add FirebaseUI Auth to your app.

  2. In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.

،

The newest version of Google Identity Toolkit has been released as Firebase Authentication . Going forward, feature work on Identity Toolkit will be frozen and all new feature development will be done on Firebase Authentication. We encourage Identity Toolkit developers to move to Firebase Authentication as soon as is practical for their applications; however, Identity Toolkit continues to work and will not be deprecated without a further announcement.

ویژگی‌های جدید

Firebase Authentication already has some significant feature enhancements over Google Identity Toolkit:

  • Access to all of Firebase

    Firebase is a mobile platform that helps you quickly develop high-quality apps, grow your user base, and earn more money. Firebase is made up of complementary features that you can mix-and-match to fit your needs and includes infrastructure for: mobile analytics , cloud messaging , realtime database , file storage , static hosting , remote configuration , mobile crash reporting and Android testing .

  • Updated UIs

    We have completely rebuilt the UI flows based on Google's latest UX research. This includes password recovery, account linking, new/existing account disambiguation flows that often take significant time to code and debug. It integrates Smart Lock for Passwords on Android, which has significantly improved sign-in and sign-up conversion for participating apps . It also supports easy theme modifications to match your application and, for maximum customizability, the Android and iOS versions have been open sourced.

  • Simplified server setup

    We have made it easier for developers to use Firebase Authentication. With Identity Toolkit, we saw that many developers chose not to implement the email recovery flow which made it impossible for their users to recover their accounts if they forgot their password. Firebase Authentication can send email verification, password reset, and changed password messages to the user and the text can be easily customized for your users. Additionally, you no longer need to host the UI widgets for hosting redirects and completing password change operations.

  • New admin console

    Firebase has a new developer console and the Authentication section allows you to view, modify and delete your users. This can be a great help in debugging your sign-in and sign-up flows. The console also allows you to configure authentication methods and customize email templates.

  • New SDKs

    All of Identity Toolkit's server APIs are now available natively with each of our client libraries (Android, iOS, web). Developers will be able to sign in and sign up old and new users, access user properties, link, update and delete accounts, reset passwords, and more without being tied to a fixed UI. If you prefer, you can manually build your own entire sign in flow and experience on top of this API.

  • Session management for mobile apps

    With Identity Toolkit, apps created their own session state based on the initial authentication event from Identity Toolkit. Firebase Auth uses a backend service that takes a refresh token, minted from the authentication event, and exchanges it for hour-long access tokens for Android, iOS and JavaScript. When a user changes their password, refresh tokens will no longer be able to generate new access tokens, thereby disabling access until the user reauthenticates on that device.

  • Anonymous and GitHub authentication

    Firebase Authentication supports two new authentication types: GitHub and anonymous. Anonymous sign-in can be used to create a unique user ID without requiring the user to go through any sign-in or sign-up process. With an anonymous user, you can now make authenticated API calls, like you would with a regular user. When the user decides to sign up for an account, all activity is preserved with the same user ID. This is great for situations like a server side shopping cart or any application where you want to engage the user before sending them through a sign-up flow.

Feature Differences

Some Identity Toolkit features are not currently available in Firebase Authentication, while other features have been redesigned and work differently. You might choose not to migrate immediately if these features are important to your app. In many cases, these features might not be important for your app or there might be easy fallbacks which will enable you to proceed with migration.

Server side differences

The core Identity Toolkit service with its underlying REST APIs, account validation logic, and primary user database have undergone only minor updates. But some features and the manner in which you integrate Firebase Authentication into your service has changed.

  • ارائه دهندگان هویت

    Paypal and AOL are not supported. Users with accounts from these IDPs can still sign in to your application with the password recovery flow and set up a password for their account.

  • Server libraries

    Currently, there are Firebase admin SDKs available for Java, Node.js, Python, Go and C#.

  • Account management emails

    Password reset, email verification, and email change messages can be performed by Firebase or from the developer's own mail server. Currently, Firebase email templates offer only limited customization.

  • Email address change confirmation

    In Identity Toolkit, when a user decides to change their email address, it sends an email to the new address that has a link to continue the email address change flow.

    Firebase confirms the email address change by sending a revocation email to the old email address with a link to revert the change.

  • IDP rollout

    Identity Toolkit had an ability to add identity providers to your sign-in system gradually, so that you could experiment with the impact on your support requests. This feature was removed in Firebase Authentication.

Client side differences

In Firebase, the features provided by Google Identity Toolkit are split into two components:

  • Firebase Authentication SDKs

    In Firebase Authentication, the functionality provided by Identity Toolkit's REST API has been packaged in client SDKs available for Android, iOS, and JavaScript. You can use the SDK to sign in and sign up users; access user profile information; link, update and delete accounts; and reset passwords using the client SDK instead of communicating with the back end service via REST calls.

  • FirebaseUI Auth

    All of the UI flows that manage sign-in, sign-up, password recovery, and account linking have been rebuilt using the Frebase Authentication SDKs. They are available as open source SDKs for iOS and Android to enable you to completely customize the flows in ways not possible with Identity Toolkit.

Additional differences include:

  • Sessions and migration

    Because sessions are managed differently in Identity Toolkit and Firebase Authentication, your users' existing sessions will be terminated upon upgrading the SDK, and your users will have to sign in again.

قبل از اینکه شروع کنی

Before you can migrate from Identity Toolkit to Firebase Authentication, you must

  1. Open the Firebase console , click Import Google Project , and select your Identity Toolkit project.

  2. Click > Permissions to open the IAM & Admin page.

  3. Open the Service accounts page. Here you can see the service account you previously configured for Identity Toolkit.

  4. Next to the service account, click > Create key . Then, in the Create private key dialog, set the Key type to JSON and click Create . A JSON file containing your service account's credentials is downloaded for you. You'll need this to initialize the SDK in the next step.

  5. Go back to the Firebase console . In the Auth section, open the Email Templates page. On this page, customize your app's email templates.

    In Identity Toolkit, when users reset passwords, changed email addresses and verified email their email addresses, you needed to get an OOB code from the Identity Toolkit server, and then send the code to users through email. Firebase sends emails based on the templates you configure with no additional actions required.

  6. Optional : If you need to access Firebase services on your server, install the Firebase SDK.

    1. You can install the Firebase Node.js module with npm :

      $ npm init
      $ npm install --save firebase-admin
      
    2. In your code, you can access Firebase using:

      var admin = require('firebase-admin');
      var app = admin.initializeApp({
        credential: admin.credential.cert('path/to/serviceAccountCredentials.json')
      });
      

Next, complete the migration steps for your app's platform: Android , iOS , web .

Servers and JavaScript

Notable changes

There are a number of additional differences in the web implementation of Firebase from Identity Toolkit.

  • Web session management

    Previously, when a user authenticated using the Identity Toolkit widget , a cookie was set for the user which was used to bootstrap the session . This cookie had a two week lifetime and was used to allow the user to use the account management widget to change password and email address. Some sites used this cookie to authenticate all other page requests on the site. Other sites used the cookie to create their own cookies via their framework's cookie management system.

    Firebase client SDKs now manage Firebase ID tokens and work with Firebase Authentication's backend to keep the session fresh. The backend expires sessions when important account changes (like user password changes) have occurred. Firebase ID tokens are not automatically set as cookies on the web client and have only an hour lifetime. Unless you want sessions of only an hour, Firebase ID tokens are not appropriate to be used as the cookie to validate all of your page requests. Instead, you will need to set up a listener for when the user logs in, get the Firebase ID token , validate the token , and create your own cookie via your framework's cookie management system.

    You will need to set the session lifetime of your cookie based on the security needs of your application.

  • Web sign-in flow

    Previously, users were redirected to accountchooser.com when sign-in was initiated to learn what identifier the user wanted to use. Firebase Auth UI's flow now begins with a list of sign-in methods, including an email option which goes to accountchooser.com for web and uses the hintRequest API on Android. In addition, email addresses are no longer required in the Firebase UI. This will make it easier to support anonymous users, custom auth users or users from providers where email addresses are not required.

  • Account management widget

    This widget provides a UI for users to change email addresses, change password ors unlink their accounts from identity providers. It is currently under development.

  • Sign-in button/widget

    Widgets like the sign-in button and user card are no longer provided. They can be built very easily using the Firebase Authentication API.

  • No signOutUrl

    You will need to call firebase.auth.signOut() and handle the callback.

  • No oobActionUrl

    Email sending is now handled by Firebase and is configured in the Firebase console.

  • CSS customization

    FirebaseUI uses Material Design Lite styling, which dynamically adds Material Design animations.

Step 1: Change Server Code

  1. If your server relies on the Identity Toolkit token (valid for two weeks) to manage web user sessions, you need to convert the server to use its own session cookie.

    1. Implement an endpoint for validating the Firebase ID token and setting the session cookie for the user. The client app sends the Firebase ID token to this endpoint.
    2. If the incoming request contains your own session cookie, you can consider the user authenticated. Otherwise, treat the request as unauthenticated.
    3. If you do not want any of your users to lose their existing logged-in sessions, you should wait for two weeks for all Identity Toolkit tokens to expire, or also do the dual token validation for your web application as described below in step 3.
  2. Next, because the Firebase tokens are different than Identity Toolkit tokens, you must update your token validation logic. Install the Firebase Server SDK to your server; or, if you use a language not supported by the Firebase Server SDK, download a JWT token validation library for your environment and properly validate the token .

  3. When you first make the above updates, you might still have code paths that rely on Identity Toolkit tokens. If you have iOS or Android applications, users will need to upgrade to the new version of the app in order to have the new code paths work. If you don't want to force your users to update your app, you can add additional server validation logic that examines the token and determines whether it needs to use the Firebase SDK or the Identity Toolkit SDK to validate the token. If you only have a web application, all new authentication requests will be shifted over to Firebase and, therefore, you only need to use the Firebase token verification methods.

See the Firebase Web API Reference .

Step 2: Update your HTML

  1. Add the Firebase initialization code to your app:

    1. Open your project in the Firebase console .
    2. On the Overview page, click Add App , then click Add Firebase to your web app . A code snippet that initializes Firebase is displayed.
    3. Copy and paste the initialization snippet into your web page.
  2. Add FirebaseUI Auth to your app:

    <script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script>
    <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" />
    <!-- *******************************************************************************************
       * TODO(DEVELOPER): Paste the initialization snippet from:
       * Firebase Console > Overview > Add Firebase to your web app. *
       ***************************************************************************************** -->
    <script type="text/javascript">
      // FirebaseUI config.
      var uiConfig = {
        'signInSuccessUrl': '<url-to-redirect-to-on-success>',
        'signInOptions': [
          // Leave the lines as is for the providers you want to offer your users.
          firebase.auth.GoogleAuthProvider.PROVIDER_ID,
          firebase.auth.FacebookAuthProvider.PROVIDER_ID,
          firebase.auth.TwitterAuthProvider.PROVIDER_ID,
          firebase.auth.GithubAuthProvider.PROVIDER_ID,
          firebase.auth.EmailAuthProvider.PROVIDER_ID
        ],
        // Terms of service url.
        'tosUrl': '<your-tos-url>',
      };
    
      // Initialize the FirebaseUI Widget using Firebase.
      var ui = new firebaseui.auth.AuthUI(firebase.auth());
      // The start method will wait until the DOM is loaded.
      ui.start('#firebaseui-auth-container', uiConfig);
    </script>
    
  3. Remove the Identity Toolkit SDK from your app.

  4. If you relied on the Identity Toolkit ID token for session management, you must make the following changes on the client side:

    1. After successfully signing in with Firebase, get a Firebase ID token by calling firebase.auth().currentUser.getToken() .

    2. Send the Firebase ID token to the backend server, validate it, and issue your own session cookie.

      Do not rely solely on the session cookie when performing sensitive operations or sending authenticated edit requests to your server. You will need to provide additional cross-site request forgery (CSRF) protection.

      If your framework does not provide CSRF protection, one way to prevent an attack would be to get a Firebase ID token for the signed-in user with getToken() and include the token with each request (the session cookie will also be sent by default). You would then validate that token using the Firebase server SDK in addition to the session cookie check, which your backend framework completed. This will make it harder for CSRF attacks to succeed, as the Firebase ID token is only stored using web storage and never in a cookie.

    3. Identity Toolkit tokens are valid for two weeks. You may want to continue issuing tokens that last two weeks, or you might want to make it longer or shorter based on the security requirements of your app. When a user signs out, clear the session cookie.

Step 3: Update IDP redirect URLs

  1. In the Firebase console, open the Authentication section and click the Sign-in Method tab.

  2. For each federated sign-in provider you support, do the following:

    1. Click the name of the sign-in provider.
    2. Copy the OAuth redirect URI.
    3. In the sign-in provider's developer console, update the OAuth redirect URI.

اندروید

Step 1: Add Firebase to your app

  1. Open the Firebase console , and select your Identity Toolkit project, which you already imported.

  2. On the Overview page, click Add App , and then click Add Firebase to your Android app . In the Add Firebase dialog, provide your app's package name and signing certificate fingerprint and click Add App . The google-services.json configuration file is then downloaded to your computer.

  3. Copy the configuration file to your Android app module root directory. This configuration file contains project and Google OAuth client information.

  4. In your Project-level build.gradle file ( <var>your-project</var>/build.gradle ), specify your app's package name in the defaultConfig section:

    defaultConfig {
       …..
      applicationId "com.your-app"
    }
    
  5. Also in your Project-level build.gradle file, add a dependency to include the google-services plugin:

    buildscript {
     dependencies {
       // Add this line
       classpath 'com.google.gms:google-services:3.0.0'
     }
    }
    
  6. In your app's App-level build.gradle file ( <var>my-project</var>/<var>app-module</var>/build.gradle ), add the following line to the bottom to enable the google-services plugin:

    // Add to the bottom of the file
    apply plugin: 'com.google.gms.google-services'
    

    The google-services plugin uses the google-services.json file to configure your application to use Firebase.

  7. Also in the App-level build.gradle file, add the Firebase Authentication dependency:

    compile 'com.google.firebase:firebase-auth:24.2.0'
    compile 'com.google.android.gms:play-services-auth:21.6.0'
    

Step 2: Remove the Identity Toolkit SDK

  1. Remove the Identity Toolkit configuration from the AndroidManifest.xml file. This information is included in the google-service.json file and loaded by the google-services plugin.
  2. Remove the Identity Toolkit SDK from your app.

Step 3: Add FirebaseUI to your app

  1. Add FirebaseUI Auth to your app.

  2. In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.

آی‌او‌اس

Step 1: Add Firebase to your app

  1. Add the Firebase SDK to your app by running the following commands:

    $ cd your-project directory
    $ pod init
    $ pod 'Firebase'
    
  2. Open the Firebase console , and select your Identity Toolkit project, which you already imported.

  3. On the Overview page, click Add App , and then click Add Firebase to your iOS app . In the Add Firebase dialog, provide your app's bundle ID and App Store ID, and then click Add App . The GoogleService-Info.plist configuration file is then downloaded to your computer. If you have multiple bundle IDs in your project, each bundle ID must be connected in the Firebase console so it can have its own GoogleService-Info.plist file.

  4. Copy the configuration file to the root of your Xcode project and add it to all targets.

Step 2: Remove the Identity Toolkit SDK

  1. Remove GoogleIdentityToolkit from your app's Podfile.
  2. Run the pod install command.

Step 3: Add FirebaseUI to your app

  1. Add FirebaseUI Auth to your app.

  2. In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.

،

The newest version of Google Identity Toolkit has been released as Firebase Authentication . Going forward, feature work on Identity Toolkit will be frozen and all new feature development will be done on Firebase Authentication. We encourage Identity Toolkit developers to move to Firebase Authentication as soon as is practical for their applications; however, Identity Toolkit continues to work and will not be deprecated without a further announcement.

ویژگی‌های جدید

Firebase Authentication already has some significant feature enhancements over Google Identity Toolkit:

  • Access to all of Firebase

    Firebase is a mobile platform that helps you quickly develop high-quality apps, grow your user base, and earn more money. Firebase is made up of complementary features that you can mix-and-match to fit your needs and includes infrastructure for: mobile analytics , cloud messaging , realtime database , file storage , static hosting , remote configuration , mobile crash reporting and Android testing .

  • Updated UIs

    We have completely rebuilt the UI flows based on Google's latest UX research. This includes password recovery, account linking, new/existing account disambiguation flows that often take significant time to code and debug. It integrates Smart Lock for Passwords on Android, which has significantly improved sign-in and sign-up conversion for participating apps . It also supports easy theme modifications to match your application and, for maximum customizability, the Android and iOS versions have been open sourced.

  • Simplified server setup

    We have made it easier for developers to use Firebase Authentication. With Identity Toolkit, we saw that many developers chose not to implement the email recovery flow which made it impossible for their users to recover their accounts if they forgot their password. Firebase Authentication can send email verification, password reset, and changed password messages to the user and the text can be easily customized for your users. Additionally, you no longer need to host the UI widgets for hosting redirects and completing password change operations.

  • New admin console

    Firebase has a new developer console and the Authentication section allows you to view, modify and delete your users. This can be a great help in debugging your sign-in and sign-up flows. The console also allows you to configure authentication methods and customize email templates.

  • New SDKs

    All of Identity Toolkit's server APIs are now available natively with each of our client libraries (Android, iOS, web). Developers will be able to sign in and sign up old and new users, access user properties, link, update and delete accounts, reset passwords, and more without being tied to a fixed UI. If you prefer, you can manually build your own entire sign in flow and experience on top of this API.

  • Session management for mobile apps

    With Identity Toolkit, apps created their own session state based on the initial authentication event from Identity Toolkit. Firebase Auth uses a backend service that takes a refresh token, minted from the authentication event, and exchanges it for hour-long access tokens for Android, iOS and JavaScript. When a user changes their password, refresh tokens will no longer be able to generate new access tokens, thereby disabling access until the user reauthenticates on that device.

  • Anonymous and GitHub authentication

    Firebase Authentication supports two new authentication types: GitHub and anonymous. Anonymous sign-in can be used to create a unique user ID without requiring the user to go through any sign-in or sign-up process. With an anonymous user, you can now make authenticated API calls, like you would with a regular user. When the user decides to sign up for an account, all activity is preserved with the same user ID. This is great for situations like a server side shopping cart or any application where you want to engage the user before sending them through a sign-up flow.

Feature Differences

Some Identity Toolkit features are not currently available in Firebase Authentication, while other features have been redesigned and work differently. You might choose not to migrate immediately if these features are important to your app. In many cases, these features might not be important for your app or there might be easy fallbacks which will enable you to proceed with migration.

Server side differences

The core Identity Toolkit service with its underlying REST APIs, account validation logic, and primary user database have undergone only minor updates. But some features and the manner in which you integrate Firebase Authentication into your service has changed.

  • ارائه دهندگان هویت

    Paypal and AOL are not supported. Users with accounts from these IDPs can still sign in to your application with the password recovery flow and set up a password for their account.

  • Server libraries

    Currently, there are Firebase admin SDKs available for Java, Node.js, Python, Go and C#.

  • Account management emails

    Password reset, email verification, and email change messages can be performed by Firebase or from the developer's own mail server. Currently, Firebase email templates offer only limited customization.

  • Email address change confirmation

    In Identity Toolkit, when a user decides to change their email address, it sends an email to the new address that has a link to continue the email address change flow.

    Firebase confirms the email address change by sending a revocation email to the old email address with a link to revert the change.

  • IDP rollout

    Identity Toolkit had an ability to add identity providers to your sign-in system gradually, so that you could experiment with the impact on your support requests. This feature was removed in Firebase Authentication.

Client side differences

In Firebase, the features provided by Google Identity Toolkit are split into two components:

  • Firebase Authentication SDKs

    In Firebase Authentication, the functionality provided by Identity Toolkit's REST API has been packaged in client SDKs available for Android, iOS, and JavaScript. You can use the SDK to sign in and sign up users; access user profile information; link, update and delete accounts; and reset passwords using the client SDK instead of communicating with the back end service via REST calls.

  • FirebaseUI Auth

    All of the UI flows that manage sign-in, sign-up, password recovery, and account linking have been rebuilt using the Frebase Authentication SDKs. They are available as open source SDKs for iOS and Android to enable you to completely customize the flows in ways not possible with Identity Toolkit.

Additional differences include:

  • Sessions and migration

    Because sessions are managed differently in Identity Toolkit and Firebase Authentication, your users' existing sessions will be terminated upon upgrading the SDK, and your users will have to sign in again.

قبل از اینکه شروع کنی

Before you can migrate from Identity Toolkit to Firebase Authentication, you must

  1. Open the Firebase console , click Import Google Project , and select your Identity Toolkit project.

  2. Click > Permissions to open the IAM & Admin page.

  3. Open the Service accounts page. Here you can see the service account you previously configured for Identity Toolkit.

  4. Next to the service account, click > Create key . Then, in the Create private key dialog, set the Key type to JSON and click Create . A JSON file containing your service account's credentials is downloaded for you. You'll need this to initialize the SDK in the next step.

  5. Go back to the Firebase console . In the Auth section, open the Email Templates page. On this page, customize your app's email templates.

    In Identity Toolkit, when users reset passwords, changed email addresses and verified email their email addresses, you needed to get an OOB code from the Identity Toolkit server, and then send the code to users through email. Firebase sends emails based on the templates you configure with no additional actions required.

  6. Optional : If you need to access Firebase services on your server, install the Firebase SDK.

    1. You can install the Firebase Node.js module with npm :

      $ npm init
      $ npm install --save firebase-admin
      
    2. In your code, you can access Firebase using:

      var admin = require('firebase-admin');
      var app = admin.initializeApp({
        credential: admin.credential.cert('path/to/serviceAccountCredentials.json')
      });
      

Next, complete the migration steps for your app's platform: Android , iOS , web .

Servers and JavaScript

Notable changes

There are a number of additional differences in the web implementation of Firebase from Identity Toolkit.

  • Web session management

    Previously, when a user authenticated using the Identity Toolkit widget , a cookie was set for the user which was used to bootstrap the session . This cookie had a two week lifetime and was used to allow the user to use the account management widget to change password and email address. Some sites used this cookie to authenticate all other page requests on the site. Other sites used the cookie to create their own cookies via their framework's cookie management system.

    Firebase client SDKs now manage Firebase ID tokens and work with Firebase Authentication's backend to keep the session fresh. The backend expires sessions when important account changes (like user password changes) have occurred. Firebase ID tokens are not automatically set as cookies on the web client and have only an hour lifetime. Unless you want sessions of only an hour, Firebase ID tokens are not appropriate to be used as the cookie to validate all of your page requests. Instead, you will need to set up a listener for when the user logs in, get the Firebase ID token , validate the token , and create your own cookie via your framework's cookie management system.

    You will need to set the session lifetime of your cookie based on the security needs of your application.

  • Web sign-in flow

    Previously, users were redirected to accountchooser.com when sign-in was initiated to learn what identifier the user wanted to use. Firebase Auth UI's flow now begins with a list of sign-in methods, including an email option which goes to accountchooser.com for web and uses the hintRequest API on Android. In addition, email addresses are no longer required in the Firebase UI. This will make it easier to support anonymous users, custom auth users or users from providers where email addresses are not required.

  • Account management widget

    This widget provides a UI for users to change email addresses, change password ors unlink their accounts from identity providers. It is currently under development.

  • Sign-in button/widget

    Widgets like the sign-in button and user card are no longer provided. They can be built very easily using the Firebase Authentication API.

  • No signOutUrl

    You will need to call firebase.auth.signOut() and handle the callback.

  • No oobActionUrl

    Email sending is now handled by Firebase and is configured in the Firebase console.

  • CSS customization

    FirebaseUI uses Material Design Lite styling, which dynamically adds Material Design animations.

Step 1: Change Server Code

  1. If your server relies on the Identity Toolkit token (valid for two weeks) to manage web user sessions, you need to convert the server to use its own session cookie.

    1. Implement an endpoint for validating the Firebase ID token and setting the session cookie for the user. The client app sends the Firebase ID token to this endpoint.
    2. If the incoming request contains your own session cookie, you can consider the user authenticated. Otherwise, treat the request as unauthenticated.
    3. If you do not want any of your users to lose their existing logged-in sessions, you should wait for two weeks for all Identity Toolkit tokens to expire, or also do the dual token validation for your web application as described below in step 3.
  2. Next, because the Firebase tokens are different than Identity Toolkit tokens, you must update your token validation logic. Install the Firebase Server SDK to your server; or, if you use a language not supported by the Firebase Server SDK, download a JWT token validation library for your environment and properly validate the token .

  3. When you first make the above updates, you might still have code paths that rely on Identity Toolkit tokens. If you have iOS or Android applications, users will need to upgrade to the new version of the app in order to have the new code paths work. If you don't want to force your users to update your app, you can add additional server validation logic that examines the token and determines whether it needs to use the Firebase SDK or the Identity Toolkit SDK to validate the token. If you only have a web application, all new authentication requests will be shifted over to Firebase and, therefore, you only need to use the Firebase token verification methods.

See the Firebase Web API Reference .

Step 2: Update your HTML

  1. Add the Firebase initialization code to your app:

    1. Open your project in the Firebase console .
    2. On the Overview page, click Add App , then click Add Firebase to your web app . A code snippet that initializes Firebase is displayed.
    3. Copy and paste the initialization snippet into your web page.
  2. Add FirebaseUI Auth to your app:

    <script src="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.js"></script>
    <link type="text/css" rel="stylesheet" href="https://www.gstatic.com/firebasejs/ui/live/0.4/firebase-ui-auth.css" />
    <!-- *******************************************************************************************
       * TODO(DEVELOPER): Paste the initialization snippet from:
       * Firebase Console > Overview > Add Firebase to your web app. *
       ***************************************************************************************** -->
    <script type="text/javascript">
      // FirebaseUI config.
      var uiConfig = {
        'signInSuccessUrl': '<url-to-redirect-to-on-success>',
        'signInOptions': [
          // Leave the lines as is for the providers you want to offer your users.
          firebase.auth.GoogleAuthProvider.PROVIDER_ID,
          firebase.auth.FacebookAuthProvider.PROVIDER_ID,
          firebase.auth.TwitterAuthProvider.PROVIDER_ID,
          firebase.auth.GithubAuthProvider.PROVIDER_ID,
          firebase.auth.EmailAuthProvider.PROVIDER_ID
        ],
        // Terms of service url.
        'tosUrl': '<your-tos-url>',
      };
    
      // Initialize the FirebaseUI Widget using Firebase.
      var ui = new firebaseui.auth.AuthUI(firebase.auth());
      // The start method will wait until the DOM is loaded.
      ui.start('#firebaseui-auth-container', uiConfig);
    </script>
    
  3. Remove the Identity Toolkit SDK from your app.

  4. If you relied on the Identity Toolkit ID token for session management, you must make the following changes on the client side:

    1. After successfully signing in with Firebase, get a Firebase ID token by calling firebase.auth().currentUser.getToken() .

    2. Send the Firebase ID token to the backend server, validate it, and issue your own session cookie.

      Do not rely solely on the session cookie when performing sensitive operations or sending authenticated edit requests to your server. You will need to provide additional cross-site request forgery (CSRF) protection.

      If your framework does not provide CSRF protection, one way to prevent an attack would be to get a Firebase ID token for the signed-in user with getToken() and include the token with each request (the session cookie will also be sent by default). You would then validate that token using the Firebase server SDK in addition to the session cookie check, which your backend framework completed. This will make it harder for CSRF attacks to succeed, as the Firebase ID token is only stored using web storage and never in a cookie.

    3. Identity Toolkit tokens are valid for two weeks. You may want to continue issuing tokens that last two weeks, or you might want to make it longer or shorter based on the security requirements of your app. When a user signs out, clear the session cookie.

Step 3: Update IDP redirect URLs

  1. In the Firebase console, open the Authentication section and click the Sign-in Method tab.

  2. For each federated sign-in provider you support, do the following:

    1. Click the name of the sign-in provider.
    2. Copy the OAuth redirect URI.
    3. In the sign-in provider's developer console, update the OAuth redirect URI.

اندروید

Step 1: Add Firebase to your app

  1. Open the Firebase console , and select your Identity Toolkit project, which you already imported.

  2. On the Overview page, click Add App , and then click Add Firebase to your Android app . In the Add Firebase dialog, provide your app's package name and signing certificate fingerprint and click Add App . The google-services.json configuration file is then downloaded to your computer.

  3. Copy the configuration file to your Android app module root directory. This configuration file contains project and Google OAuth client information.

  4. In your Project-level build.gradle file ( <var>your-project</var>/build.gradle ), specify your app's package name in the defaultConfig section:

    defaultConfig {
       …..
      applicationId "com.your-app"
    }
    
  5. Also in your Project-level build.gradle file, add a dependency to include the google-services plugin:

    buildscript {
     dependencies {
       // Add this line
       classpath 'com.google.gms:google-services:3.0.0'
     }
    }
    
  6. In your app's App-level build.gradle file ( <var>my-project</var>/<var>app-module</var>/build.gradle ), add the following line to the bottom to enable the google-services plugin:

    // Add to the bottom of the file
    apply plugin: 'com.google.gms.google-services'
    

    The google-services plugin uses the google-services.json file to configure your application to use Firebase.

  7. Also in the App-level build.gradle file, add the Firebase Authentication dependency:

    compile 'com.google.firebase:firebase-auth:24.2.0'
    compile 'com.google.android.gms:play-services-auth:21.6.0'
    

Step 2: Remove the Identity Toolkit SDK

  1. Remove the Identity Toolkit configuration from the AndroidManifest.xml file. This information is included in the google-service.json file and loaded by the google-services plugin.
  2. Remove the Identity Toolkit SDK from your app.

Step 3: Add FirebaseUI to your app

  1. Add FirebaseUI Auth to your app.

  2. In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.

آی‌او‌اس

Step 1: Add Firebase to your app

  1. Add the Firebase SDK to your app by running the following commands:

    $ cd your-project directory
    $ pod init
    $ pod 'Firebase'
    
  2. Open the Firebase console , and select your Identity Toolkit project, which you already imported.

  3. On the Overview page, click Add App , and then click Add Firebase to your iOS app . In the Add Firebase dialog, provide your app's bundle ID and App Store ID, and then click Add App . The GoogleService-Info.plist configuration file is then downloaded to your computer. If you have multiple bundle IDs in your project, each bundle ID must be connected in the Firebase console so it can have its own GoogleService-Info.plist file.

  4. Copy the configuration file to the root of your Xcode project and add it to all targets.

Step 2: Remove the Identity Toolkit SDK

  1. Remove GoogleIdentityToolkit from your app's Podfile.
  2. Run the pod install command.

Step 3: Add FirebaseUI to your app

  1. Add FirebaseUI Auth to your app.

  2. In your app, replace calls to the Identity Toolkit SDK with calls to FirebaseUI.