Autentikasi Nomor Telepon
Terapkan autentikasi nomor telepon yang andal menggunakan verifikasi SMS untuk akses pengguna yang aman.
Autentikasi Nomor Telepon adalah pelajaran Firebase Auth & Realtime Database Apps gratis di CoddyKit. Ini adalah pelajaran 1 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Firebase Auth & Realtime Database Apps, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Firebase Auth & Realtime Database Apps mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Secure Login with Phone Numbers
Phone number authentication allows users to sign in to your app using their mobile phone number. It's a secure and convenient method, especially for users who prefer not to create traditional email/password accounts or use social logins.
- Accessibility: Many users find it easy to use.
- Security: Leverages SMS for verification, adding a layer of security.
- No Passwords: Reduces password fatigue and forgotten password issues.
Enabling Phone Authentication
Before you can use phone number authentication in your app, you need to enable it in your Firebase project settings.
- Go to the Firebase Console.
- Navigate to Authentication > Sign-in method.
- Enable the Phone provider.
- Optionally, specify which phone numbers are allowed for testing.
This step tells Firebase that your project will support phone sign-ins.
Client-Side Preparation
To use phone authentication, your client-side application needs to be set up correctly. This often involves specific mechanisms to verify the user isn't a bot.
- Web: You'll need to use a
RecaptchaVerifierto protect against abuse. - Android: Firebase uses SafetyNet for device verification.
- iOS: Firebase uses DeviceCheck for device verification.
These checks ensure that the phone number verification requests are coming from legitimate app instances.
The Verification Flow
The phone number authentication process typically follows these steps:
- The user enters their phone number into your app.
- Your app requests Firebase to send a verification code via SMS to that number.
- Firebase sends the SMS and returns a
confirmationResultobject to your app. - The user receives the SMS and enters the code into your app.
- Your app uses the
confirmationResultand the SMS code to sign the user in.
Let's see how to implement this.
Initiating Phone Verification (Web)
On the web, you'll use firebase.auth().signInWithPhoneNumber(). It requires a phone number and a RecaptchaVerifier instance. The confirmationResult is crucial for the next step.
/* Assuming Firebase SDK is initialized and 'auth' is firebase.auth() */
// 1. Prepare reCAPTCHA verifier (invisible is common for better UX)
const appVerifier = new firebase.auth.RecaptchaVerifier('recaptcha-container', {
'size': 'invisible',
'callback': (response) => {
// reCAPTCHA solved, now signInWithPhoneNumber can proceed
console.log('reCAPTCHA solved!');
}
});
// 2. Send the verification code
function sendVerificationCode(phoneNumber) {
firebase.auth().signInWithPhoneNumber(phoneNumber, appVerifier)
.then((confirmationResult) => {
// SMS sent. Save this object globally to confirm the code later.
window.confirmationResult = confirmationResult;
console.log('Verification code sent to ' + phoneNumber);
}).catch((error) => {
console.error('Error sending SMS:', error.message);
});
}
// Example usage (in a real app, this would be triggered by a button click)
// sendVerificationCode('+15551234567');
console.log("Function 'sendVerificationCode' defined. Call it with a phone number (e.g., sendVerificationCode('+15551234567')) to try.");Protecting with reCAPTCHA
For web applications, Firebase Phone Auth requires reCAPTCHA verification to prevent abuse, like automated bots attempting to send SMS messages.
- You need an HTML element (e.g., a
div) with a specific ID (like'recaptcha-container') where reCAPTCHA can render, even if it's invisible. - The
RecaptchaVerifierhandles the challenge. Once solved, the callback is triggered, allowingsignInWithPhoneNumberto proceed.
It's an important security measure for web clients.
Confirming the SMS Code
Once the user receives the SMS code and enters it, you use the confirmationResult object (saved from the previous step) to verify the code and complete the sign-in.
/* Assuming 'window.confirmationResult' holds the object from signInWithPhoneNumber */
function verifySmsCode(smsCode) {
if (window.confirmationResult) {
window.confirmationResult.confirm(smsCode)
.then((result) => {
// User signed in successfully!
const user = result.user;
console.log('User signed in with phone number:', user.phoneNumber);
console.log('User UID:', user.uid);
}).catch((error) => {
// User couldn't sign in (e.g., invalid code)
console.error('Error verifying SMS code:', error.message);
});
} else {
console.error('No confirmationResult found. Send SMS first!');
}
}
// Example usage (in a real app, this would be triggered by a button click)
// verifySmsCode('123456'); // Replace with the actual code received via SMS
console.log("Function 'verifySmsCode' defined. Call it with an SMS code (e.g., verifySmsCode('123456')) after sending a verification code.");Accessing User Information
After a successful phone number sign-in, the user's information is available through the firebase.auth().currentUser object, just like any other authentication method.
- You can access their
uid,phoneNumber, and other profile details. - Use the
onAuthStateChangedlistener to monitor the user's login state across your application.
This allows you to personalize content and manage user sessions.
Handling Common Errors
It's important to anticipate and handle errors gracefully to provide a good user experience. Some common errors with phone authentication include:
auth/invalid-phone-number: The provided phone number is not valid.auth/missing-verification-code: The user didn't enter a code or it was empty.auth/invalid-verification-code: The entered SMS code is incorrect.auth/captcha-check-failed: reCAPTCHA verification failed (web).auth/too-many-requests: Too many verification attempts from the same device/IP.
Always display user-friendly messages for these errors.
Verify Your Knowledge
Which of the following is REQUIRED for phone number authentication in a web application?
Phone Auth Summary
You've learned how to implement phone number authentication with Firebase!
- Enable the provider in the Firebase Console.
- Set up client-side checks (reCAPTCHA for web).
- Initiate verification with
signInWithPhoneNumber(). - Confirm the SMS code using the
confirmationResult. - Handle various error scenarios gracefully.
Phone auth offers a great balance of security and convenience for your users. Practice implementing it in your projects!
Belajar Firebase Auth & Realtime Database Apps dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 11
- Pelajaran
- 44
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Autentikasi Nomor Telepon” gratis?
Ya — teks lengkap “Autentikasi Nomor Telepon” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Firebase Auth & Realtime Database Apps, upgrade ke CoddyKit PRO. Kursus Firebase Auth & Realtime Database Apps mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Autentikasi Nomor Telepon”?
Terapkan autentikasi nomor telepon yang andal menggunakan verifikasi SMS untuk akses pengguna yang aman. Kamu berlatih Firebase Auth & Realtime Database Apps dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Firebase Auth & Realtime Database Apps?
Tidak diperlukan pengalaman sebelumnya. Firebase Auth & Realtime Database Apps di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 1 dari 4.
Berapa lama pelajaran “Autentikasi Nomor Telepon” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Firebase Auth & Realtime Database Apps ini?
Ya. Setiap pelajaran Firebase Auth & Realtime Database Apps menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Autentikasi Nomor Telepon
- Autentikasi Multifaktor (MFA)
- Klaim Kustom & Aturan Keamanan
- Penautan Akun dan Pengelolaan Penyedia