匿名認証とカスタム認証
一時ユーザー向けの匿名認証と、Firebaseを使ったカスタム認証システムの実装方法を学びます。
「匿名認証とカスタム認証」はCoddyKit上の無料Firebase Auth & Realtime Database Appsレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはFirebase Auth & Realtime Database Apps学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Anonymous & Custom Auth
Welcome to a lesson on advanced authentication methods! We'll explore two powerful Firebase features:
- Anonymous Authentication: For temporary users who don't want to sign up yet.
- Custom Authentication: For integrating Firebase Auth with your existing user systems.
Let's dive in!
What is Anonymous Authentication?
Anonymous authentication allows users to sign in without providing any credentials like email or social accounts. Firebase creates a temporary anonymous account for them.
This is perfect for:
- Guest modes in apps.
- Allowing users to try out features before committing to a full signup.
- Saving progress temporarily without requiring an account.
Implementing Anonymous Sign-In
Signing in anonymously is straightforward. The Firebase SDK handles creating the temporary user for you.
Try running this example to see a simulated anonymous sign-in:
class FirebaseAuth {
static FirebaseAuth getInstance() { return new FirebaseAuth(); }
void signInAnonymously() {
System.out.println("Attempting anonymous sign-in...");
try { Thread.sleep(100); } catch (InterruptedException e) {}
System.out.println("Anonymous user signed in!");
System.out.println("Temporary User ID: guest_123abc");
}
}
public class Main {
public static void main(String[] args) {
FirebaseAuth auth = FirebaseAuth.getInstance();
auth.signInAnonymously();
}
}Upgrading Anonymous Accounts
Anonymous accounts are temporary. What if your user decides to sign up later?
Firebase allows you to link an anonymous account to a permanent one (e.g., email/password, Google). The user's data and progress from their anonymous session will then be associated with their new permanent account.
This is done using methods like linkWithCredential() or linkWithPopup() once the user provides permanent credentials.
Introduction to Custom Authentication
Custom authentication is for when you already have your own user management system or want to integrate Firebase Auth with a complex backend.
Instead of Firebase handling user sign-up directly, your backend authenticates the user and then mints a special custom token. Your client application then uses this token to sign into Firebase.
Custom Auth: The Flow
Here's how custom authentication works:
- User logs in via your app, sending credentials to your backend.
- Your backend verifies credentials (e.g., against your own database).
- If successful, your backend uses the Firebase Admin SDK to create a custom token for that user.
- Your backend sends this custom token back to your client app.
- Your client app uses the Firebase client SDK to sign in with this custom token.
Generating Custom Tokens (Backend)
The critical step on your server is to generate the custom token using the Firebase Admin SDK. This SDK must be initialized with your Firebase project's service account credentials for security.
Here's a conceptual look at how your backend might generate a token (this code is for your server, not your app):
// This code runs on your secure backend server,
// NOT in your client-side application.
// It requires the Firebase Admin SDK.
// import com.google.firebase.auth.FirebaseAuth;
public class BackendCustomToken {
// This method would be part of your server logic.
public static String generateToken(String userId) {
try {
// In a real app:
// return FirebaseAuth.getInstance().createCustomToken(userId);
// For this example, we simulate it:
String token = "mock_token_for_" + userId + "_123xyz";
System.out.println("Backend generated token for " + userId);
return token;
} catch (Exception e) {
System.err.println("Backend error: " + e.getMessage());
return null;
}
}
public static void main(String[] args) {
// This main method is just to illustrate the concept.
// In reality, this logic is triggered by an API call.
String userId = "userFromYourDB";
String customToken = generateToken(userId);
if (customToken != null) {
System.out.println("Backend is ready to send this token: " + customToken);
}
}
}Signing In with a Custom Token (Client)
Once your client app receives the custom token from your backend, it uses the Firebase client SDK's signInWithCustomToken() method to complete the authentication process.
Run this example to see how your app uses the token to sign in:
class FirebaseAuth {
static FirebaseAuth getInstance() { return new FirebaseAuth(); }
void signInWithCustomToken(String token) {
System.out.println("Attempting sign-in with custom token...");
if (token != null && !token.isEmpty()) {
try { Thread.sleep(100); } catch (InterruptedException e) {}
System.out.println("Signed in with custom token successfully!");
System.out.println("User ID: custom_user_xyz");
} else {
System.out.println("Error: Custom token is missing.");
}
}
}
public class Main {
public static void main(String[] args) {
FirebaseAuth auth = FirebaseAuth.getInstance();
// Imagine this token comes from your backend
String customToken = "YOUR_CUSTOM_TOKEN_FROM_BACKEND";
auth.signInWithCustomToken(customToken);
}
}Benefits of Custom Auth
Custom authentication offers significant advantages:
- Flexibility: Integrate with virtually any existing user database or identity provider.
- Control: Maintain full control over your user registration and login logic on your backend.
- Migration: Easily migrate existing users to Firebase without forcing them to re-register.
- Complex Workflows: Implement intricate authentication flows that might not be directly supported by Firebase's built-in providers.
Quick Check: Auth Methods
Which of the following statements about Anonymous and Custom Authentication in Firebase are TRUE?
Recap: Temporary & Flexible Auth
Great job! In this lesson, we explored two powerful ways to manage user authentication:
- Anonymous Authentication: Ideal for guest users and initial app exploration, with the option to upgrade to a permanent account.
- Custom Authentication: Provides maximum flexibility by letting your backend handle user verification and issue Firebase custom tokens.
These methods allow you to tailor your app's authentication experience to a wide range of needs. Keep building amazing apps!
よくある質問
「匿名認証とカスタム認証」レッスンは無料ですか?
はい。「匿名認証とカスタム認証」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Firebase Auth & Realtime Database Appsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。
「匿名認証とカスタム認証」で何を学びますか?
一時ユーザー向けの匿名認証と、Firebaseを使ったカスタム認証システムの実装方法を学びます。 ブラウザで直接実行するハンズオンコードでFirebase Auth & Realtime Database Appsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Firebase Auth & Realtime Database Appsを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのFirebase Auth & Realtime Database Appsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。
「匿名認証とカスタム認証」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このFirebase Auth & Realtime Database Appsレッスンでコードを書いて実行できますか?
はい。すべてのFirebase Auth & Realtime Database Appsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。