0Pricing
Firebase Auth & Realtime Database Apps · 강의

다중 요소 인증(MFA)

Firebase 사용자를 위한 다중 요소 인증을 활성화하고 구성하여 보안을 강화합니다.

다중 요소 인증(MFA)은(는) CoddyKit의 무료 Firebase Auth & Realtime Database Apps 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Firebase Auth & Realtime Database Apps 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Firebase Auth & Realtime Database Apps 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Secure Your App with MFA

Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts. Instead of just a password, users need a second "factor" to prove their identity.

This significantly reduces the risk of unauthorized access, even if a password is stolen.

Firebase MFA Overview

Firebase Authentication provides built-in support for MFA. It allows users to enroll multiple second factors, like a phone number for SMS verification.

When MFA is enabled, users first sign in with their primary method (e.g., email/password), then complete a challenge with one of their enrolled second factors.

Prerequisites for MFA

To enable MFA for a user, they must first be signed into your app. Firebase MFA works by associating additional factors with an existing user account.

  • User must be signed in.
  • Firebase SDK initialized.
  • You'll guide the user to enroll a second factor.

Adding a Phone Factor

A common second factor is a phone number, verified via SMS. This process involves:

  1. Sending a verification code to the user's phone.
  2. The user entering that code into your app.
  3. Firebase verifying the code and linking the phone number to the user's account.

Start Phone Enrollment

Here's how to initiate sending an SMS verification code to a user's phone number as an MFA factor. Remember to replace +16505551234 with the user's actual phone number.

import com.google.firebase.auth.*;
import com.google.firebase.FirebaseApp;
import java.util.concurrent.TimeUnit;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized and a user is signed in.
    // FirebaseAuth auth = FirebaseAuth.getInstance();
    // FirebaseUser user = auth.getCurrentUser(); // Must be non-null

    System.out.println("Simulating MFA phone enrollment initiation:");

    // Example PhoneAuthOptions (actual implementation requires Activity context)
    PhoneAuthOptions options = PhoneAuthOptions.newBuilder(FirebaseAuth.getInstance())
        .setPhoneNumber("+16505551234") // User's phone number
        .setTimeout(60L, TimeUnit.SECONDS)
        .setActivity(null) // Use 'this' for Activity context on Android
        .setCallbacks(new PhoneAuthProvider.OnVerificationStateChangedCallbacks() {
            @Override public void onVerificationCompleted(PhoneAuthCredential credential) { /* auto-verified */ }
            @Override public void onVerificationFailed(FirebaseException e) { System.err.println("Failed: " + e.getMessage()); }
            @Override public void onCodeSent(String verificationId, PhoneAuthProvider.ForceResendingToken token) {
                System.out.println("Code sent. Store verificationId: " + verificationId);
                // Prompt user for SMS code here.
            }
        }).build();

    // In a real app: PhoneAuthProvider.verifyPhoneNumber(options);
    System.out.println("SMS verification initiated (simulated).");
  }
}

Verify & Finalize Enrollment

Once the user receives the SMS code and enters it, you use the verificationId (from the previous step) and the code to create a PhoneAuthCredential, then enroll it as an MFA factor.

import com.google.firebase.auth.*;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized and a user is signed in.
    // FirebaseAuth auth = FirebaseAuth.getInstance();
    // FirebaseUser user = auth.getCurrentUser(); // Must be non-null

    String verificationId = "YOUR_VERIFICATION_ID"; // From onCodeSent callback
    String smsCode = "123456"; // User's input

    PhoneAuthCredential credential = PhoneAuthProvider.getCredential(verificationId, smsCode);

    // Enroll the credential as an MFA factor
    // user.multiFactor.enroll(credential)
    //     .addOnCompleteListener(task -> {
    //         if (task.isSuccessful()) {
    //             System.out.println("MFA factor enrolled successfully!");
    //         } else {
    //             System.err.println("MFA factor enrollment failed: " + task.getException().getMessage());
    //         }
    //     });
    System.out.println("MFA enrollment code demonstrated. Actual enrollment is async.");
  }
}

Authenticating with MFA

When a user with MFA enabled tries to sign in, the initial sign-in (e.g., with email/password) might return a MultiFactorResolver. This resolver contains information about the available second factors.

Your app then prompts the user to select and verify one of their enrolled factors.

Respond to MFA Challenge

After a primary sign-in, if MFA is required, you'll get a MultiFactorResolver. You then use this to complete the sign-in with a second factor, such as a phone SMS code.

import com.google.firebase.auth.*;
import java.util.List;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized.
    // FirebaseAuth auth = FirebaseAuth.getInstance();

    // --- Scenario: After an initial sign-in attempt (e.g., email/password)
    // --- that requires MFA, you would receive a MultiFactorResolver.
    // --- This is a simplified demo.

    System.out.println("Simulating MFA sign-in challenge response:");

    // MultiFactorResolver resolver = ... (obtained from initial sign-in result)
    // For demonstration, let's mock a resolver context.
    // In a real app, you'd get this from a FirebaseAuthException.

    // Example of how you'd get enrolled factors from a resolver
    // List<MultiFactorInfo> factors = resolver.getFactors();
    // if (!factors.isEmpty()) {
    //     MultiFactorInfo selectedFactor = factors.get(0); // Choose one, e.g., phone
    //     if (selectedFactor.getFactorId().equals(PhoneMultiFactorGenerator.FACTOR_ID)) {
    //         // Initiate SMS verification for this factor
    //         // Then, get the SMS code from the user
    //         // String smsCode = "123456";
    //         // PhoneAuthCredential credential = PhoneAuthProvider.getCredential(verificationId, smsCode);
    //         // MultiFactorAssertion assertion = PhoneMultiFactorGenerator.getAssertion(credential);
    //
    //         // auth.signInWithMultiFactorCredential(resolver.resolveSignIn(assertion))
    //         //     .addOnCompleteListener(task -> {
    //         //         if (task.isSuccessful()) {
    //         //             System.out.println("Signed in successfully with MFA!");
    //         //         } else {
    //         //             System.err.println("MFA sign-in failed: " + task.getException().getMessage());
    //         //         }
    //         //     });
    //     }
    // }
    System.out.println("MFA sign-in challenge response simulated. See comments.");
  }
}

View & Unenroll Factors

Users can manage their enrolled MFA factors. This includes viewing a list of factors they've added and removing (unenrolling) factors they no longer wish to use.

This is crucial for user control and security, allowing them to revoke access for lost devices.

import com.google.firebase.auth.*;
import java.util.List;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized and a user is signed in.
    // FirebaseAuth auth = FirebaseAuth.getInstance();
    // FirebaseUser user = auth.getCurrentUser(); // Must be non-null

    if (user != null) {
      System.out.println("Managing MFA factors for user: " + user.getUid());

      // Get enrolled factors
      List<MultiFactorInfo> enrolledFactors = user.getMultiFactor().getEnrolledFactors();
      System.out.println("\nEnrolled factors:");
      if (enrolledFactors.isEmpty()) {
        System.out.println("  No MFA factors enrolled.");
      } else {
        for (MultiFactorInfo factor : enrolledFactors) {
          System.out.println("  - Factor ID: " + factor.getFactorId() + ", Display Name: " + factor.getDisplayName());
          // Example: unenroll the first factor
          // user.getMultiFactor().unenroll(factor)
          //     .addOnCompleteListener(task -> {
          //         if (task.isSuccessful()) {
          //             System.out.println("Factor unenrolled successfully: " + factor.getFactorId());
          //         } else {
          //             System.err.println("Failed to unenroll: " + task.getException().getMessage());
          //         }
          //     });
        }
      }
    } else {
      System.out.println("No user signed in to manage MFA factors.");
    }
  }
}

MFA Quick Check

Which of the following is NOT a typical step when a user with MFA enabled signs into a Firebase application?

MFA: Stronger Security

In this lesson, you learned how to enhance your application's security by implementing Firebase Multi-Factor Authentication (MFA).

  • We covered enrolling new MFA factors, specifically phone numbers.
  • We explored how to handle the MFA challenge during user sign-in.
  • You also saw how users can manage their enrolled factors.

MFA is a powerful tool to protect user accounts from unauthorized access.

자주 묻는 질문

“다중 요소 인증(MFA)” 강의는 무료인가요?

네 — “다중 요소 인증(MFA)” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Firebase Auth & Realtime Database Apps 강의 전체를 잠금 해제할 수 있습니다. Firebase Auth & Realtime Database Apps 강의에는 총 4개의 강의가 포함되어 있습니다.

“다중 요소 인증(MFA)”에서 뭘 배우나요?

Firebase 사용자를 위한 다중 요소 인증을 활성화하고 구성하여 보안을 강화합니다. 브라우저에서 직접 실행하는 실습 코드로 Firebase Auth & Realtime Database Apps을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Firebase Auth & Realtime Database Apps을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Firebase Auth & Realtime Database Apps은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.

“다중 요소 인증(MFA)” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Firebase Auth & Realtime Database Apps 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Firebase Auth & Realtime Database Apps 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 전화번호 인증
  2. 다중 요소 인증(MFA)
  3. 사용자 지정 클레임 및 보안 규칙
  4. 계정 연결 및 인증 제공자 관리
← Firebase Auth & Realtime Database Apps(으)로 돌아가기