匿名与自定义身份验证
探索面向临时用户的匿名身份验证,并学习如何使用 Firebase 实现自定义身份验证系统
匿名与自定义身份验证 是 CoddyKit 上的免费 Firebase Auth & Realtime Database Apps 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Firebase Auth & Realtime Database Apps 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Firebase Auth & Realtime Database Apps 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Anonymous & Custom Auth
Welcome to a lesson on advanced authentication methods! We'll explore two powerful Firebase features:
- Anonymous Authentication: For temporary users who don't want to sign up yet.
- Custom Authentication: For integrating Firebase Auth with your existing user systems.
Let's dive in!
What is Anonymous Authentication?
Anonymous authentication allows users to sign in without providing any credentials like email or social accounts. Firebase creates a temporary anonymous account for them.
This is perfect for:
- Guest modes in apps.
- Allowing users to try out features before committing to a full signup.
- Saving progress temporarily without requiring an account.
Implementing Anonymous Sign-In
Signing in anonymously is straightforward. The Firebase SDK handles creating the temporary user for you.
Try running this example to see a simulated anonymous sign-in:
class FirebaseAuth {
static FirebaseAuth getInstance() { return new FirebaseAuth(); }
void signInAnonymously() {
System.out.println("Attempting anonymous sign-in...");
try { Thread.sleep(100); } catch (InterruptedException e) {}
System.out.println("Anonymous user signed in!");
System.out.println("Temporary User ID: guest_123abc");
}
}
public class Main {
public static void main(String[] args) {
FirebaseAuth auth = FirebaseAuth.getInstance();
auth.signInAnonymously();
}
}Upgrading Anonymous Accounts
Anonymous accounts are temporary. What if your user decides to sign up later?
Firebase allows you to link an anonymous account to a permanent one (e.g., email/password, Google). The user's data and progress from their anonymous session will then be associated with their new permanent account.
This is done using methods like linkWithCredential() or linkWithPopup() once the user provides permanent credentials.
Introduction to Custom Authentication
Custom authentication is for when you already have your own user management system or want to integrate Firebase Auth with a complex backend.
Instead of Firebase handling user sign-up directly, your backend authenticates the user and then mints a special custom token. Your client application then uses this token to sign into Firebase.
Custom Auth: The Flow
Here's how custom authentication works:
- User logs in via your app, sending credentials to your backend.
- Your backend verifies credentials (e.g., against your own database).
- If successful, your backend uses the Firebase Admin SDK to create a custom token for that user.
- Your backend sends this custom token back to your client app.
- Your client app uses the Firebase client SDK to sign in with this custom token.
Generating Custom Tokens (Backend)
The critical step on your server is to generate the custom token using the Firebase Admin SDK. This SDK must be initialized with your Firebase project's service account credentials for security.
Here's a conceptual look at how your backend might generate a token (this code is for your server, not your app):
// This code runs on your secure backend server,
// NOT in your client-side application.
// It requires the Firebase Admin SDK.
// import com.google.firebase.auth.FirebaseAuth;
public class BackendCustomToken {
// This method would be part of your server logic.
public static String generateToken(String userId) {
try {
// In a real app:
// return FirebaseAuth.getInstance().createCustomToken(userId);
// For this example, we simulate it:
String token = "mock_token_for_" + userId + "_123xyz";
System.out.println("Backend generated token for " + userId);
return token;
} catch (Exception e) {
System.err.println("Backend error: " + e.getMessage());
return null;
}
}
public static void main(String[] args) {
// This main method is just to illustrate the concept.
// In reality, this logic is triggered by an API call.
String userId = "userFromYourDB";
String customToken = generateToken(userId);
if (customToken != null) {
System.out.println("Backend is ready to send this token: " + customToken);
}
}
}Signing In with a Custom Token (Client)
Once your client app receives the custom token from your backend, it uses the Firebase client SDK's signInWithCustomToken() method to complete the authentication process.
Run this example to see how your app uses the token to sign in:
class FirebaseAuth {
static FirebaseAuth getInstance() { return new FirebaseAuth(); }
void signInWithCustomToken(String token) {
System.out.println("Attempting sign-in with custom token...");
if (token != null && !token.isEmpty()) {
try { Thread.sleep(100); } catch (InterruptedException e) {}
System.out.println("Signed in with custom token successfully!");
System.out.println("User ID: custom_user_xyz");
} else {
System.out.println("Error: Custom token is missing.");
}
}
}
public class Main {
public static void main(String[] args) {
FirebaseAuth auth = FirebaseAuth.getInstance();
// Imagine this token comes from your backend
String customToken = "YOUR_CUSTOM_TOKEN_FROM_BACKEND";
auth.signInWithCustomToken(customToken);
}
}Benefits of Custom Auth
Custom authentication offers significant advantages:
- Flexibility: Integrate with virtually any existing user database or identity provider.
- Control: Maintain full control over your user registration and login logic on your backend.
- Migration: Easily migrate existing users to Firebase without forcing them to re-register.
- Complex Workflows: Implement intricate authentication flows that might not be directly supported by Firebase's built-in providers.
Quick Check: Auth Methods
Which of the following statements about Anonymous and Custom Authentication in Firebase are TRUE?
Recap: Temporary & Flexible Auth
Great job! In this lesson, we explored two powerful ways to manage user authentication:
- Anonymous Authentication: Ideal for guest users and initial app exploration, with the option to upgrade to a permanent account.
- Custom Authentication: Provides maximum flexibility by letting your backend handle user verification and issue Firebase custom tokens.
These methods allow you to tailor your app's authentication experience to a wide range of needs. Keep building amazing apps!
常见问题解答
「匿名与自定义身份验证」课时是免费的吗?
是的 — 「匿名与自定义身份验证」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Firebase Auth & Realtime Database Apps 课程的其余内容,请升级到 CoddyKit PRO。 Firebase Auth & Realtime Database Apps 课程共包含 4 节课。
「匿名与自定义身份验证」这节课中我会学到什么?
探索面向临时用户的匿名身份验证,并学习如何使用 Firebase 实现自定义身份验证系统 你通过在浏览器中直接运行的动手代码来练习 Firebase Auth & Realtime Database Apps,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Firebase Auth & Realtime Database Apps 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Firebase Auth & Realtime Database Apps 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。
「匿名与自定义身份验证」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Firebase Auth & Realtime Database Apps 课中编写并运行代码吗?
能。每节 Firebase Auth & Realtime Database Apps 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。