0Pricing
Firebase Auth & Realtime Database Apps · 课时

多重身份验证(MFA)

通过为 Firebase 用户启用并配置多重身份验证来增强安全性

多重身份验证(MFA) 是 CoddyKit 上的免费 Firebase Auth & Realtime Database Apps 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Firebase Auth & Realtime Database Apps 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Firebase Auth & Realtime Database Apps 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Secure Your App with MFA

Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts. Instead of just a password, users need a second "factor" to prove their identity.

This significantly reduces the risk of unauthorized access, even if a password is stolen.

Firebase MFA Overview

Firebase Authentication provides built-in support for MFA. It allows users to enroll multiple second factors, like a phone number for SMS verification.

When MFA is enabled, users first sign in with their primary method (e.g., email/password), then complete a challenge with one of their enrolled second factors.

Prerequisites for MFA

To enable MFA for a user, they must first be signed into your app. Firebase MFA works by associating additional factors with an existing user account.

  • User must be signed in.
  • Firebase SDK initialized.
  • You'll guide the user to enroll a second factor.

Adding a Phone Factor

A common second factor is a phone number, verified via SMS. This process involves:

  1. Sending a verification code to the user's phone.
  2. The user entering that code into your app.
  3. Firebase verifying the code and linking the phone number to the user's account.

Start Phone Enrollment

Here's how to initiate sending an SMS verification code to a user's phone number as an MFA factor. Remember to replace +16505551234 with the user's actual phone number.

import com.google.firebase.auth.*;
import com.google.firebase.FirebaseApp;
import java.util.concurrent.TimeUnit;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized and a user is signed in.
    // FirebaseAuth auth = FirebaseAuth.getInstance();
    // FirebaseUser user = auth.getCurrentUser(); // Must be non-null

    System.out.println("Simulating MFA phone enrollment initiation:");

    // Example PhoneAuthOptions (actual implementation requires Activity context)
    PhoneAuthOptions options = PhoneAuthOptions.newBuilder(FirebaseAuth.getInstance())
        .setPhoneNumber("+16505551234") // User's phone number
        .setTimeout(60L, TimeUnit.SECONDS)
        .setActivity(null) // Use 'this' for Activity context on Android
        .setCallbacks(new PhoneAuthProvider.OnVerificationStateChangedCallbacks() {
            @Override public void onVerificationCompleted(PhoneAuthCredential credential) { /* auto-verified */ }
            @Override public void onVerificationFailed(FirebaseException e) { System.err.println("Failed: " + e.getMessage()); }
            @Override public void onCodeSent(String verificationId, PhoneAuthProvider.ForceResendingToken token) {
                System.out.println("Code sent. Store verificationId: " + verificationId);
                // Prompt user for SMS code here.
            }
        }).build();

    // In a real app: PhoneAuthProvider.verifyPhoneNumber(options);
    System.out.println("SMS verification initiated (simulated).");
  }
}

Verify & Finalize Enrollment

Once the user receives the SMS code and enters it, you use the verificationId (from the previous step) and the code to create a PhoneAuthCredential, then enroll it as an MFA factor.

import com.google.firebase.auth.*;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized and a user is signed in.
    // FirebaseAuth auth = FirebaseAuth.getInstance();
    // FirebaseUser user = auth.getCurrentUser(); // Must be non-null

    String verificationId = "YOUR_VERIFICATION_ID"; // From onCodeSent callback
    String smsCode = "123456"; // User's input

    PhoneAuthCredential credential = PhoneAuthProvider.getCredential(verificationId, smsCode);

    // Enroll the credential as an MFA factor
    // user.multiFactor.enroll(credential)
    //     .addOnCompleteListener(task -> {
    //         if (task.isSuccessful()) {
    //             System.out.println("MFA factor enrolled successfully!");
    //         } else {
    //             System.err.println("MFA factor enrollment failed: " + task.getException().getMessage());
    //         }
    //     });
    System.out.println("MFA enrollment code demonstrated. Actual enrollment is async.");
  }
}

Authenticating with MFA

When a user with MFA enabled tries to sign in, the initial sign-in (e.g., with email/password) might return a MultiFactorResolver. This resolver contains information about the available second factors.

Your app then prompts the user to select and verify one of their enrolled factors.

Respond to MFA Challenge

After a primary sign-in, if MFA is required, you'll get a MultiFactorResolver. You then use this to complete the sign-in with a second factor, such as a phone SMS code.

import com.google.firebase.auth.*;
import java.util.List;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized.
    // FirebaseAuth auth = FirebaseAuth.getInstance();

    // --- Scenario: After an initial sign-in attempt (e.g., email/password)
    // --- that requires MFA, you would receive a MultiFactorResolver.
    // --- This is a simplified demo.

    System.out.println("Simulating MFA sign-in challenge response:");

    // MultiFactorResolver resolver = ... (obtained from initial sign-in result)
    // For demonstration, let's mock a resolver context.
    // In a real app, you'd get this from a FirebaseAuthException.

    // Example of how you'd get enrolled factors from a resolver
    // List<MultiFactorInfo> factors = resolver.getFactors();
    // if (!factors.isEmpty()) {
    //     MultiFactorInfo selectedFactor = factors.get(0); // Choose one, e.g., phone
    //     if (selectedFactor.getFactorId().equals(PhoneMultiFactorGenerator.FACTOR_ID)) {
    //         // Initiate SMS verification for this factor
    //         // Then, get the SMS code from the user
    //         // String smsCode = "123456";
    //         // PhoneAuthCredential credential = PhoneAuthProvider.getCredential(verificationId, smsCode);
    //         // MultiFactorAssertion assertion = PhoneMultiFactorGenerator.getAssertion(credential);
    //
    //         // auth.signInWithMultiFactorCredential(resolver.resolveSignIn(assertion))
    //         //     .addOnCompleteListener(task -> {
    //         //         if (task.isSuccessful()) {
    //         //             System.out.println("Signed in successfully with MFA!");
    //         //         } else {
    //         //             System.err.println("MFA sign-in failed: " + task.getException().getMessage());
    //         //         }
    //         //     });
    //     }
    // }
    System.out.println("MFA sign-in challenge response simulated. See comments.");
  }
}

View & Unenroll Factors

Users can manage their enrolled MFA factors. This includes viewing a list of factors they've added and removing (unenrolling) factors they no longer wish to use.

This is crucial for user control and security, allowing them to revoke access for lost devices.

import com.google.firebase.auth.*;
import java.util.List;

public class Main {
  public static void main(String[] args) {
    // Assume FirebaseApp is initialized and a user is signed in.
    // FirebaseAuth auth = FirebaseAuth.getInstance();
    // FirebaseUser user = auth.getCurrentUser(); // Must be non-null

    if (user != null) {
      System.out.println("Managing MFA factors for user: " + user.getUid());

      // Get enrolled factors
      List<MultiFactorInfo> enrolledFactors = user.getMultiFactor().getEnrolledFactors();
      System.out.println("\nEnrolled factors:");
      if (enrolledFactors.isEmpty()) {
        System.out.println("  No MFA factors enrolled.");
      } else {
        for (MultiFactorInfo factor : enrolledFactors) {
          System.out.println("  - Factor ID: " + factor.getFactorId() + ", Display Name: " + factor.getDisplayName());
          // Example: unenroll the first factor
          // user.getMultiFactor().unenroll(factor)
          //     .addOnCompleteListener(task -> {
          //         if (task.isSuccessful()) {
          //             System.out.println("Factor unenrolled successfully: " + factor.getFactorId());
          //         } else {
          //             System.err.println("Failed to unenroll: " + task.getException().getMessage());
          //         }
          //     });
        }
      }
    } else {
      System.out.println("No user signed in to manage MFA factors.");
    }
  }
}

MFA Quick Check

Which of the following is NOT a typical step when a user with MFA enabled signs into a Firebase application?

MFA: Stronger Security

In this lesson, you learned how to enhance your application's security by implementing Firebase Multi-Factor Authentication (MFA).

  • We covered enrolling new MFA factors, specifically phone numbers.
  • We explored how to handle the MFA challenge during user sign-in.
  • You also saw how users can manage their enrolled factors.

MFA is a powerful tool to protect user accounts from unauthorized access.

常见问题解答

「多重身份验证(MFA)」课时是免费的吗?

是的 — 「多重身份验证(MFA)」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Firebase Auth & Realtime Database Apps 课程的其余内容,请升级到 CoddyKit PRO。 Firebase Auth & Realtime Database Apps 课程共包含 4 节课。

「多重身份验证(MFA)」这节课中我会学到什么?

通过为 Firebase 用户启用并配置多重身份验证来增强安全性 你通过在浏览器中直接运行的动手代码来练习 Firebase Auth & Realtime Database Apps,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Firebase Auth & Realtime Database Apps 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Firebase Auth & Realtime Database Apps 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「多重身份验证(MFA)」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Firebase Auth & Realtime Database Apps 课中编写并运行代码吗?

能。每节 Firebase Auth & Realtime Database Apps 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 电话号码身份验证
  2. 多重身份验证(MFA)
  3. 自定义声明与安全规则
  4. 账户关联与身份验证提供商管理
← 返回 Firebase Auth & Realtime Database Apps