Theory
एक Account की पूरी Life
एक real app सिर्फ़ users को log in नहीं कराती। एक account की life में इसे नए users register करने पड़ते हैं, इन्हें log in और out कराना पड़ता है, जब वे अपना password भूल जाएँ तब मदद करनी पड़ती है, और confirm करना पड़ता है वे actually अपना email address own करते हैं। Firebase Authentication हर एक के लिए एक method provide करता है, तो आपको बिना कुछ भी खुद build किए पूरा lifecycle मिलता है।
यह lesson email और password authentication को end to end walk through करता है: registration, login, logout, password reset, और email verification। ये everyday auth features हैं जो FestConnect Mobile को चाहिए।
Theory
Register, Log In, Log Out
तीन basics जो आप SDK के साथ मिले:
- Register:
createUserWithEmailAndPassword(email, password)account create करता है (और success पर user को sign in करता है)। - Log in:
signInWithEmailAndPassword(email, password)एक existing user के लिए। - Log out:
auth.signOut()session end करता है, जिसके बादauth.currentUsernull है।
हर networked call एक Task return करता है जिसे आप एक listener से handle करते हैं। सिर्फ़ इन तीन के साथ, एक user एक account create कर सकता है और आ-जा सकता है। पर दो और features experience को complete और secure बनाते हैं: एक भूला हुआ password reset करना और email verify करना।
Practical
Password Reset और Email Verification
val auth = Firebase.auth
// Password reset: Firebase emails a reset link to the address
auth.sendPasswordResetEmail(email)
.addOnCompleteListener { task ->
if (task.isSuccessful) { /* tell user to check their inbox */ }
}
// Email verification: send a verification link to the signed-in user
auth.currentUser?.sendEmailVerification()
// Later, check whether they have verified:
val verified = auth.currentUser?.isEmailVerified ?: falseFormula
Firebase Passwords Handle करता है; आप कभी नहीं
Notice कीजिए आप क्या NOT करते हैं: आप कभी passwords store नहीं करते, और आप कभी इन्हें खुद reset नहीं करते। जब एक user अपना password भूल जाता है, आप sendPasswordResetEmail call करते हैं, और Firebase इन्हें एक secure reset link email करता है; user एक नया password Firebase के through set करता है, आपके code के through नहीं।
Similarly, email verification Firebase एक confirmation link email कर रहा होता है; आप बस इसे trigger करते हैं और बाद में isEmailVerified check करते हैं। यह एक security win है: sensitive credential handling Firebase के trusted system के अंदर रहती है, तो आपकी app कभी raw passwords touch नहीं करती या risky reset flows build नहीं करती। Feature trigger कीजिए, sensitive part Firebase को करने दीजिए।
Quiz
एक FestConnect user अपना password भूल गया। Correct Firebase approach क्या है?
- Database से उनका पुराना password पढ़िए और उन्हें दिखाइए
- auth.sendPasswordResetEmail(email) call कीजिए; Firebase उन्हें एक नया password set करने के लिए एक secure link email करता है
- उन्हें एक पूरा नया account create करने के लिए कहिए
- Passwords को plain text में store कीजिए तो आप इन्हें look up कर सकें
Show the answer
auth.sendPasswordResetEmail(email) call कीजिए; Firebase उन्हें एक नया password set करने के लिए एक secure link email करता है
Correct approach है auth.sendPasswordResetEmail(email): Firebase user को email से एक secure link भेजता है, जिसके through वे एक नया password set करते हैं, यह सब Firebase handle करता है, तो आपकी app कभी password touch नहीं करती। Option A impossible और insecure है: Firebase passwords को एक readable form में store नहीं करता (ये securely hashed होते हैं), तो दिखाने के लिए कोई 'old password' नहीं है, और passwords दिखाना एक serious security flaw होगा। Option C unnecessary और bad UX है: password reset करना उनका existing account और data रखता है। Option D एक dangerous anti-pattern है; passwords को कभी plain text में store मत कीजिए। Firebase को credentials handle करने दीजिए: reset email trigger कीजिए, और यह baaki securely करता है।
Think first
User के Email Address को Verify करने की Trouble क्यों उठाएँ?
User पहले से एक email से register हो चुका है। एक verification link क्यों भेजें और isEmailVerified check क्यों करें? फिर tap कीजिए।
Show the answer
क्योंकि एक email से register होना यह prove नहीं करता user actually उस address को OWN करता है, और email verification वह तरीका है जिससे आप confirm करते हैं वे करते हैं, जो security, communication, और trust के लिए matter करता है। जब कोई sign up करता है, वे कोई भी email type कर सकते हैं, एक mistyped email सहित, या किसी और का। Verification के बिना, आपके पास ऐसे accounts हो सकते हैं जो addresses से tied हैं जिन्हें उनके owners कभी नहीं देखते: password-reset emails wrong जगह जातीं, important notifications lost हो जातीं, और एक malicious user किसी और के email के under register कर सकता। Email verification इस gap को close करता है: Firebase दिए गए address को एक unique link email करता है, और सिर्फ़ वही जिसकी उस inbox तक access है इस पर click कर सकता है, ownership prove करते हुए। आपकी app फिर isEmailVerified check करती है और decide कर सकती है unverified users क्या कर सकते हैं, शायद उन्हें browse करने देते हुए पर एक event के लिए register करने या notices पाने से पहले verification require करते हुए। यह address के real owner को protect करता है, सुनिश्चित करता है आपके emails एक valid inbox तक पहुँचें, और fake या mistaken accounts घटाता है। यह reliability और security में बड़े payoffs वाला एक छोटा step है, यही वजह है serious apps onboarding के हिस्से की तरह emails verify करती हैं। और, password reset की तरह, Firebase sensitive part करता है, link भेजना और validate करना, तो आप बस इसे trigger करते हैं और flag check करते हैं। Address का ownership prove करना ही point है; एक typed email सिर्फ़ verify होने तक एक claim है।
Summary
Key takeaways
- Email/password authentication FirebaseAuth methods के through पूरे account lifecycle को cover करता है।
- createUserWithEmailAndPassword से register कीजिए; signInWithEmailAndPassword से log in कीजिए; signOut() से log out कीजिए।
- Password reset: sendPasswordResetEmail(email) call कीजिए, और Firebase एक secure reset link email करता है; आप कभी passwords खुद store या reset नहीं करते।
- Email verification: currentUser.sendEmailVerification() call कीजिए, फिर currentUser.isEmailVerified check कीजिए।
- Firebase sensitive credential work handle करता है, raw passwords को आपकी app से बाहर रखते हुए।
- Email verification confirm करता है user actually address own करता है, security और reliable communication improve करते हुए।
- Memory hook: create, signIn, signOut, sendPasswordResetEmail, sendEmailVerification, Firebase risky parts करता है।