E-Mail and Password authentication: User Registration, Manage Login/Logout, Password Reset and E-Mail verification

Email और password authentication पूरा account lifecycle है: एक user register कीजिए, उन्हें log in और out कराइए, उन्हें एक भूला हुआ password reset करने दीजिए, और उनका email address verify कीजिए, यह सब FirebaseAuth methods के through।

11 min read · 7 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

एक Account की पूरी Life

एक real app सिर्फ़ users को log in नहीं कराती। एक account की life में इसे नए users register करने पड़ते हैं, इन्हें log in और out कराना पड़ता है, जब वे अपना password भूल जाएँ तब मदद करनी पड़ती है, और confirm करना पड़ता है वे actually अपना email address own करते हैं। Firebase Authentication हर एक के लिए एक method provide करता है, तो आपको बिना कुछ भी खुद build किए पूरा lifecycle मिलता है।

यह lesson email और password authentication को end to end walk through करता है: registration, login, logout, password reset, और email verification। ये everyday auth features हैं जो FestConnect Mobile को चाहिए।

Theory

Register, Log In, Log Out

तीन basics जो आप SDK के साथ मिले:

  • Register: createUserWithEmailAndPassword(email, password) account create करता है (और success पर user को sign in करता है)।
  • Log in: signInWithEmailAndPassword(email, password) एक existing user के लिए।
  • Log out: auth.signOut() session end करता है, जिसके बाद auth.currentUser null है।

हर networked call एक Task return करता है जिसे आप एक listener से handle करते हैं। सिर्फ़ इन तीन के साथ, एक user एक account create कर सकता है और आ-जा सकता है। पर दो और features experience को complete और secure बनाते हैं: एक भूला हुआ password reset करना और email verify करना।

Practical

Password Reset और Email Verification

val auth = Firebase.auth

// Password reset: Firebase emails a reset link to the address
auth.sendPasswordResetEmail(email)
    .addOnCompleteListener { task ->
        if (task.isSuccessful) { /* tell user to check their inbox */ }
    }

// Email verification: send a verification link to the signed-in user
auth.currentUser?.sendEmailVerification()

// Later, check whether they have verified:
val verified = auth.currentUser?.isEmailVerified ?: false

Formula

Firebase Passwords Handle करता है; आप कभी नहीं

Notice कीजिए आप क्या NOT करते हैं: आप कभी passwords store नहीं करते, और आप कभी इन्हें खुद reset नहीं करते। जब एक user अपना password भूल जाता है, आप sendPasswordResetEmail call करते हैं, और Firebase इन्हें एक secure reset link email करता है; user एक नया password Firebase के through set करता है, आपके code के through नहीं।

Similarly, email verification Firebase एक confirmation link email कर रहा होता है; आप बस इसे trigger करते हैं और बाद में isEmailVerified check करते हैं। यह एक security win है: sensitive credential handling Firebase के trusted system के अंदर रहती है, तो आपकी app कभी raw passwords touch नहीं करती या risky reset flows build नहीं करती। Feature trigger कीजिए, sensitive part Firebase को करने दीजिए।

Quiz

एक FestConnect user अपना password भूल गया। Correct Firebase approach क्या है?

  1. Database से उनका पुराना password पढ़िए और उन्हें दिखाइए
  2. auth.sendPasswordResetEmail(email) call कीजिए; Firebase उन्हें एक नया password set करने के लिए एक secure link email करता है
  3. उन्हें एक पूरा नया account create करने के लिए कहिए
  4. Passwords को plain text में store कीजिए तो आप इन्हें look up कर सकें
Show the answer

auth.sendPasswordResetEmail(email) call कीजिए; Firebase उन्हें एक नया password set करने के लिए एक secure link email करता है

Correct approach है auth.sendPasswordResetEmail(email): Firebase user को email से एक secure link भेजता है, जिसके through वे एक नया password set करते हैं, यह सब Firebase handle करता है, तो आपकी app कभी password touch नहीं करती। Option A impossible और insecure है: Firebase passwords को एक readable form में store नहीं करता (ये securely hashed होते हैं), तो दिखाने के लिए कोई 'old password' नहीं है, और passwords दिखाना एक serious security flaw होगा। Option C unnecessary और bad UX है: password reset करना उनका existing account और data रखता है। Option D एक dangerous anti-pattern है; passwords को कभी plain text में store मत कीजिए। Firebase को credentials handle करने दीजिए: reset email trigger कीजिए, और यह baaki securely करता है।

Think first

User के Email Address को Verify करने की Trouble क्यों उठाएँ?

User पहले से एक email से register हो चुका है। एक verification link क्यों भेजें और isEmailVerified check क्यों करें? फिर tap कीजिए।

Show the answer

क्योंकि एक email से register होना यह prove नहीं करता user actually उस address को OWN करता है, और email verification वह तरीका है जिससे आप confirm करते हैं वे करते हैं, जो security, communication, और trust के लिए matter करता है। जब कोई sign up करता है, वे कोई भी email type कर सकते हैं, एक mistyped email सहित, या किसी और का। Verification के बिना, आपके पास ऐसे accounts हो सकते हैं जो addresses से tied हैं जिन्हें उनके owners कभी नहीं देखते: password-reset emails wrong जगह जातीं, important notifications lost हो जातीं, और एक malicious user किसी और के email के under register कर सकता। Email verification इस gap को close करता है: Firebase दिए गए address को एक unique link email करता है, और सिर्फ़ वही जिसकी उस inbox तक access है इस पर click कर सकता है, ownership prove करते हुए। आपकी app फिर isEmailVerified check करती है और decide कर सकती है unverified users क्या कर सकते हैं, शायद उन्हें browse करने देते हुए पर एक event के लिए register करने या notices पाने से पहले verification require करते हुए। यह address के real owner को protect करता है, सुनिश्चित करता है आपके emails एक valid inbox तक पहुँचें, और fake या mistaken accounts घटाता है। यह reliability और security में बड़े payoffs वाला एक छोटा step है, यही वजह है serious apps onboarding के हिस्से की तरह emails verify करती हैं। और, password reset की तरह, Firebase sensitive part करता है, link भेजना और validate करना, तो आप बस इसे trigger करते हैं और flag check करते हैं। Address का ownership prove करना ही point है; एक typed email सिर्फ़ verify होने तक एक claim है।

Summary

Key takeaways

  • Email/password authentication FirebaseAuth methods के through पूरे account lifecycle को cover करता है।
  • createUserWithEmailAndPassword से register कीजिए; signInWithEmailAndPassword से log in कीजिए; signOut() से log out कीजिए।
  • Password reset: sendPasswordResetEmail(email) call कीजिए, और Firebase एक secure reset link email करता है; आप कभी passwords खुद store या reset नहीं करते।
  • Email verification: currentUser.sendEmailVerification() call कीजिए, फिर currentUser.isEmailVerified check कीजिए।
  • Firebase sensitive credential work handle करता है, raw passwords को आपकी app से बाहर रखते हुए।
  • Email verification confirm करता है user actually address own करता है, security और reliable communication improve करते हुए।
  • Memory hook: create, signIn, signOut, sendPasswordResetEmail, sendEmailVerification, Firebase risky parts करता है।

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from FirebaseUI Auth authentication

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati