Theory
एक Account से Log In कीजिए जो पहले से आपके पास है
Users को एक और password invent कराना friction है; बहुत से bother नहीं करेंगे। Google Sign-In इसे हटाता है: users FestConnect में अपने existing Google account से log in करते हैं, नए credentials create करने की बजाय इसे choose करने के लिए tap करते हुए।
यह federated authentication है, user Google को prove करता है वे कौन हैं, और Firebase इस पर trust करता है। यह lesson flow दिखाता है और वह एक नया idea जो यह introduce करता है: एक Google token को एक Firebase credential से exchange करना। यह एक pattern है जो आप Facebook और दूसरे providers के लिए reuse करेंगे, तो इसे यहाँ एक बार सीखिए।
Theory
Federated Flow
Google Sign-In कुछ steps में काम करता है:
1. आपकी app Google sign-in flow launch करती है।
2. User अपना Google account pick करता है (और approve करता है, अगर पहली बार है)।
3. Google एक Google ID token return करता है, proof कि Google ने इस user को authenticate किया।
4. आपकी app उस token को GoogleAuthProvider.getCredential(idToken, null) से एक Firebase credential की तरह wrap करती है।
5. आप auth.signInWithCredential(credential) call करते हैं, और Firebase user को sign in करता है।
इसके बाद, user एक normal FirebaseUser है (currentUser set है), exactly email/password की तरह, बस Google के through authenticated। आप पहले Firebase console में Google को एक provider की तरह enable भी करते हैं।
Practical
Google Token को एक Firebase Sign-In से Exchange करना
// After the Google sign-in flow returns a Google ID token:
val credential = GoogleAuthProvider.getCredential(idToken, null)
Firebase.auth.signInWithCredential(credential)
.addOnCompleteListener { task ->
if (task.isSuccessful) {
val user = Firebase.auth.currentUser // signed in via Google
} else {
// handle task.exception
}
}
// The user never created a password for your app; Google vouched for them.Formula
Token-to-Credential Pattern
हर federated sign-in का heart same है: provider (Google) user को authenticate करता है और आपको एक token देता है; आप उस token को एक Firebase credential में बदलते हैं और signInWithCredential call करते हैं।
Google के लिए यह GoogleAuthProvider.getCredential(...) है; Facebook के लिए (अगला lesson) यह FacebookAuthProvider.getCredential(...) होगा। बाकी, signInWithCredential और resulting FirebaseUser, identical है। तो एक बार आप समझ लें 'provider से एक token पाइए, इसे एक Firebase credential से exchange कीजिए', आप सभी federated logins समझ जाते हैं। वह shared shape ही है जिस वजह से Firebase कई providers को cleanly support कर सकता है।
Quiz
Firebase के साथ Google Sign-In में, आपकी app को मिलने वाले Google ID token के साथ आप क्या करते हैं?
- इसे user के password की तरह store कीजिए
- इसे एक Firebase credential की तरह wrap कीजिए (GoogleAuthProvider.getCredential) और user को Firebase में sign in करने के लिए signInWithCredential call कीजिए
- इसे user को email कीजिए
- इसे ignore कीजिए; Firebase को इसकी ज़रूरत नहीं
Show the answer
इसे एक Firebase credential की तरह wrap कीजिए (GoogleAuthProvider.getCredential) और user को Firebase में sign in करने के लिए signInWithCredential call कीजिए
Google ID token proof है कि Google ने user को authenticate किया; आप इसे GoogleAuthProvider.getCredential(idToken, null) से एक Firebase credential में convert करते हैं और इसे auth.signInWithCredential(...) को pass करते हैं, जो user को Firebase में sign in करता है। Option A wrong है: token store करने के लिए एक password नहीं है; यह एक Firebase sign-in के लिए exchange होने वाला identity का one-time proof है। Option C कोई sense नहीं बनाता; token programmatically इस्तेमाल होता है, email नहीं होता। Option D wrong है: token exactly वह है जो Firebase federated sign-in complete करने के लिए चाहिए, इसे ignore करने का मतलब है user कभी sign in नहीं होगा। Pattern: provider token -> Firebase credential -> signInWithCredential।
Think first
Users को Password Create कराने की बजाय Google से Sign In करने क्यों दें?
Google जैसे federated sign-in से users और developers क्या पाते हैं? फिर tap कीजिए।
Show the answer
दोनों sides CONVENIENCE और SECURITY पाते हैं, क्योंकि user एक trusted account reuse करता है जो उनके पास पहले से है बजाय एक और password create और manage करने के। USER के लिए: sign up करना उनका Google account choose करने के लिए एक single tap बन जाता है, invent, याद रखने, या बाद में reset करने के लिए कोई नया password नहीं, जो getting started की friction dramatically कम करता है (बहुत से लोग वे sign-ups abandon करते हैं जो एक नया account demand करते हैं)। वे यह भी trust करते हैं कि Google उनके credentials guard करे, और उन्हें आपकी app पर free में Google की protections मिलती हैं (strong passwords और two-factor authentication जैसी)। DEVELOPER और app के लिए: आप उस user का password कभी handle या store नहीं करते बिल्कुल, Google इन्हें authenticate करता है और इनके लिए vouch करता है, तो आपके system में protect करने के लिए एक कम sensitive credential है, और एक कम attack surface। आपको provider से reliable profile information (verified email, name) भी मिलती है। Trade-offs: आप provider पर depend करते हैं, और कुछ users accounts link करना prefer नहीं करते, यही वजह है apps usually federated options (Google, Facebook) AND plain email/password दोनों offer करती हैं, हर user को choose करने देते हुए। Federated sign-in popular है exactly इसलिए क्योंकि यह onboarding को लगभग effortless बनाता है security improve करते हुए, एक rare win-win, यही वजह है 'Sign in with Google' offer करना modern apps में standard practice है। एक trusted identity reuse कीजिए: users के लिए easier, आपके लिए safer।
Summary
Key takeaways
- Google Sign-In federated authentication है: user अपने existing Google account से log in करता है, आपकी app में एक password से नहीं।
- Flow: Google sign-in launch कीजिए, user एक account pick करता है, आपको एक Google ID token मिलता है।
- Token को GoogleAuthProvider.getCredential(idToken, null) से एक Firebase credential की तरह wrap कीजिए।
- auth.signInWithCredential(credential) call कीजिए; success पर user एक normal FirebaseUser है।
- पहले Firebase console में Google को एक provider की तरह enable कीजिए।
- Token-to-credential pattern सभी federated providers के across shared है (Facebook FacebookAuthProvider को same तरीके से इस्तेमाल करता है)।
- Memory hook: provider एक token देता है, इसे एक Firebase credential से exchange कीजिए, signInWithCredential।