Theory
When login goes wrong
Authentication always succeed થતું નથી. User password ખોટો લખી શકે છે, પહેલેથી રહેલા emailથી register કરવાનો પ્રયત્ન કરી શકે છે, અથવા password બહુ weak પસંદ કરી શકે છે. જો app આ failures ignore કરે, તો userને કંઈ થતું નથી એવું લાગે અથવા crash થઈ શકે છે. Good app દરેક failure catch કરે છે અને userને કઈ વસ્તુ સુધારવી તે clearly કહે છે.
Firebase auth failures તમે પહેલેથી handle કરતા Task દ્વારા report કરે છે: જ્યારે Task fail થાય, ત્યારે task.exception કારણ બતાવે છે. આ lesson common auth errors અને તેમને friendly messagesમાં બદલવાની રીત સમજાવે છે. Error handling સારી રીતે કરવી polished app અને frustrating app વચ્ચેનો મોટો તફાવત છે.
At a glance
| Exception | Typical cause |
|---|---|
| FirebaseAuthInvalidUserException | આ email માટે account નથી (અથવા account disabled/deleted છે) |
| FirebaseAuthInvalidCredentialsException | Wrong password અથવા malformed email address |
| FirebaseAuthUserCollisionException | પહેલેથી ઉપયોગમાં રહેલા emailથી registration |
| FirebaseAuthWeakPasswordException | પસંદ કરેલો password ખૂબ weak છે (registration વખતે) |
Practical
Failed Taskને friendly messageમાં ફેરવવું
auth.signInWithEmailAndPassword(email, password)
.addOnCompleteListener { task ->
if (task.isSuccessful) {
// proceed to the app
} else {
val message = when (task.exception) {
is FirebaseAuthInvalidUserException ->
"No account found for that email."
is FirebaseAuthInvalidCredentialsException ->
"Incorrect email or password."
else -> "Sign-in failed. Please try again."
}
showError(message) // display it on your UI, do not crash
}
}Formula
Catch failure, guide user
Rule: auth failureને ક્યારેય silent અથવા raw ન છોડો. હંમેશા task.isSuccessful check કરો અને false હોય ત્યારે task.exception વાંચીને યોગ્ય message નક્કી કરો.
દરેક errorને clear, friendly message સાથે map કરો, જેમ કે: 'Incorrect email or password', 'આ email પહેલેથી registered છે, login કરવાનો પ્રયાસ કરો', 'કૃપા કરીને stronger password પસંદ કરો'. Raw exception અથવા stack trace userને ન બતાવો; તે confuse કરી શકે છે અને details leak કરી શકે છે. વધુ information reveal ન થાય તેનું પણ ધ્યાન રાખો. Security માટે 'no such user' કરતાં vague 'incorrect email or password' ઘણીવાર safer છે. Helpful અને safe messages userને success તરફ guide કરે છે.
Quiz
User પહેલેથી account ધરાવતા emailથી register કરવાનો પ્રયત્ન કરે છે. કઈ Firebase exception signal કરે છે અને appએ શું કરવું જોઈએ?
- FirebaseAuthWeakPasswordException; લાંબો password માંગવો
- FirebaseAuthUserCollisionException; 'આ email પહેલેથી registered છે, login કરવાનો પ્રયાસ કરો' જેવી friendly message બતાવવી
- Developer ધ્યાન આપે તે માટે app crash થવી જોઈએ
- કોઈ exception થતી નથી; duplicate silently ignore થાય છે
Show the answer
FirebaseAuthUserCollisionException; 'આ email પહેલેથી registered છે, login કરવાનો પ્રયાસ કરો' જેવી friendly message બતાવવી
પહેલેથી ઉપયોગમાં રહેલા emailથી registration કરવાથી FirebaseAuthUserCollisionException આવે છે. Appએ આ exception task.exceptionમાંથી catch કરીને clear, friendly message બતાવવી જોઈએ, જેમ કે 'આ email પહેલેથી registered છે, login કરવાનો પ્રયાસ કરો'. Option A ખોટી exception છે: FirebaseAuthWeakPasswordException password બહુ weak હોય ત્યારે આવે છે, duplicate email માટે નહીં. Option C bad practice છે: failed registration expected situation છે અને તેને gracefully handle કરવી જોઈએ, crash નહીં. Option D પણ ખોટું છે: Firebase collision report કરે છે જેથી તમે userને inform કરી શકો.
Think first
Auth errorમાં વધારે information reveal કરવી security risk કેમ હોઈ શકે?
‘આ email માટે account નથી’ જેવી precise message helpful લાગે છે. તો ‘incorrect email or password’ જેવી vague message વધુ safe કેમ હોઈ શકે? પછી tap.
Show the answer
કારણ કે overly precise auth errors attackersને useful information આપી શકે છે, ખાસ કરીને કોઈ email તમારા appમાં REGISTERED છે કે નહીં. આ techniqueને account enumeration કહે છે. માનો login error 'no account for that email' અને 'wrong password' વચ્ચે ફરક બતાવે છે. Attacker email addressesની list સાથે app probe કરી શકે છે: 'wrong password' મળેલા emails પર ચોક્કસ account છે, જ્યારે 'no account' મળેલા emails registered નથી. આ confirmed user-email list phishing, credential-stuffing અથવા social engineering માટે ઉપયોગી બની શકે છે, અને કોઈ ચોક્કસ વ્યક્તિ service વાપરે છે તે પણ reveal થઈ શકે છે. Login failures માટે એક vague message, જેમ કે 'incorrect email or password', attackerને email અસ્તિત્વમાં છે કે password ખોટો છે તે નક્કી કરવા દેતું નથી.
Usability અને security વચ્ચે trade-off છે: precise message honest user માટે વધુ helpful હોઈ શકે છે, ખાસ કરીને તે કયો email વાપર્યો હતો તે ભૂલી ગયો હોય ત્યારે. તેથી apps login વખતે vague message રાખે છે, જ્યારે safe હોય ત્યારે specific guidance આપે છે. Registration વખતે email પહેલેથી in use છે તે કહેવું અને weak password વખતે password stronger કરવાની સલાહ આપવી સામાન્ય છે. Principle એ છે કે legitimate userને મદદ કરવા જેટલી information આપો, પણ attackerને accountsનો map ન આપો.
Summary
Key takeaways
- Authentication predictable રીતે fail થઈ શકે છે; good apps દરેક failure catch કરીને clear message બતાવે છે.
- Failed Taskમાં task.exception કારણ ધરાવે છે; પહેલાં task.isSuccessful check કરો.
- Common exceptions: FirebaseAuthInvalidUserException (no such user), FirebaseAuthInvalidCredentialsException (wrong password/bad email), FirebaseAuthUserCollisionException (email already in use), FirebaseAuthWeakPasswordException (weak password).
- દરેક exceptionને friendly, actionable message સાથે map કરો; raw exception ન બતાવો અને failure silent ન છોડો.
- Registration વખતે collision એટલે 'આ email પહેલેથી registered છે'; weak password એટલે 'stronger password પસંદ કરો'.
- Email exists કે નહીં તે વધારે reveal કરવાનું ટાળો, જેથી account enumeration અટકાવી શકાય; vague login error ઘણીવાર safer છે.
- Memory hook: Task check કરો, exception type વાંચો, helpful અને safe message બતાવો.