Handling Firebase Authentication Error

Authentication predictable तरीकों से fail होता है, wrong password, email already registered, weak password, no such user, और good apps failed Task से हर एक को catch करती हैं और user को एक clear, friendly message दिखाती हैं एक crash या blank screen की बजाय।

10 min read · 7 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

जब Login गलत होता है

Authentication हमेशा succeed नहीं होता। एक user अपना password mistype करता है, एक ऐसा email register करने की कोशिश करता है जो पहले से exist करता है, या एक password चुनता है जो बहुत weak है। अगर आपकी app इन failures को ignore करती है, user को कुछ होते नहीं दिखता, या worse, एक crash। एक good app हर failure को catch करती है और user को clearly बताती है क्या fix करना है।

Firebase auth failures उस Task के through report करता है जो आप पहले से handle करते हैं: जब यह fail होती है, task.exception बताता है क्यों। यह lesson common auth errors और इन्हें friendly messages में बदलने का तरीका cover करता है। Errors अच्छी तरह handle करना ही एक polished app को एक frustrating app से अलग करता है।

At a glance

ExceptionTypical Cause
FirebaseAuthInvalidUserExceptionउस email के लिए कोई account नहीं (या यह disabled/deleted है)
FirebaseAuthInvalidCredentialsExceptionWrong password, या एक malformed email address
FirebaseAuthUserCollisionExceptionएक email register करना जो पहले से इस्तेमाल में है
FirebaseAuthWeakPasswordExceptionChosen password बहुत weak है (registration पर)

Practical

एक Failed Task को एक Friendly Message में बदलना

auth.signInWithEmailAndPassword(email, password)
    .addOnCompleteListener { task ->
        if (task.isSuccessful) {
            // proceed to the app
        } else {
            val message = when (task.exception) {
                is FirebaseAuthInvalidUserException ->
                    "No account found for that email."
                is FirebaseAuthInvalidCredentialsException ->
                    "Incorrect email or password."
                else -> "Sign-in failed. Please try again."
            }
            showError(message)   // display it on your UI, do not crash
        }
    }

Formula

Failure Catch कीजिए, User को Guide कीजिए

Rule: कभी भी एक auth failure को silent या raw मत रहने दीजिए। हमेशा task.isSuccessful check कीजिए, और जब यह false हो, decide करने के लिए task.exception पढ़िए क्या कहना है।

हर error को एक clear, friendly message से map कीजिए जिस पर user act कर सके: 'Incorrect email or password', 'That email is already registered, try logging in', 'Please choose a stronger password'। Raw exception या stack trace मत दिखाइए, यह users को confuse करता है और details leak कर सकता है। और सावधान रहिए बहुत ज़्यादा reveal न करें (security के लिए, एक vague 'incorrect email or password' अक्सर 'no such user' से बेहतर है, जो एक attacker को बताता है कौन से emails exist करते हैं)। Helpful, safe messages user को success तक guide करते हैं।

Quiz

एक user एक ऐसे email से register करने की कोशिश करता है जिसका already एक account है। कौन सी Firebase exception यह signal करती है, और app को कैसे respond करना चाहिए?

  1. FirebaseAuthWeakPasswordException; एक longer password मांगिए
  2. FirebaseAuthUserCollisionException; 'That email is already registered, try logging in' जैसा एक friendly message दिखाइए
  3. इसे crash होना चाहिए तो developer को पता चले
  4. कोई exception नहीं होती; duplicate को silently ignore किया जाता है
Show the answer

FirebaseAuthUserCollisionException; 'That email is already registered, try logging in' जैसा एक friendly message दिखाइए

पहले से इस्तेमाल में एक email register करना FirebaseAuthUserCollisionException raise करता है, और app को इसे task.exception से catch करना चाहिए और एक clear, friendly message दिखाना चाहिए जैसे 'That email is already registered, try logging in'। Option A wrong exception name करता है: FirebaseAuthWeakPasswordException एक बहुत weak password के लिए है, एक duplicate email के लिए नहीं। Option C bad practice है: एक failed registration एक expected situation है gracefully handle करने के लिए, crash होने का reason नहीं। Option D wrong है: Firebase इसे silently ignore नहीं करता; यह collision report करता है तो आप user को inform कर सकें। Exception को cause से match कीजिए और इसे helpful guidance में बदलिए।

Think first

एक Auth Error में बहुत ज़्यादा Reveal करना एक Security Risk क्यों हो सकता है?

'no account exists for that email' जैसा एक precise message helpful लगता है। एक vaguer 'incorrect email or password' safer क्यों हो सकता है? फिर tap कीजिए।

Show the answer

क्योंकि overly precise auth errors ऐसी information leak कर सकती हैं जो attackers की help करती है, most notably क्या एक given email आपकी app पर REGISTERED है, एक technique जिसे account enumeration कहते हैं। मान लीजिए आपका login error 'no account for that email' को 'wrong password' से distinguish करता है। एक attacker अब आपकी app को email addresses की एक list से probe कर सकता है: जो 'wrong password' return करते हैं clearly accounts HAVE करते हैं, जबकि 'no account' वाले नहीं। यह इन्हें आपके users के emails की एक confirmed list देता है, जिसे वे phishing, credential-stuffing (दूसरे breaches से leaked passwords try करना), या social engineering से target कर सकते हैं, और यह यहाँ तक reveal कर सकता है कि एक specific person आपकी service इस्तेमाल करता है, खुद में एक privacy concern। Login failures के लिए एक single, vaguer message इस्तेमाल करना, जैसे 'incorrect email or password', attacker को वह signal deny करता है: वे नहीं बता सकते email exist करता है या password गलत था, तो probing कुछ भी useful yield नहीं करती। Usability के साथ एक genuine trade-off है (एक precise message honest users के लिए friendlier है जो simply भूल गए वे कौन सा email इस्तेमाल करते थे), तो बहुत सी apps इसे balance करती हैं, login पर vaguer रहते हुए फिर भी clear, specific guidance देते हुए जहाँ यह safe हो (उदाहरण के लिए, registration पर आप कह सकते हैं एक email पहले से इस्तेमाल में है, और password strength के लिए आप कह सकते हैं password बहुत weak है)। Principle है legitimate users की help करने के लिए enough reveal करना बिना attackers को अपने accounts का एक map हाथ में दिए। Users के लिए helpful, attackers के लिए unhelpful, यही balance है जो aim करना है।

Summary

Key takeaways

  • Authentication predictable तरीकों से fail होता है; good apps हर failure catch करती हैं और एक clear message दिखाती हैं।
  • एक failed Task पर, task.exception reason hold करता है; पहले task.isSuccessful check कीजिए।
  • Common exceptions: FirebaseAuthInvalidUserException (no such user), FirebaseAuthInvalidCredentialsException (wrong password/bad email), FirebaseAuthUserCollisionException (email already in use), FirebaseAuthWeakPasswordException (weak password)।
  • हर एक को एक friendly, actionable message से map कीजिए; कभी raw exceptions मत दिखाइए या failures silent मत छोड़िए।
  • Registration पर, एक collision का मतलब है 'that email is already registered'; एक weak password का मतलब है 'choose a stronger one'।
  • बहुत ज़्यादा reveal करने से बचिए (जैसे एक email exist करता है या नहीं) account enumeration रोकने के लिए; एक vague login error अक्सर safer है।
  • Memory hook: Task check कीजिए, exception type पढ़िए, एक helpful और safe message दिखाइए।

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from FirebaseUI Auth authentication

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Handling Firebase Authentication Error · Advance Mobile Application Development - II (Major-15-02) · Gri-Learn