Knowledgebase

Firebase Authentication Print

  • googletechnology, google, password, email, security, domainrenewal, guide, howto
  • 0

Identifying users.

WHAT IT PROVIDES

Sign-in with email and password, phone, and federated providers Anonymous sign-in Token issuance and refresh Integration with security rules

WHY IT IS WIDELY USED

It removes password handling, which is easy to implement subtly wrong.

WHAT TO ENABLE

Only the providers you actually offer.

WHAT TO CONFIGURE

Email enumeration protection Password policy Authorised domains

WHAT TO KNOW ABOUT PHONE AUTHENTICATION

It costs money per verification, and is a common target for abuse.

WHAT ABUSE LOOKS LIKE

Automated requests generating verification messages, at your expense.

WHAT TO DO ABOUT IT

Enable the platform's abuse protection, and monitor volume.

WHY THAT MATTERS LOCALLY

Message costs vary by country, and some are targeted deliberately.

WHAT CUSTOM CLAIMS PROVIDE

Additional information in the token, such as a role.

WHAT TO USE THEM FOR

Authorisation decisions in security rules.

WHAT TO NEVER DO

Let a client set its own claims.

WHAT TO SET THEM FROM

Server-side code only.

WHAT TO HANDLE

Token expiry and refresh Sign-out, revoking server-side


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot