You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter调用Firebase Functions时持续触发Unauthenticated错误

排查Firebase Functions调用[firebase_functions/unauthenticated]错误方案

核心排查步骤

1. 优先查看Cloud Functions日志

登录Firebase控制台进入Cloud Functions,找到testFunction的实时日志,重点看Auth context:的输出:

  • 若输出为null:说明函数未收到有效用户认证令牌,问题出在客户端令牌传递环节
  • 若输出有用户UID:则排查函数端IAM权限或App Check验证逻辑

2. 确认Flutter端Firebase服务初始化顺序

确保Auth和App Check在Cloud Functions前完成初始化,避免令牌未准备好就发起请求:

void main() async {
  WidgetsFlutterBinding.ensureInitialized();
  await Firebase.initializeApp();
  // 等待Auth初始化完成
  await FirebaseAuth.instance.authStateChanges().first;
  // 激活App Check
  await FirebaseAppCheck.instance.activate(
    androidProvider: AndroidProvider.playIntegrity,
    appleProvider: AppleProvider.appAttest,
  );
  runApp(MyApp());
}

3. 强制刷新用户ID令牌

用户本地缓存的令牌可能过期,手动刷新后再测试:

User? user = FirebaseAuth.instance.currentUser;
if (user != null) {
  await user.getIdToken(true); // 强制刷新令牌
}

4. 检查Cloud Functions的IAM权限

登录Google Cloud Console,找到目标函数进入「权限」标签页:

  • 确认已添加allAuthenticatedUsers角色(或更精细的认证用户权限)
  • 若权限被手动修改,恢复默认的认证用户访问权限

5. 验证Firebase Auth令牌有效性

获取用户令牌后验证是否合法:

String? token = await user?.getIdToken();

用Firebase CLI命令验证:

firebase auth:verify-id-token <你的令牌>

若验证失败,说明令牌无效,需检查用户会话或Auth配置

6. 统一Firebase包版本

确保cloud_functions与其他Firebase包版本兼容,避免版本冲突导致令牌传递失败:

dependencies:
  firebase_core: ^2.24.0
  firebase_auth: ^4.16.0
  cloud_functions: ^4.6.0
  firebase_app_check: ^0.2.1+11

临时排查方案

暂时注释函数内的App Check验证逻辑,重新部署后测试:

  • 若调用成功:说明App Check验证环节存在问题(客户端令牌有效但函数端验证失败)
  • 若仍失败:问题集中在用户认证环节

手动传递令牌的兜底方案

如果自动传递令牌失效,手动在请求头附加令牌:

final HttpsCallable callable = FirebaseFunctions.instance.httpsCallable('testFunction');
final token = await user?.getIdToken();
final response = await callable.call(
  options: HttpsCallableOptions(
    headers: {'Authorization': 'Bearer $token'},
  ),
);

函数端手动验证令牌:

const { getAuth } = require("firebase-admin/auth");

exports.testFunction = functions.https.onCall(async (data, context) => {
  const token = context.rawRequest.headers.authorization?.split('Bearer ')[1];
  if (!token) {
    throw new functions.https.HttpsError('unauthenticated', 'No token provided');
  }
  try {
    const decodedToken = await getAuth().verifyIdToken(token);
    context.auth = { uid: decodedToken.uid };
  } catch (e) {
    throw new functions.https.HttpsError('unauthenticated', 'Invalid token');
  }

  // 后续逻辑...
  return {message: "Authentication and App Check are working!"};
});

内容的提问来源于stack exchange,提问作者Android_devNL

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 03:50:55