You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在同一Firebase项目中配置Web与iOS的Sign in with Apple不同标识?

Firebase Auth适配Web与iOS不同标识实现Sign in with Apple的解决方案

核心思路:利用Apple开发者后台的主App ID关联多标识特性,配合Firebase Auth的多受众验证支持,实现同一Firebase项目下Web(Services ID)和iOS(Bundle ID)的Apple登录共存。

1. 确认Apple开发者后台配置

  • 主App ID(com.example.app)已启用Sign in with Apple权限
  • Services ID(com.example.app.web)关联至该主App ID,且配置了Web端的重定向URL(需与Firebase Auth中设置一致)
  • iOS Bundle ID(com.example.app)已启用Sign in with Apple,并归属同一主App ID

2. 修正Firebase Auth的Apple登录配置

  • 确保Firebase中使用的Apple密钥是关联主App ID(com.example.app)生成的,而非仅关联Services ID。该密钥需开启Sign in with Apple权限,且密钥ID、Team ID与Firebase配置完全匹配
  • Firebase控制台中,Apple登录的Services ID保持为com.example.app.web(保证Web端正常工作),无需修改——Firebase会自动验证同一主App ID下所有关联标识的ID Token

3. iOS/Expo端代码调整

Expo返回的ID Token受众为iOS Bundle ID,需正确转换为Firebase可识别的凭证:

import * as AppleAuthentication from 'expo-apple-authentication';
import { getAuth, signInWithCredential, OAuthProvider } from 'firebase/auth';

// 获取Apple登录凭证
const appleCredential = await AppleAuthentication.signInAsync({
  requestedScopes: [
    AppleAuthentication.AppleAuthenticationScope.FULL_NAME,
    AppleAuthentication.AppleAuthenticationScope.EMAIL,
  ],
});

// 转换为Firebase OAuth凭证
const auth = getAuth();
const appleProvider = new OAuthProvider('apple.com');
const firebaseCredential = appleProvider.credential({
  idToken: appleCredential.identityToken,
  rawNonce: appleCredential.nonce, // 确保nonce一致,防止重放攻击
});

// 完成登录
await signInWithCredential(auth, firebaseCredential);

4. 验证配置有效性

  • Web端:保持原有代码不变,使用Services IDcom.example.app.web即可正常登录
  • iOS端:运行上述代码,Firebase会验证ID Token的受众是否属于主App ID下的合法标识,验证通过后完成登录

失败原因复盘

  • 修改iOS Bundle ID为com.example.app.web失败:该标识已被Web端的Services ID占用,Apple开发者后台不允许重复注册
  • 修改Firebase Services ID为iOS Bundle ID:Web端Apple登录要求使用Services ID作为client_id,因此请求被Apple拒绝,触发invalid_request错误

额外检查项

  • Expo的app.json需正确配置iOS权限:
    {
      "expo": {
        "ios": {
          "bundleIdentifier": "com.example.app",
          "usesAppleSignIn": true
        }
      }
    }
    
  • 确保Apple开发者后台中,Web端重定向URL已添加到Services ID的允许列表,且与Firebase Auth配置一致

内容的提问来源于stack exchange,提问作者Takaki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 14:13:23