Firebase手机认证报错:设备因异常活动被封禁求助
Firebase手机号验证真机APK报错解决方案
问题描述
开发了一款使用Firebase Phone Authentication的应用,在模拟器测试时功能正常,但打包APK到真机测试时,始终收到报错:"We have blocked all requests from this device due to unusual activity. Try again later."。更换手机号、更换设备后仍出现相同错误。
相关实现代码
Future<void> phoneAuthentication (String phoneNumber) async { verificationCompleted(PhoneAuthCredential credential) async { await _auth.signInWithCredential(credential); print("TEST_LOG============verificationCompleted=========>"); showSnackBar("Authentication Successful"); } verificationFailed(FirebaseAuthException e) { print("TEST_LOG========failure=============>${e.message}"); showSnackBar("Authentication Failed: ${e.message}"); } codeSent(String verificationId, int? resendToken) { print("TEST_LOG===========Code shared==========>${verificationId}"); Navigator.push( context, MaterialPageRoute(builder: (context) => MyVerify( verificationId: verificationId, login: _loginController.text, email: _emailController.text, password: _passwordController.text, phoneNumber: _phoneNumberController.text, ) ), ); } codeAutoRetrievalTimeout(String verificationId) { print('TEST_LOG===========Time out==========>${verificationId}'); } showDialog( context: context, barrierDismissible: false, builder: (BuildContext context) { return Center( child: CircularProgressIndicator(), // Display CircularProgressIndicator ); }, ); showSnackBar('Verifying...'); await FirebaseAuth.instance.verifyPhoneNumber( phoneNumber: phoneNumber, timeout: const Duration(seconds: 60), verificationCompleted: verificationCompleted, verificationFailed: verificationFailed, codeSent: codeSent, codeAutoRetrievalTimeout: codeAutoRetrievalTimeout, ); Navigator.pop(context); }
问题原因及解决办法
1. 未配置发布签名证书的SHA值
模拟器用的是调试签名,打包APK用的是发布签名,两者SHA值不同,Firebase会拒绝未验证的发布APK请求。
- 操作:
- 用keytool命令生成发布密钥库的SHA-1和SHA-256:
keytool -list -v -keystore 你的发布密钥库路径 -alias 密钥别名 - 登录Firebase控制台,进入项目设置→应用,添加生成的SHA值
- 下载更新后的
google-services.json替换项目中的旧文件,重新打包APK
- 用keytool命令生成发布密钥库的SHA-1和SHA-256:
2. Firebase可疑活动保护误判
Firebase的安全检测机制可能把真机测试请求判定为异常活动。
- 操作:
- 进入Firebase控制台→Authentication→设置→高级
- 调整“可疑活动保护”的检测级别,或添加测试设备/号码到白名单
- 检查是否有过于严格的IP、设备限制规则
3. 发布APK配置与Firebase不匹配
包名不一致或google-services.json配置错误会导致验证失败。
- 操作:
- 确认
android/app/build.gradle中的applicationId和Firebase注册的包名完全一致 - 确保
google-services.json放在android/app目录下,打包时已正确引入
- 确认
4. 网络环境触发安全拦截
代理、VPN或时间偏差可能被Firebase判定为异常。
- 操作:
- 测试时关闭代理、VPN,使用普通移动数据或稳定WiFi
- 同步设备时间与网络时间,避免时间偏差触发检测
5. 未正式启用Phone Authentication服务
即使模拟器能运行,发布环境需要确保服务已启用。
- 操作:
- 进入Firebase控制台→Authentication→登录方法,确认“电话号码”登录已启用,且无额外限制条件
内容的提问来源于stack exchange,提问作者Sok Leaphea
相关产品推荐
相关产品推荐

