为何Firebase身份验证返回invalid-credentials而非user-not-found?
问题:输入未注册账号时Firebase身份验证返回
invalid-credentials而非user-not-found的原因? 当输入未注册的账号凭证时,Firebase身份验证返回的错误码是invalid-credentials,而非预期的user-not-found,请问这是什么原因?
以下是使用的Dart代码:
try { final userCredential = await FirebaseAuth.instance .signInWithEmailAndPassword( email: email, password: password, ); print(userCredential); } on FirebaseAuthException catch (e) { print("FirebaseAuthException: $e"); print("Complete exception details: ${e.toString()}"); if (e.code == 'user-not-found') { print('User not found'); } else { // Handle other specific error cases if needed } }
原因分析
这是因为Firebase Auth默认启用了防止枚举攻击的安全机制。为避免恶意攻击者通过错误信息批量判断哪些邮箱已注册,Firebase会统一返回invalid-credentials错误,不再区分user-not-found和wrong-password两种情况。
如果确实需要区分这两类错误,可在Firebase控制台调整设置:
- 进入Firebase控制台 → 身份验证 → 设置 → 高级
- 找到“防止枚举攻击”选项并关闭
注意:关闭该机制会降低账号隐私安全性,需根据业务需求权衡利弊。
内容的提问来源于stack exchange,提问作者TM12
相关产品推荐
相关产品推荐

