Jetpack Compose中Firebase Apple登录遇403请求被阻问题排查
问题背景
我正在Jetpack Compose应用中通过Firebase实现Apple登录,对应iOS应用已在同一Firebase服务器完成Apple登录配置(包含Services ID、Apple Team ID、Key ID、私钥及授权URL),Firebase相关配置已完成。点击登录按钮弹出Chrome标签页后,出现403错误:
{"error":{"code":403,"message":"Requests from this Android client application are blocked.","errors":[{"message":"Requests from this Android client application are blocked.","domain":"global","reason":"forbidden"}],"status":"PERMISSION_DENIED","details":[{"@type":"type.googleapis.com/google.rpc.ErrorInfo","reason":"API_KEY_ANDROID_APP_BLOCKED","domain":"googleapis.com","metadata":{"service":"identitytoolkit.googleapis.com","consumer":"projects/952288320256"}}]}}
相关代码
Apple登录核心类及方法
class ContinueWithApple( private val context: Context, private val appLanguage: String, private val isSigningIn: MutableState<Boolean> ): Register() { fun singIn() { isSigningIn.value = true userIsAlreadySigningIn(auth, isSigningIn) { if (!it) { singInUser( auth = auth, context = context, appLanguage = appLanguage, isSigningIn = isSigningIn ) { } } //: END IF } //: USER IS ALREADY SIGNING IN } //: FUN } //: CLASS fun userIsAlreadySigningIn( auth: FirebaseAuth, isSigningIn: MutableState<Boolean>, completion: (Boolean) -> Unit ) { val pending = auth.pendingAuthResult if (pending != null) { pending .addOnSuccessListener { authResult -> Log.d("SIGN IN WITH APPLE", "checkPending:onSuccess:$authResult") isSigningIn.value = false completion(true) } //: ON SUCCESS .addOnFailureListener { e -> Log.w("SIGN IN WITH APPLE", "checkPending:onFailure", e) isSigningIn.value = false completion(true) } //: ON FAILURE } else { Log.d("SIGN IN WITH APPLE", "pending: null") completion(false) } //: END IF } //: FUN fun singInUser( auth: FirebaseAuth, context: Context, appLanguage: String, isSigningIn: MutableState<Boolean>, completion: (FirebaseUser?) -> Unit ) { val provider = OAuthProvider .newBuilder("apple.com") .setScopes(mutableListOf("email", "name")) .addCustomParameter("locale", HelperFunctions.currentLanguageLocale(appLanguage)) .build() auth .startActivityForSignInWithProvider(context.getActivity(), provider) .addOnSuccessListener { authResult -> Log.d("SIGN IN WITH APPLE", "activitySignIn:onSuccess:${authResult.user}") completion(authResult.user) } //: ON SUCCESS .addOnFailureListener { e -> Log.w("SIGN IN WITH APPLE", "activitySignIn:onFailure", e) isSigningIn.value = false completion(null) } //: ON FAILURE } //: FUN
Context转Activity工具方法
internal fun Context.getActivity(): Activity { var context = this while (context is ContextWrapper) { if (context is Activity) return context context = context.baseContext } throw IllegalStateException("Permissions should be called in the context of an Activity") }
错误原因分析及解决方案
错误信息中的*API_KEY_ANDROID_APP_BLOCKED*明确指出是Android应用的API Key被阻止,核心原因是Firebase控制台未正确配置Android应用的签名信息或API Key限制。
排查步骤:
- 检查Firebase控制台的Android应用配置:确认Firebase项目中已添加当前Android应用,包名与项目一致;核对应用的SHA-1/SHA-256签名指纹是否正确添加,注意区分调试和发布签名,两种环境都需要配置。
- 检查API Key的限制设置:进入关联的Google Cloud控制台,找到
identitytoolkit.googleapis.com服务对应的API Key,确保未设置过于严格的限制(比如仅允许特定包名/签名应用调用,而当前应用信息未包含在内)。 - 验证google-services.json文件:重新下载Firebase控制台的
google-services.json文件替换项目旧文件,确保文件中的包名、签名指纹等信息与当前应用匹配。 - 确认Apple登录跨平台配置:虽然iOS端已配置,仍需检查Firebase控制台的Apple登录设置中,是否允许Android应用使用该配置,授权URL等参数是否对Android端生效。
内容的提问来源于stack exchange,提问作者Iraklis Eleftheriadis

