现有Google Cloud项目无法在Firebase显示,需集成实现指定域Google Auth2.0登录
Hey there! Let's tackle your problems step by step—first getting your existing GCP project hooked up to Firebase, then setting up Google Auth to only let users from your custom domain log in.
It’s common to not see your existing GCP project in the Firebase console’s project list by default—here’s how to fix that:
Option A: Link via GCP Console
- Head to the GCP Console and select your IIMA Student App project.
- Use the search bar to find and open the Firebase page (under the "Products" section).
- Click the Add Firebase button. Follow the prompts to complete the link. Even if you’ve exhausted Firebase’s free tier, you can upgrade to the Blaze pay-as-you-go plan—most Auth features have generous free usage limits, so you’ll only pay if you exceed them.
- Once linked, your project will show up in the Firebase Console’s project list.
Option B: Link via Firebase CLI
If you prefer command-line tools:
- Install the Firebase CLI:
npm install -g firebase-tools - Log in to your Google account:
firebase login - Associate your GCP project with Firebase:
Select your IIMA Student App from the list of projects, and follow the prompts to finish linking.firebase use --add
Once your project is linked to Firebase, setting up domain-restricted login is straightforward. Here are the most reliable methods:
Method 1: Client-Side Validation (Quick & Simple)
After a user signs in with Google, check their email domain directly in your Android code:
val currentUser = FirebaseAuth.getInstance().currentUser currentUser?.let { user -> val userEmail = user.email if (userEmail != null && userEmail.endsWith("@mydomain.com")) { // User is allowed—navigate to your app's main screen } else { // Reject the login: sign out and show an error message FirebaseAuth.getInstance().signOut() Toast.makeText(this, "Only users with @mydomain.com emails are allowed", Toast.LENGTH_LONG).show() } }
Method 2: Cloud Function Enforcement (Server-Side Security)
For stronger security (to prevent client-side tampering), use a Firebase Cloud Function to automatically delete users who don’t match your domain:
const functions = require("firebase-functions"); const admin = require("firebase-admin"); admin.initializeApp(); exports.blockNonDomainUsers = functions.auth.user().onCreate((user) => { const userEmail = user.email; if (userEmail && !userEmail.endsWith("@mydomain.com")) { return admin.auth().deleteUser(user.uid) .then(() => console.log(`Deleted unauthorized user: ${userEmail}`)) .catch(error => console.error(`Error deleting user: ${error}`)); } return null; });
Deploy this function via the Firebase CLI with firebase deploy --only functions.
Method 3: Firestore Security Rules (Restrict Data Access)
If you’re using Firestore, add rules to ensure only authorized users can access your app’s data:
rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /{document=**} { allow read, write: if request.auth != null && request.auth.token.email.matches(/.*@mydomain\.com$/); } } }
This adds an extra layer of security by blocking access to data even if a non-domain user somehow bypasses client-side checks.
内容的提问来源于stack exchange,提问作者Arnab_Mohanta

