Firebase OTP已接收但输入后无法验证,求技术解决方案
Firebase短信验证码输入后无法完成验证问题
问题描述
使用Firebase短信验证码(OTP)功能时,能正常接收验证码,但输入后无法完成验证。以下是相关实现代码:
验证码请求代码
PhoneAuthProvider.getInstance().verifyPhoneNumber( phoneNum, 30L /*timeout*/, TimeUnit.SECONDS, this, new PhoneAuthProvider.OnVerificationStateChangedCallbacks() { @Override public void onCodeSent(String verificationId, PhoneAuthProvider.ForceResendingToken forceResendingToken) { } @Override public void onVerificationCompleted(PhoneAuthCredential phoneAuthCredential) { VerificationCode = phoneAuthCredential.getSmsCode().toString(); } @Override public void onVerificationFailed(FirebaseException e) { Toasty.error(LoginActivity.this, e.getMessage(), Toast.LENGTH_SHORT).show(); } }); }
OTP验证代码
relative_layout_confirm_top_login_activity.setOnClickListener(v->{ if(otp_edit_text_login_activity.getText().toString().length()<6){ Toasty.error(this, "验证码输入错误!", Toast.LENGTH_SHORT).show(); }else{ if (otp_edit_text_login_activity.getText().toString().trim().equals(VerificationCode.toString().trim())){ String photo = "https://lh3.googleusercontent.com/-XdUIqdMkCWA/AAAAAAAAAAI/AAAAAAAAAAA/4252rscbv5M/photo.jpg" ; signUp(phoneNum,phoneNum,"null".toString(),"phone",photo); }else{ Toasty.error(this, "验证码输入错误!", Toast.LENGTH_SHORT).show(); } } });
问题分析与解决方法
核心问题
你当前的验证逻辑是直接对比本地存储的VerificationCode和用户输入的内容,这不符合Firebase OTP的标准验证流程,且存在以下隐患:
onVerificationCompleted仅在设备自动获取验证码(如系统短信自动填充)时触发,用户手动输入验证码时该方法不会执行,导致VerificationCode可能未被赋值,对比必然失败。- 本地字符串对比的方式存在安全风险,且未经过Firebase官方认证流程,无法确保验证的有效性。
修正后的实现方案
1. 保存验证ID
在onCodeSent回调中保存verificationId(后续验证必备):
private String verificationId; private PhoneAuthProvider.ForceResendingToken resendToken; @Override public void onCodeSent(String id, PhoneAuthProvider.ForceResendingToken token) { verificationId = id; resendToken = token; }
2. 修改验证逻辑
使用Firebase官方提供的凭证验证方式,替换本地字符串对比:
relative_layout_confirm_top_login_activity.setOnClickListener(v->{ String inputOtp = otp_edit_text_login_activity.getText().toString().trim(); if(inputOtp.length() != 6){ Toasty.error(this, "验证码输入错误!", Toast.LENGTH_SHORT).show(); return; } // 用verificationId和用户输入的验证码创建认证凭证 PhoneAuthCredential credential = PhoneAuthProvider.getCredential(verificationId, inputOtp); // 调用Firebase接口完成验证 signInWithPhoneAuthCredential(credential); });
3. 实现认证回调
编写signInWithPhoneAuthCredential方法处理验证结果:
private void signInWithPhoneAuthCredential(PhoneAuthCredential credential) { FirebaseAuth.getInstance().signInWithCredential(credential) .addOnCompleteListener(this, task -> { if (task.isSuccessful()) { // 验证成功,执行后续注册/登录逻辑 String photo = "https://lh3.googleusercontent.com/-XdUIqdMkCWA/AAAAAAAAAAI/AAAAAAAAAAA/4252rscbv5M/photo.jpg" ; signUp(phoneNum,phoneNum,"null".toString(),"phone",photo); } else { // 验证失败,根据错误类型提示 if (task.getException() instanceof FirebaseAuthInvalidCredentialsException) { Toasty.error(this, "验证码输入错误!", Toast.LENGTH_SHORT).show(); } else { Toasty.error(this, "验证失败:" + task.getException().getMessage(), Toast.LENGTH_SHORT).show(); } } }); }
额外注意事项
- 移除原有的
VerificationCode变量,避免空指针异常 - 若需要支持验证码重发,可使用保存的
resendToken调用verifyPhoneNumber的重载方法
内容的提问来源于stack exchange,提问作者Chandu 4ever
相关产品推荐
相关产品推荐

