You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python操作Firestore查询时调用find方法触发AttributeError报错

问题背景

基于Firebase数据库、hashlib库开发带登录、注册功能的终端应用时,尝试将查询获取的用户信息、哈希密码赋值给变量时持续触发报错,所有依赖包均已正确安装,问题仍未解决。

原实现代码
import firebase_admin, hashlib
from firebase_admin import firestore
from firebase_admin import credentials

cred = credentials.Certificate("serviceAccountKey.json")
firebase_admin.initialize_app(cred)
db = firestore.client()
ask = input("Do you want to login or signup?\n")
if ask.lower() == "signup" or ask.lower() == "Signup":
    username = input("Please enter a username to signup.\n")
    password = input("Please enter a password to signup.\n")
    hashedpass = hashlib.md5(password.encode("utf-8")).hexdigest()
    print("Here is your password hash " + hashedpass +
          "Don't lose it or you won't be able to login.")
    data = {'user': username, 'password': hashedpass}
    db.collection("Data").add(data)
elif ask.lower() == "login" or ask.lower() == "Login":
    loginuser = input("What is your username?\n")
    loginusercheck = db.collection("Data").where("user", "==", loginuser).get()
    searchuser = loginusercheck.find(loginuser)
    if searchuser.lower() == 0:
      loginpass = input("What is your password hash?\n")
      loginpasscheck = db.collection("Data").where("password", "==", loginpass)
      searchpass = loginpasscheck.find(loginpass)
    if searchpass.lower() == 0:
      print("You've logged into your account.")
    elif searchpass.lower() == -1:
       exit(400)
    elif searchuser.lower() == -1:
      exit(400)
触发的报错信息
Traceback (most recent call last):
File "main.py", line 20, in <module>
 searchuser = loginusercheck.find(loginuser)
AttributeError: 'list' object has no attribute 'find'

报错触发位置为代码第20行searchuser = loginusercheck.find(loginuser)语句,提示列表对象不存在find属性。

错误原因
  • 核心报错原因:Firestore执行where().get()后返回的是匹配条件的文档快照列表,不是字符串类型。find()是字符串类型的内置查找方法,列表没有该方法,直接调用必然抛出属性错误。
  • 代码附带的其他逻辑问题:
    • 条件判断冗余:ask.lower() == "signup" or ask.lower() == "Signup"逻辑无效,字符串转小写后不可能匹配首字母大写的"Signup"
    • 密码查询缺少.get()调用,根本不会执行查询返回结果
    • 用户名、密码分开查询存在逻辑漏洞,可能出现A用户的用户名匹配到、B用户的密码哈希匹配到就误判登录成功的问题
    • 登录流程要求用户输入md5哈希值不符合使用逻辑,普通用户无法记忆32位哈希字符串
    • 对整数类型的查询结果调用.lower()方法会触发新的类型错误
修正后可运行代码
import firebase_admin
import hashlib
from firebase_admin import firestore
from firebase_admin import credentials

cred = credentials.Certificate("serviceAccountKey.json")
firebase_admin.initialize_app(cred)
db = firestore.client()

ask = input("Do you want to login or signup?\n").strip().lower()
if ask == "signup":
    username = input("Please enter a username to signup.\n").strip()
    password = input("Please enter a password to signup.\n").strip()
    # 注意:MD5哈希安全性较低,生产环境建议替换为bcrypt、scrypt等专用密码哈希算法
    hashedpass = hashlib.md5(password.encode("utf-8")).hexdigest()
    print("Your account has been created successfully.")
    data = {'user': username, 'password': hashedpass}
    db.collection("Data").add(data)
elif ask == "login":
    loginuser = input("What is your username?\n").strip()
    # 按用户名查询匹配文档
    user_docs = list(db.collection("Data").where("user", "==", loginuser).get())
    # 查询结果为空说明用户名不存在
    if len(user_docs) == 0:
        print("Invalid username or password")
        exit(400)
    # 取匹配到的第一条用户文档
    user_info = user_docs[0].to_dict()
    loginpass = input("What is your password?\n").strip()
    loginpass_hash = hashlib.md5(loginpass.encode("utf-8")).hexdigest()
    # 直接比对当前用户文档里存储的密码哈希
    if loginpass_hash == user_info['password']:
        print("You've logged into your account.")
    else:
        print("Invalid username or password")
        exit(400)
else:
    print("Invalid option, please enter login or signup")
    exit(400)

注:MD5不属于安全的密码哈希算法,上述代码仅修正原有逻辑错误,正式使用请替换为加盐的慢哈希算法处理密码存储。

内容的提问来源于stack exchange,提问作者Panda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 16:12:17