You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Google Callable Function仅允许指定客户端应用访问

可用原生实现方案,推荐按以下优先级选择:

方案1:Firebase App Check + 应用ID校验(最适配你的场景)

这是专门用于限制仅指定客户端应用调用云函数的原生能力,操作步骤如下:

  • 确认你两个用途的应用(发通知专属安卓应用、主应用的iOS/安卓端)都已在当前Firebase项目内完成注册,每个应用对应唯一的Firebase应用ID,可在Firebase控制台「项目设置」页面查看对应值
  • 为所有应用开启Firebase App Check,按平台要求配置校验凭证(安卓端用Play Integrity、iOS端用DeviceCheck/App Attest),避免伪造请求绕过校验
  • 在sendNotification函数内添加校验逻辑,仅允许你的专属发通知应用调用,修改后代码如下:
export const sendNotification = functions
.runWith({ timeoutSeconds: 540 })
.region("asia-southeast2")
.https.onCall(async (data, context) => {
  // 校验请求是否通过App Check,拦截非官方应用的请求
  if (context.app === undefined) {
    throw new functions.https.HttpsError(
      'failed-precondition',
      '请求未通过合法应用校验'
    );
  }

  // 替换为你专属发通知安卓应用的Firebase应用ID
  const ALLOWED_APP_ID = "1:1234567890:android:abc123def456ghi789jkl0";
  if (context.app.appId !== ALLOWED_APP_ID) {
    throw new functions.https.HttpsError(
      'permission-denied',
      '当前应用无调用权限'
    );
  }

  // 原有业务逻辑写在下方
});

方案2:自定义身份声明校验(适合仅指定账号可调用的场景)

如果你的发通知安卓应用仅限特定管理员账号登录使用,可以用Firebase Auth的自定义声明实现权限隔离:

  • 给允许调用该接口的管理员账号添加自定义声明canSendNotification: true
  • 在函数内添加身份权限校验逻辑即可:
export const sendNotification = functions
.runWith({ timeoutSeconds: 540 })
.region("asia-southeast2")
.https.onCall(async (data, context) => {
  // 校验用户登录状态
  if (!context.auth) {
    throw new functions.https.HttpsError('unauthenticated', '用户未登录');
  }
  // 校验用户权限
  if (!context.auth.token.canSendNotification) {
    throw new functions.https.HttpsError('permission-denied', '无调用权限');
  }

  // 原有业务逻辑写在下方
});

内容的提问来源于stack exchange,提问作者Agung

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 07:09:02