部署Firebase Hosting后访问跳转至Google登录页问题排查
Hey there, let's dig into why your SSR app on Firebase Hosting is redirecting to Google Accounts, and walk through how to fix it.
Possible Causes
- Forced authentication in your SSR function (
index.js): It’s likely yourindex.jsincludes Firebase Auth middleware that requires users to be logged in for all routes, with no exceptions for public pages. When an unauthenticated user visits, Firebase Auth automatically redirects them to Google’s login page (its default behavior for unauthenticated requests). - Misconfigured Firebase Hosting rewrites: Your
firebase.jsonmight have incorrect rewrite rules that send requests to a protected endpoint, or your SSR Cloud Function has IAM permissions set to only allow authenticated users. This triggers an automatic redirect when unauthenticated users try to access the function. - Overly restrictive Hosting authentication settings: If you added
authenticationrules infirebase.jsonthat enforce login for all paths (without exceptions), every unauthenticated visit will trigger the Google Accounts redirect.
Fixes to Try
Adjust SSR Function Authentication Logic
Open your index.js and check your auth middleware setup:
- Exclude public pages from auth checks: If only certain routes need login, apply the auth middleware selectively instead of globally:
// ❌ Bad: Global auth enforcement app.use(requireAuth); // ✅ Good: Apply auth only to protected routes app.get('/profile', requireAuth, (req, res) => { /* SSR protected profile page */ }); app.get('/', (req, res) => { /* SSR public homepage, no auth needed */ }); - Customize unauthenticated behavior: If you do need full-site login, tweak the middleware to return a custom 401 page instead of redirecting, or adjust the redirect target to your own login page (instead of Google’s default).
Fix Firebase Hosting Rewrite Rules
Check your firebase.json for incorrect rewrite configurations:
- Ensure rewrites point to your correct SSR function:
{ "hosting": { "public": "public", "rewrites": [ { "source": "**", "function": "ssrRenderer" // Replace with your actual SSR function name } ] } } - Update Cloud Function IAM permissions: If your SSR function is set to only allow authenticated users, head to the Firebase Console → Cloud Functions, find your SSR function, and adjust its permissions to allow
allUsersto invoke it (if public access is intended).
Tune Hosting Authentication Settings
If you have authentication rules in firebase.json:
- Restrict auth requirements to specific paths only:
{ "hosting": { "public": "public", "authentication": { "required": false, // Default to no auth "paths": { "/dashboard/**": { "required": true // Only enforce auth on dashboard routes } } } } } - Remove the
authenticationblock entirely if you don’t need any site-wide auth enforcement.
After making these changes, redeploy your app with firebase deploy and test using an incognito window to verify the redirect no longer happens.
内容的提问来源于stack exchange,提问作者Patrickkx
相关产品推荐
相关产品推荐

