You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何检测Firebase Authentication中用户的密码变更?

How to Track Firebase Auth Password Changes for Syncing to Another Database

Hey there! Let's work through your scenario: you need to know when a user resets their Firebase Auth password (via the password reset email) so you can sync that new password to your second database once they log back in.

First off, an important heads-up: Firebase Auth doesn't have a dedicated "password changed" event listener out of the box, but we can use a few practical workarounds to make this happen. Let's break down the best options:

1. Track Password Resets with a Database Flag + Login Check

This is the most reliable approach, as it explicitly marks when a user has just reset their password:

  • When the user successfully sets their new password (either in a custom reset page or right after the default Firebase reset flow), add a temporary flag to your Firebase database (Firestore/Realtime DB) for that user (like passwordJustReset: true).
  • When the user logs back in, check for that flag. If it exists, you know this login is immediately post-password-reset.
  • Use the password the user just entered to log in to update your second database, then clear the flag so this sync doesn't run on every subsequent login.

Example code (Web):

// Step 1: Mark the user after successful password reset (custom reset page)
firebase.auth().confirmPasswordReset(resetCode, newPassword)
  .then(async () => {
    // Fetch the user via their email
    const userRecord = await firebase.auth().getUserByEmail(userEmail);
    // Add the reset flag to Firestore
    await firebase.firestore().collection('users').doc(userRecord.uid).update({
      passwordJustReset: true
    });
    // Redirect to login page
    window.location.href = '/login';
  })
  .catch(err => console.error('Password reset error:', err));

// Step 2: Check flag on login and sync password to your second database
firebase.auth().signInWithEmailAndPassword(email, userEnteredPassword)
  .then(async (userCredential) => {
    const user = userCredential.user;
    const userDoc = await firebase.firestore().collection('users').doc(user.uid).get();
    
    if (userDoc.data()?.passwordJustReset) {
      // Sync the new password to your second database
      await updateSecondDatabasePassword(user.uid, userEnteredPassword);
      // Clear the flag to avoid repeated syncs
      await firebase.firestore().collection('users').doc(user.uid).update({
        passwordJustReset: false
      });
    }
  })
  .catch(err => console.error('Login error:', err));

2. Use Auth Metadata to Detect Post-Reset Logins

If you don't want to add extra flags to your database, you can use Firebase's built-in user metadata to make an educated guess:

  • Firebase user objects include lastSignInTime metadata. When a user resets their password, their next login's lastSignInTime will be very close to the reset timestamp.
  • You can store the reset time in your database when sending the password reset email, then compare it to the lastSignInTime on login to trigger the sync.

Note: This method is less reliable than the flag approach, since users might reset their password and log in hours later, making the timestamp comparison less accurate.

Critical Security & Implementation Notes

  • Firebase never exposes plaintext passwords: You can't retrieve the user's password from the Firebase Auth user object. You must capture the password when the user enters it (either during the reset flow or login) to sync it to your second database.
  • Always encrypt passwords: Ensure your second database stores passwords using a secure hashing algorithm (like bcrypt) just like Firebase Auth does. Never store plaintext passwords anywhere.

内容的提问来源于stack exchange,提问作者Cesar gutierrez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:23:41