You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取Firebase Authentication访问令牌以完成账号重新认证?

解决Firebase重认证时获取Access Token的问题

嘿,这个Firebase重认证的问题我刚好处理过,其实关键是不同的登录提供商(比如邮箱密码、Google、Facebook),获取accessToken的方式完全不一样,而且大部分情况你不需要直接调用那个通用的credentialWithProviderID:accessToken:,用对应提供商的专属方法创建凭证会更稳妥。下面分情况给你讲:

1. 邮箱/密码登录(Provider ID: password)

这个情况比较特殊,因为邮箱密码登录没有持久的accessToken可以直接获取,你得让用户重新输入邮箱和密码,然后用专门的邮箱密码凭证方法创建:

// 先收集用户重新输入的邮箱和密码
NSString *userEmail = @"user@example.com"; // 替换为用户输入的邮箱
NSString *userPassword = @"userPassword"; // 替换为用户输入的密码

FIREmailPasswordAuthCredential *credential = [FIREmailPasswordAuthCredential credentialWithEmail:userEmail password:userPassword];

// 然后调用重认证方法
[[FIRAuth auth].currentUser reauthenticateAndRetrieveDataWithCredential:credential completion:^(FIRAuthDataResult * _Nullable result, NSError * _Nullable error) {
    if (error) {
        // 处理重认证失败
    } else {
        // 重认证成功,现在可以执行账号删除等操作
    }
}];

2. Google登录(Provider ID: google.com)

如果用户是用Google登录的,你可以通过Google Sign-In SDK直接获取当前用户的accessToken:

// 确保已经集成了Google Sign-In SDK
GIDGoogleUser *googleUser = [GIDSignIn sharedInstance].currentUser;
if (googleUser) {
    NSString *accessToken = googleUser.authentication.accessToken;
    NSString *idToken = googleUser.authentication.idToken;
    
    // 用Google专属方法创建凭证
    FIRAuthCredential *credential = [FIRGoogleAuthProvider credentialWithIDToken:idToken accessToken:accessToken];
    
    // 发起重认证
    [[FIRAuth auth].currentUser reauthenticateAndRetrieveDataWithCredential:credential completion:^(FIRAuthDataResult * _Nullable result, NSError * _Nullable error) {
        // 处理结果
    }];
}

如果accessToken过期了,你可以调用googleUser.authentication.refreshTokenWithHandler:来刷新token。

3. Facebook登录(Provider ID: facebook.com)

类似Google,通过Facebook SDK获取当前的accessToken:

// 确保集成了Facebook SDK
FBSDKAccessToken *fbAccessToken = [FBSDKAccessToken currentAccessToken];
if (fbAccessToken && !fbAccessToken.isExpired) {
    NSString *accessToken = fbAccessToken.tokenString;
    
    // 用Facebook专属方法创建凭证
    FIRAuthCredential *credential = [FIRFacebookAuthProvider credentialWithAccessToken:accessToken];
    
    // 重认证
    [[FIRAuth auth].currentUser reauthenticateAndRetrieveDataWithCredential:credential completion:^(FIRAuthDataResult * _Nullable result, NSError * _Nullable error) {
        // 处理结果
    }];
}

4. 其他提供商(Apple、Twitter等)

  • Apple登录(Provider ID: apple.com):需要从Apple的授权凭证中获取identityToken,配合之前登录时用的rawNonce来创建凭证:
    // 假设你在登录时保存了rawNonce
    NSString *rawNonce = @"yourSavedRawNonce";
    ASAuthorizationAppleIDCredential *appleIDCredential = // 从Apple登录流程中获取的凭证
    NSString *identityToken = [[NSString alloc] initWithData:appleIDCredential.identityToken encoding:NSUTF8StringEncoding];
    
    FIRAuthCredential *credential = [FIROAuthProvider credentialWithProviderID:@"apple.com" IDToken:identityToken rawNonce:rawNonce];
    
  • Twitter登录(Provider ID: twitter.com):需要用户的authToken和authTokenSecret,你可以在FirebaseUI登录成功时保存这两个值,重认证时直接使用:
    NSString *authToken = @"savedAuthToken";
    NSString *authTokenSecret = @"savedAuthTokenSecret";
    
    FIRAuthCredential *credential = [FIRTwitterAuthProvider credentialWithAuthToken:authToken authTokenSecret:authTokenSecret];
    

通用建议

  1. 先通过Auth.auth().currentUser.providerID判断用户的登录方式,再分支处理对应的凭证创建逻辑。
  2. 如果不想让用户重复输入密码/重新授权,可以在首次登录成功时,把对应的凭证信息(比如Google的refreshToken、Facebook的token)存在Keychain里,后续重认证时直接调用,但要注意token的有效期,过期了要及时刷新。
  3. 尽量使用各提供商的专属credentialWithXXX方法,而不是通用的credentialWithProviderID:accessToken:,因为不同提供商对token的要求不同(比如Google需要ID Token+Access Token,而Facebook只需要Access Token)。

内容的提问来源于stack exchange,提问作者Haagenti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:42:34