【发布时间】:2021-08-11 23:28:58
【问题描述】:
我尝试将 Firebase 托管与 Firebase 函数结合使用,这样只有拥有有效 Firebase 令牌的用户才能访问 .html 内容。
当访问 Firebase 托管时,我能够在我的 iOS 应用程序中发送令牌,并且我的云函数被调用并成功解码令牌(我在 Firebase 函数日志中看到“ID 令牌正确解码”)。
之后应该打开 index.html,它位于我的 /functions 文件夹的子文件夹 (/myhomepage) 内(因此不在“/public”内)。
我的 App-Browser 中总是出现错误:“Cannot GET /”
Firebase-Functions-Log 显示:“函数执行耗时 1654 毫秒,完成状态码:404”
index.js 里面的代码:
const admin = require("firebase-admin");
const functions = require('firebase-functions');
const express = require('express');
const cookieParser = require('cookie-parser')();
const cors = require('cors')({origin: true});
const app = express();
admin.initializeApp();
let db = admin.firestore();
// Express middleware that validates Firebase ID Tokens passed in the Authorization HTTP header.
// The Firebase ID token needs to be passed as a Bearer token in the Authorization HTTP header like this:
// `Authorization: Bearer <Firebase ID Token>`.
// when decoded successfully, the ID Token content will be added as `req.user`.
const validateFirebaseIdToken = async (req, res, next) => {
functions.logger.log('Check if request is authorized with Firebase ID token');
if ((!req.headers.authorization || !req.headers.authorization.startsWith('Bearer ')) &&
!(req.cookies && req.cookies.__session)) {
functions.logger.error(
'No Firebase ID token was passed as a Bearer token in the Authorization header.',
'Make sure you authorize your request by providing the following HTTP header:',
'Authorization: Bearer <Firebase ID Token>',
'or by passing a "__session" cookie.'
);
res.status(403).send('Unauthorized');
return;
}
let idToken;
if (req.headers.authorization && req.headers.authorization.startsWith('Bearer ')) {
functions.logger.log('Found "Authorization" header');
// Read the ID Token from the Authorization header.
idToken = req.headers.authorization.split('Bearer ')[1];
} else if(req.cookies) {
functions.logger.log('Found "__session" cookie');
// Read the ID Token from cookie.
idToken = req.cookies.__session;
} else {
// No cookie
res.status(403).send('Unauthorized');
return;
}
try {
const decodedIdToken = await admin.auth().verifyIdToken(idToken);
functions.logger.log('ID Token correctly decoded', decodedIdToken);
req.user = decodedIdToken;
next();
return;
} catch (error) {
functions.logger.error('Error while verifying Firebase ID token:', error);
res.status(403).send('Unauthorized');
return;
}
};
app.use(cors);
app.use(cookieParser);
app.use(validateFirebaseIdToken);
app.get('/myhomepage', (req, res) => { // <-- The problem seems to be here
functions.logger.log('Calling get.'); // This line does not get called in my log.
res.status(200).sendFile('/index.html');
});
exports.myfunction = functions.https.onRequest(app);
令牌成功解码后,如何访问“/functions/myhomepage”内的内容?
【问题讨论】:
标签: javascript firebase express google-cloud-functions