login state with signInWithCustomToken shared with browser tabs
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Accessibilité débutants
- 25/100
- Type d'issue
- Fonctionnalité
- Clarté
- À clarifier
- Activité
- À l'abandon
- Stack technique
- angular, firebase, typescript
- Domaine
- authentication
Piste de recherche
Commencez par les méthodes login et loginAsPublicUser de FireService, en particulier leurs appels à angularFireAuth.signInWithCustomToken et signOut. Vérifiez les points d’entrée d’authentification de AngularFire et le comportement de persistance du navigateur afin de déterminer si un état distinct par onglet est pris en charge. Le travail est terminé lorsque les sessions du propriétaire du compte et de l’utilisateur public restent isolées entre les onglets sans écraser l’état d’autorisation de l’autre.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Hi
I have an application built with angular fire.
How can I not share login state among tabs in a same browser ?
Application overview
I have a class 'FireService' to login with custom token.
And application let users to login two ways 'as account owner' or 'as public user'.
And if an account owner logins, FireService#login method will be called.
And if a public user logins, FireService#loginAsPublicUser method will be called.
Issue
With same browser but different tab, login as an account owner in a tab 'A' and login as a public user in a tab 'B', the login state was overridden with the public users's and he gets an error due to insufficient permission of firebase rules. Because the owner was trying to access as the public user and blocked by my firebase rules.
I checked the browsers log, after the account owner's stats was overridden, the authorization headers value to start session with firestore was the public user's not the account ownser's.
How can I use login state separately for users different tabs in a same browser?
curl 'https://firestore.googleapis.com/google.firestore.v1.Firestore/Listen/channel?VER=8&database=projects%2{project name}%2Fdatabases%2F(default)&RID=*****&CVER=*****X-HTTP-Session-Id=gsessionid&zx=*****&t=1' \
~~~
-H 'x-client-data: CJ2EywE=' \
--data-raw 'headers=*****Authorization%3ABearer%20eyJhbGciOiJSU*****'
@Injectable()
export class FireService {
~~~~
public async login(roomId?: string): Promise<void> {
if (roomId) {
this.roomId = roomId;
}
const res = await this.serverClient
.getFirebaseToken(this.roomId)
.toPromise();
this.accountId = this.serverClient.getAccountId();
try {
await this.angularFireAuth.signInWithCustomToken(res.firebaseToken);
this.startTokenRefresh(true);
this.loggedIn = true;
} catch (error) {
console.error(error);
}
}
public async loginAsPublicUser(
participantId: string,
sharedRoomId: string,
password: string
): Promise<void> {
this.participantId = participantId;
this.sharedRoomId = sharedRoomId;
this.password = password;
const res = await this.serverClient
.getPublicFirebaseToken(
this.participantId,
this.sharedRoomId,
this.password
)
.toPromise();
try {
await this.angularFireAuth.signOut();
await this.angularFireAuth.signInWithCustomToken(res.firebaseToken);
this.startTokenRefresh(true);
this.loggedIn = true;
} catch (error) {
console.error(error);
}
}
- Langage dominant
- TypeScript
- Étoiles
- 7.8k
- Forks
- 2.2k
- Merge moyen
- 3 j 6 h
- PR mergées (30 j)
- 5
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de angular/angularfire
-
comp: build/pipeline type: bug version: current (v17+)
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
angular/angularfire#3766 ·
-
comp: schematics type: bug version: current (v17+)
Difficulté 3/5 1-2 jours Accessibilité débutants 76/100
angular/angularfire#3768 ·
-
comp: docs type: chore version: current (v17+)
Difficulté 4/5 3-5 jours Accessibilité débutants 58/100
angular/angularfire#3764 ·
-
comp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 1 personne assignée ·
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachable Ouvertecomp: core type: feature
angular/angularfire#3755 · 1 personne assignée ·
Toutes les issues de angular/angularfire
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
safetrustcr/dApp-SafeTrust#426 ·
-
area:workflow bug ready-for-agent
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
fil-donadoni/tolaria#4409 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
Fission-AI/OpenSpec#1960 ·
-
Add dependabot Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
corsairdev/corsair#1764 ·