login state with signInWithCustomToken shared with browser tabs
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 25/100
- Issue 類型
- 功能
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 技術堆疊
- angular, firebase, typescript
研究方向
從 FireService 的 login 和 loginAsPublicUser 方法開始,尤其檢查它們對 angularFireAuth.signInWithCustomToken 和 signOut 的呼叫。檢查 AngularFire 的驗證進入點和瀏覽器持久化行為,以判斷是否支援獨立的分頁狀態。完成的標準是,帳戶擁有者工作階段和公開使用者工作階段在不同分頁之間保持隔離,且不會覆寫彼此的授權狀態。
由索引模型根據 Issue 內容生成。
描述
Hi
I have an application built with angular fire.
How can I not share login state among tabs in a same browser ?
Application overview
I have a class 'FireService' to login with custom token.
And application let users to login two ways 'as account owner' or 'as public user'.
And if an account owner logins, FireService#login method will be called.
And if a public user logins, FireService#loginAsPublicUser method will be called.
Issue
With same browser but different tab, login as an account owner in a tab 'A' and login as a public user in a tab 'B', the login state was overridden with the public users's and he gets an error due to insufficient permission of firebase rules. Because the owner was trying to access as the public user and blocked by my firebase rules.
I checked the browsers log, after the account owner's stats was overridden, the authorization headers value to start session with firestore was the public user's not the account ownser's.
How can I use login state separately for users different tabs in a same browser?
curl 'https://firestore.googleapis.com/google.firestore.v1.Firestore/Listen/channel?VER=8&database=projects%2{project name}%2Fdatabases%2F(default)&RID=*****&CVER=*****X-HTTP-Session-Id=gsessionid&zx=*****&t=1' \
~~~
-H 'x-client-data: CJ2EywE=' \
--data-raw 'headers=*****Authorization%3ABearer%20eyJhbGciOiJSU*****'
@Injectable()
export class FireService {
~~~~
public async login(roomId?: string): Promise<void> {
if (roomId) {
this.roomId = roomId;
}
const res = await this.serverClient
.getFirebaseToken(this.roomId)
.toPromise();
this.accountId = this.serverClient.getAccountId();
try {
await this.angularFireAuth.signInWithCustomToken(res.firebaseToken);
this.startTokenRefresh(true);
this.loggedIn = true;
} catch (error) {
console.error(error);
}
}
public async loginAsPublicUser(
participantId: string,
sharedRoomId: string,
password: string
): Promise<void> {
this.participantId = participantId;
this.sharedRoomId = sharedRoomId;
this.password = password;
const res = await this.serverClient
.getPublicFirebaseToken(
this.participantId,
this.sharedRoomId,
this.password
)
.toPromise();
try {
await this.angularFireAuth.signOut();
await this.angularFireAuth.signInWithCustomToken(res.firebaseToken);
this.startTokenRefresh(true);
this.loggedIn = true;
} catch (error) {
console.error(error);
}
}
- 主要語言
- TypeScript
- 星號
- 7.8k
- 分支
- 2.2k
- 平均合併
- 3 天 6 小時
- 30 天內合併 PR
- 5
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
angular/angularfire 的其他 Issue
-
comp: build/pipeline type: bug version: current (v17+)
難度 2/5 1-3 小時 新手友好度 74/100
angular/angularfire#3766 ·
-
comp: schematics type: bug version: current (v17+)
難度 3/5 1-2 天 新手友好度 76/100
angular/angularfire#3768 ·
-
comp: docs type: chore version: current (v17+)
難度 4/5 3-5 天 新手友好度 58/100
angular/angularfire#3764 ·
-
comp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 已指派 1 人 ·
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachable 未關閉comp: core type: feature
angular/angularfire#3755 · 已指派 1 人 ·
查看 angular/angularfire 的全部 Issue
相似的 Issue
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs 未關閉
難度 2/5 1-3 小時 新手友好度 70/100
-
Crush 未關閉
難度 1/5 1 小時以內 新手友好度 85/100
catppuccin/catppuccin#3125 ·
-
難度 1/5 1 小時以內 新手友好度 90/100
ElementsProject/cln-application#167 · 1 則留言 · 1 個 reaction ·
-
難度 2/5 1-3 小時 新手友好度 75/100
Quantco/pnpm-licenses#17 ·
-
難度 2/5 1-3 小時 新手友好度 75/100