Supabase Google 登录(iOS)
复制一个包含安装步骤和此插件的完整Markdown指南的设置提示
介绍
标题为“介绍”本指南将帮助您在 iOS 上将 Google Sign-In 与 Supabase 身份验证集成。假设您已经完成了:
- the the
- the Supabase Google 登录 - 通用设置.
实现
实现完整的实现可在 示例应用程序的 supabaseAuthUtils.ts 文件中找到。 本指南解释了关键概念和如何使用它。
使用身份验证助手
身份验证助手The authenticateWithGoogleSupabase 复制到剪贴板
import { authenticateWithGoogleSupabase } from './supabaseAuthUtils';
const result = await authenticateWithGoogleSupabase();if (result.success) { console.log('Signed in:', result.user); // Navigate to your authenticated area} else { console.error('Error:', result.error);}本指南解释了如何使用 Capgo 构建者进行本地云构建。
如何工作For a detailed explanation of how the authentication flow works, including nonce generation, JWT validation, and Supabase sign-in, see the 如何工作.
重要注意事项
重要注意事项iOS token 缓存和 nonce 问题
iOS Token 缓存和非一次性问题iOS 非法令牌缓存问题
iOS 中,Google Sign-In 可以缓存令牌,这可能会导致 nonce 验证失败。 validateJWTToken function 自动处理此问题:
- 自动检测: 验证令牌中的 nonce 是否与预期相符
nonceDigest - 自动重试: 如果验证失败,会自动从 Google 登出并尝试一次
- 错误处理: 如果重试也失败,则会返回错误
为什么会这样: iOS Google Sign-In SDK 为性能考虑缓存令牌。当缓存令牌返回时,它可能是使用不同的 nonce (或无 nonce) 生成的,导致不匹配。
解决方案: 实现自动处理此问题,通过登出并重试,强制 Google 生成一个带有正确 nonce 的新令牌。
手动解决方案 : (如果自动重试不起作用):
// Logout first to clear cached tokensawait SocialLogin.logout({ provider: 'google' });
// Then authenticateconst result = await authenticateWithGoogleSupabase();: 这样可以确保获得带有正确 nonce 的新令牌。
For the complete code reference, see the 完成通用设置指南中的Code参考部分.
Nonce 处理
Section titled “Nonce 处理”The nonce implementation follows the pattern from the 指向 Supabase 的:
rawNonceSupabase 生成一个哈希值signInWithIdToken()- 并与
rawNoncewhich is included in the ID token from Google Sign-InnonceDigest在 Google Sign-In 的 ID token 中包含的。 nonceDigest(SHA-256 hash, hex编码)将转到nonceGoogle Sign-In API中的参数
自动重试机制
自动重试机制该函数包含一个参数: authenticateWithGoogleSupabase 第一次调用( retry parameter:
- ):如果验证失败,则自动注销并尝试一次
retry=false重试调用( - ):如果验证失败,则立即返回错误
retry=true这将自动处理iOS令牌缓存问题
自动处理 iOS token 缓存问题。
故障排除
故障排除如果认证失败:
- 非法 nonce: 函数会自动重试 - 检查控制台日志以获取详细信息。如果问题持续存在,请手动注销
- 无效受众: 确认在 Google Cloud Console 和 Supabase 中(包括 iOS 和 Web 客户端 ID)中都配置了正确的 Google Client IDs
- 令牌验证失败: 确保在初始化调用中使用
mode: 'online'在 initialize 调用中使用 - Info.plist 配置: 确保 Info.plist 中包含正确的 URL 方案和 GIDClientID
- 查看 example app code 为了参考
继续从 Supabase Google Login on iOS
Section titled “继续从 Supabase Google Login on iOS”如果您正在使用 Google iOS Supabase 登录 来规划身份验证和帐户流程,连接它与 使用 @capgo/capacitor-social-login 为 native 能力在使用 @capgo/capacitor-social-login @capgo/capacitor-社交登录 为实现细节在 @capgo/capacitor-social-login @capgo/capacitor-passkey 查看@capgo/capacitor-passkey的实现细节 @capgo/capacitor-native-biometric 查看@capgo/capacitor-native-biometric的实现细节,并 双因素认证 查看双因素认证的实现细节。