我们正在将应用程序从 AWS 迁移到 GCP。在AWS中,我们使用Cognito服务来维护用户池内不同类型的用户(例如:SSO用户有不同的用户池,并且具有电子邮件和密码的用户在不同的用户池中配置,对于MFA用户,他们有不同的用户池)在AWS Cognito中,我们还利用某些功能(例如 appclient id 和密钥)在预注册触发器中生成 JWT 令牌和授权者 lambda)
在GCP中我们如何实现上述的实现呢?
amazon-web-services google-cloud-platform amazon-cognito google-cloud-identity
Google Identity Platform 文档仅提到通过短信进行 MFA。像 TOTP 这样的程序真的不支持吗?这是近期的计划吗?
对于复杂的企业应用程序,出于安全原因和短信成本的考虑,我认为这是必要的。
Firebase规则文档建议构建条件,将经过身份验证的用户令牌(即request.auth)与目标 Firestore 文档进行比较。就像是:
match /posts/{postId} {
allow read, write: if (request.auth.uid != null) &&
(resource.data.tenantId == request.auth.token.tenantId);
}
Run Code Online (Sandbox Code Playgroud)
但是,Firebase 规则tenantId中似乎没有像其他相关身份验证字段那样可用 (例如、、uidemailemail_verified等)
一种选择似乎是使用SDK 作为自定义声明tenantId单独添加。但这会在用户对象上创建重复信息:firebase-admin
{
uid: 'nzjNp3QIfSR6uWy',
emailVerified: true,
displayName: 'pickleR'
...
tenantId: 'wubalubadubdub',
customClaims: { tenantId: 'wubalubadubdub' },
}
Run Code Online (Sandbox Code Playgroud)
另一种选择似乎是tenants在 Firestore 中创建集合。然而,这种方法似乎引入了不必要的复杂性并增加了所需的 Firestore 查询数量。
是否有其他方法可以访问tenantIdFirestore 规则和/或通过多租户使用 Firestore 的替代最佳实践?
我试图了解以下之间的区别:Cloud Identity、Firebase Auth、Identity Platform
我已阅读以下文件:https : //cloud.google.com/identity-platform/docs/product-comparison https://cloud.google.com/blog/products/identity-security/identity-and-authentication -the-google-cloud-way
我的问题是:
如果您需要了解我的用例,我基本上是在构建一个模块化企业应用程序,供我公司用于我们的建筑项目。
谢谢大家!
firebase google-cloud-platform firebase-authentication google-cloud-identity
尝试在 SAML 与 Firebase 中正确运行时点一些 Is 并交叉一些 T。我遵循了 Google 关于如何将 SAML 添加到项目的工作流程(https://cloud.google.com/identity-platform/docs/how-to-enable-application-for-saml),但遇到了困难授权回调地址。单击登录转到 SAML 时,它会将您带到提供商的 URL 进行登录。但是登录后,您只是被重定向回 firebase 站点 (*.firebaseapp.com/__/auth/handler),而不是实际站点。我已将网站 URL 设置为 Firebase/Cloud Identity Platform 中的授权域。我没有为该项目使用 Firebase 托管,但我认为只要 URL 位于授权域中,我就不需要设置重定向。
*3:26pm 2/26 - 我认为部分原因也可能是我输入 SP 实体 ID 的方式。我使用的实体 ID 与 SSO URL 中的实体 ID 相同
我正在尝试像这样部署 Firebase 功能:
firebase deploy --only functions
Run Code Online (Sandbox Code Playgroud)
但是,我收到以下错误:
错误:缺少部署功能所需的权限。您必须拥有服务帐户 xyz@appspot.gserviceaccount.com 的 iam.serviceAccounts.ActAs 权限。要解决此错误,请要求项目所有者通过以下 URL 为您的帐户分配“服务帐户用户”角色: https: //console.cloud.google.com/iam-admin/iam?xyz
我已经通过访问授予自己服务帐户用户权限
身份 -> 服务帐户 -> xyz@appspot.gserviceaccount.com -> 权限 -> + 授予访问权限
我已在 中添加了链接的电子邮件和服务帐户GOOGLE_APPLICATION_CREDENTIALS。我仍然遇到同样的错误。
有任何想法吗?
firebase service-accounts google-cloud-functions google-cloud-iam google-cloud-identity
我有一个谷歌云函数,我在谷歌身份平台的触发器中运行beforeCreate它,如下所示:
import * as gcipCloudFunctions from "gcip-cloud-functions";
const authClient = new gcipCloudFunctions.Auth();
const beforeCreate = authClient.functions().beforeCreateHandler((user, context) => {
console.log("Hello world");
});
export default beforeCreate;
Run Code Online (Sandbox Code Playgroud)
我如何创建笑话测试来模拟此事件?或者如何创建测试来执行此功能?
阻塞函数。
unit-testing node.js google-cloud-functions ts-jest google-cloud-identity
我们正在构建的一个项目使用了 Google 云身份工具包多租户功能。我们正在积极使用两个租户。我们通过 Firebase 的身份验证套件与所有这些进行交互。
我注意到,使用此功能时,用户帐户不再显示在 Firestore 的 UI 中。本地模拟器也是如此。
我知道用户已创建,因为当我登录时,我会返回与 firestore 中创建的用户配置文件相匹配的正确 uid,我可以在本地模拟器中看到该用户配置文件。
我想知道是否有人可以帮助我解决以下问题之一:
有没有办法通过模拟器管理为多租户设置创建的用户?
有没有办法在本地使用 gcloud cli 来管理我在本地创建的用户?
firebase google-cloud-platform firebase-authentication google-cloud-identity
我正在尝试从 GCP 环境外部通过 Python 以编程方式访问受 IAP 保护的 App Engine Standard 应用程序。我尝试了各种方法,包括此处文档中显示的方法: https: //cloud.google.com/iap/docs/authentication-howto#iap-make-request-python。这是我的代码:
from google.auth.transport.requests import Request
from google.oauth2 import id_token
import requests
def make_iap_request(url, client_id, method='GET', **kwargs):
"""Makes a request to an application protected by Identity-Aware Proxy.
Args:
url: The Identity-Aware Proxy-protected URL to fetch.
client_id: The client ID used by Identity-Aware Proxy.
method: The request method to use
('GET', 'OPTIONS', 'HEAD', 'POST', 'PUT', 'PATCH', 'DELETE')
**kwargs: Any of the parameters defined for the request function:
https://github.com/requests/requests/blob/master/requests/api.py
If …Run Code Online (Sandbox Code Playgroud) google-app-engine google-api-python-client google-cloud-platform google-iap google-cloud-identity
如果我打开组织策略约束“域限制共享”(doc)并将其设置为仅允许我的组织域foo.com,这是否会阻止大量平台服务帐户获得其 IAM 权限?例如,域中的帐户@iam.gserviceaccount.com或@developer.gserviceaccount.com. 这些服务帐户在所有地方都得到配置和授予权限。我担心启用“域限制共享”会阻止这些帐户获得 IAM 访问权限。
另一种提问方式是:是否“域限制共享” 忽略了这些基于平台的服务帐户?如果没有,我觉得很难维护一个例外列表。
一个更基本的问题 - “域限制共享”是否仅适用于 Cloud Identity / Google Workspace 帐户,因此与服务帐户无关?