You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm currently using Google Identity Toolkit (Gitkit) for authentication on my website, which has a Google App Engine (GAE) for Java backend. Since Gitkit is now deprecated and Firebase Auth is its replacement, I have been trying to migrate to Firebase Auth with limited success.
I have run across an issue with sending verification emails for email/password based authentication. With Gitkit, the server SDK has the ability to send verification emails to the user. But with Firebase Auth, the admin SDK (Java) doesn't have the ability to send verification emails, which can only be sent from the client. The lack of ability to send verification emails from the server has several limitations and disadvantages. I have been discussing the issues over on the FirebaseUI Web GitHub issue. Here's the list of limitations that I currently face with using a "client-only" flow for sending verification emails:
Sending the first verification email to the user: There's no client-only way to send an email to the user right at the point of sign-up as is the norm for email/password based authentication. With Gitkit, the server can check the database to see whether the user exists, and if the user doesn't exist, it can add the user to the database, send a verification email to the user immediately, and log the verification link also in the database.
Keep track of the number of verification emails requested: There's no client-only way to count the number of verification emails sent to a user. The server can track the number of emails sent. Keeping a track of the emails sent is important for the reason explained in Setting Up the Release Process #3 below.
Prevent spam / misuse of resend verification email feature: In the past I had a case where a prankster misused someone else's email address to register for an account, and then kept using the "resend verification email" feature on my website to send verification emails to the owner of that email address. To prevent this, I added a limit of 3 verification emails in the system. This is not possible in the client-only flow.
Send verification link manually to a user. With GitKit, the link has to be generated through an API and then an email needs to be sent to the user with the link. I record the link in the database. In case a user is not able to receive the email for any reason, I can send the link manually to the user to verify, or I can even click the link myself on behalf of the user to verify the email if the user is writing to me from the registered email address.
Firebase Auth doesn't allow the verification email template to be changed. If I could generate the link through the admin SDK, I could use my own server to send the emails, and do not need to rely on Firebase's email.
Without the ability to send verification emails from the server, Firebase Auth for email/password based login is severely crippled. Sending verification email is a must-have feature for email/password based authentication, and having this feature in the admin SDK is also a must-have.
If you have other suggestions I'm open to them. I know I can use Firebase realtime database or my GAE backend to get around some of these limitations but it's going to be more cumbersome than having the admin SDK with the ability to send the verification emails directly.
We have plans to support sending email verifications from the admin SDK: firebase/firebase-admin-node#46. We are taking into consideration the ability to customize email templates, control how the email is sent, etc.
Reacted by donoso.eth, Leonardo Costa, Luis Santiago Re and Juan Jose A.
@bojeil-google can this be closed since the email action link API is now released? Do we plan to do any more work to support sending emails from the server-side?
You have to implement code to send the email out using your own SMTP/email server. That's what sendCustomEmail is supposed to represent. But we don't provide detailed examples for that since it will depend on the exact SMTP/email service the developer chooses to use.
I'm currently using Google Identity Toolkit (Gitkit) for authentication on my website, which has a Google App Engine (GAE) for Java backend. Since Gitkit is now deprecated and Firebase Auth is its replacement, I have been trying to migrate to Firebase Auth with limited success.
I have run across an issue with sending verification emails for email/password based authentication. With Gitkit, the server SDK has the ability to send verification emails to the user. But with Firebase Auth, the admin SDK (Java) doesn't have the ability to send verification emails, which can only be sent from the client. The lack of ability to send verification emails from the server has several limitations and disadvantages. I have been discussing the issues over on the FirebaseUI Web GitHub issue. Here's the list of limitations that I currently face with using a "client-only" flow for sending verification emails:
Sending the first verification email to the user: There's no client-only way to send an email to the user right at the point of sign-up as is the norm for email/password based authentication. With Gitkit, the server can check the database to see whether the user exists, and if the user doesn't exist, it can add the user to the database, send a verification email to the user immediately, and log the verification link also in the database.
Keep track of the number of verification emails requested: There's no client-only way to count the number of verification emails sent to a user. The server can track the number of emails sent. Keeping a track of the emails sent is important for the reason explained in Setting Up the Release Process #3 below.
Prevent spam / misuse of resend verification email feature: In the past I had a case where a prankster misused someone else's email address to register for an account, and then kept using the "resend verification email" feature on my website to send verification emails to the owner of that email address. To prevent this, I added a limit of 3 verification emails in the system. This is not possible in the client-only flow.
Send verification link manually to a user. With GitKit, the link has to be generated through an API and then an email needs to be sent to the user with the link. I record the link in the database. In case a user is not able to receive the email for any reason, I can send the link manually to the user to verify, or I can even click the link myself on behalf of the user to verify the email if the user is writing to me from the registered email address.
Firebase Auth doesn't allow the verification email template to be changed. If I could generate the link through the admin SDK, I could use my own server to send the emails, and do not need to rely on Firebase's email.
Without the ability to send verification emails from the server, Firebase Auth for email/password based login is severely crippled. Sending verification email is a must-have feature for email/password based authentication, and having this feature in the admin SDK is also a must-have.
If you have other suggestions I'm open to them. I know I can use Firebase realtime database or my GAE backend to get around some of these limitations but it's going to be more cumbersome than having the admin SDK with the ability to send the verification emails directly.
Environment: