Skip to content

feat(cloud_functions): expose allowInsecureTokenAttachment for Apple debug builds - #18734

Merged
SelaseKay merged 2 commits into
mainfrom
feat/issue-18732
Sep 29, 2026
Merged

SelaseKay merged 2 commits into
mainfrom
feat/issue-18732

Conversation

@SelaseKay

Copy link
Copy Markdown
Contributor

Description

Exposes FirebaseFunctions.allowInsecureTokenAttachment so a physical Apple device can send Auth, FCM, and App Check tokens to a Functions emulator on a LAN address.

Since Apple SDK 12.17, Functions refuses those tokens over plain HTTP unless the host is loopback. A device cannot use the Mac's loopback, so useFunctionsEmulator('192.168.1.x', 5001) fails with unauthenticated when App Check is enforced. SDK 12.19.0, already pinned by firebase_core, adds a debug-only opt-in. This PR forwards that flag from Dart through call() and stream(), and sets it on the Apple Functions instance inside #if DEBUG. Android and web already attach the tokens, so the flag has no effect there. Profile and release builds ignore it because the Apple SDK does not compile the property in.

Related Issues

Fixes #18732

Related to #18714

Checklist

Before you create this PR confirm that it meets all requirements listed below by checking the relevant checkboxes ([x]).
This will ensure a smooth and quick review process. Updating the pubspec.yaml and changelogs is not required.

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • My PR includes unit or integration tests for all changed/updated/fixed behaviors (See Contributor Guide).
  • All existing and new tests are passing.
  • I updated/added relevant documentation (doc comments with ///).
  • The analyzer (melos run analyze) does not report any problems on my PR.
  • I read and followed the Flutter Style Guide.
  • I signed the CLA.
  • I am willing to follow-up on review comments in a timely manner.

Breaking Change

Does your PR require plugin users to manually update their apps to accommodate your change?

  • Yes, this is a breaking change.
  • No, this is not a breaking change.

Test plan

  • flutter test in cloud_functions (firebase_functions_test.dart)
  • flutter test in cloud_functions_platform_interface (method_channel_https_callable_test.dart)
  • dart analyze on cloud_functions and cloud_functions_platform_interface
  • Debug flutter run on a physical iOS device against a Functions emulator on a LAN IP with App Check enforced

…debug builds

Physical devices cannot send Auth and App Check tokens to a Functions emulator on a LAN address unless the Apple SDK debug opt-in is set.
@gemini-code-assist

Copy link
Copy Markdown
Contributor
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

@SelaseKay
SelaseKay merged commit 8f95461 into main Sep 29, 2026
44 of 45 checks passed
@SelaseKay
SelaseKay deleted the feat/issue-18732 branch September 29, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🚀 [cloud_functions] Implement allowInsecureTokenAttachment property

3 participants