Permission error when accessing a cached firestore collection after logout/login
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- firebase, react, typescript
- Domain
- authentication, databases
Research direction
Reproduce the sign-out/sign-in sequence with useFirestoreCollectionData and the same collection, then inspect how the global collection cache handles authentication changes. Compare the cached read with the workaround of changing idField after login. Done means the same collection can be read after reauthentication without a permission error, ideally with a regression test or documented reproduction.
Written by the indexing model from the issue text.
Description
Version info
React: 17.0.2
Firebase: 9.4.0
ReactFire: 4.2.0
Other (e.g. Node, browser, operating system) (if applicable): Chrome, Windows 10
Test case
Test cases seem challenging to produce since a firebase instance is involved.
Steps to reproduce
- Sign In (I used
GoogleAuthProvider), or be already signed-in. - Read from a collection.
- Sign Out
- Sign In
- Read from the same collection.
Expected behavior
The same data is read.
Actual behavior
Uncaught FirebaseError: Missing or insufficient permissions. is thrown.
This seems to be caused by the global cache of collections. The problem can be mitigated by:
- Refreshing the page after sign out
- Changing the
idFieldpassed touseFirestoreCollectionData. Any easy way to test this is to useid-${auth.stsTokenManager.expirationTime}as youridField, sinceexpirationTimechanges on every Sign Out/In cycle.
Note that waiting more than 30 seconds does not fix the problem. So, the cache resetting of the collection is insufficient to resolve the issue. I suspect that the collection is associated with the stale auth token which has been disabled due to logout.
A possible resolution might be to purge the cache on sign out.
- Dominant language
- TypeScript
- Stars
- 3.6k
- Forks
- 403
- Avg merge
- 4d 19h
- Merged PRs (30d)
- 11
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from FirebaseExtended/reactfire
-
Difficulty 5/5 Over a week Newbie friendliness 38/100
FirebaseExtended/reactfire#801 ·
Maintainers usually reply within 2 days
-
v5
Difficulty 4/5 3-5 days Newbie friendliness 48/100
FirebaseExtended/reactfire#793 ·
Maintainers usually reply within 2 days
-
v5
Difficulty 4/5 3-5 days Newbie friendliness 35/100
FirebaseExtended/reactfire#790 · 2 comments ·
Maintainers usually reply within 2 days
-
v5
Difficulty 4/5 3-5 days Newbie friendliness 55/100
FirebaseExtended/reactfire#789 ·
Maintainers usually reply within 2 days
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
FirebaseExtended/reactfire#788 ·
Maintainers usually reply within 2 days
All issues in FirebaseExtended/reactfire
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
lichess-org/api#678 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
PostHog/posthog.com#20628 ·
Maintainers usually reply within 1 day
-
bug status:Needs Triage
Difficulty 1/5 Under an hour Newbie friendliness 92/100
jupyterlab/jupyterlab#19964 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agentscope-ai/QwenPaw#8064 · 1 comment ·
Maintainers usually reply within 1 day
-
area: notebooks-jupyter bug theme: new notebook frontend
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
posit-dev/positron#16347 · 1 comment ·
Maintainers usually reply within 1 day