Repository navigation
Functions: Node 24 with Gen2 auth trigger, fix alert callable, drop legacy Runtime Config - #1692
Open
HugoGresse wants to merge 3 commits into
Open
HugoGresse wants to merge 3 commits into
HugoGresse wants to merge 3 commits into
Conversation
firebase-functions 7.4.0 made 2nd gen Authentication triggers generally available. Replace the Gen1 auth.user().onCreate trigger (the only Gen1 function, which capped the runtime at nodejs22) with onUserCreated, so the whole codebase is Gen2 and can run on nodejs24. - userCreate (Gen1) -> userCreated (Gen2). The CLI cannot upgrade a function from Gen1 to Gen2 in place, so it is renamed; the deploy deletes the old userCreate. - firebase-functions ^6.6.0 -> ^7.4.0; firebase-tools 14.27.0 -> 15.31.0 (Gen2 auth triggers work in the emulators from 15.30.2). - engines.node, .nvmrc and the local launch config -> 24. Closes #1678 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_58a7bdfa-4677-48e4-8ef2-ba07fd4e1752) |
|
Preview for ecb89c2 (sandbox project open-feedback-hugo, expires in 7 days): https://open-feedback-hugo--pr-1692-bu131zno.web.app |
3 tasks done
open-feedback
|
||||||||||||||||||||||||||||
| Project |
open-feedback
|
| Branch Review |
feat/functions-node24-gen2-auth
|
| Run status |
|
| Run duration | 02m 08s |
| Commit |
|
| Committer | Hugo Gresse |
| View all properties for this run ↗︎ | |
| Test results | |
|---|---|
|
|
0
|
|
|
0
|
|
|
0
|
|
|
0
|
|
|
14
|
| View all changes introduced in this branch ↗︎ | |
The root firebase-functions export is v2 since v6, so the alert onCall handler received a CallableRequest, not the payload: the empty check never fired and the whole request (including the Express rawRequest) was serialized as the OpsGenie body. Use the v2 onCall/HttpsError imports and request.data, and cover the handler with a spec. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The functions read their configuration from functions/.env* files, not functions.config(). The CLI still fetched the project's leftover Runtime Config values and bundled them into every deploy, which prints the "Action required before March 2027" deprecation notice and would break deploys once Runtime Config shuts down. disallowLegacyRuntimeConfig skips that step. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 of 2 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1678
Also includes the
alertcallable fix (was #1693) and the Runtime Config deprecation fix (was #1694).Why
The upstream blocker is gone: firebase-functions 7.4.0 (2026-09-15) made 2nd gen Authentication triggers (
onUserCreated/onUserDeleted) generally available (firebase/firebase-functions#1959, closing firebase/firebase-functions#1383).userCreatewas the only Gen1 function, so moving it makes the whole codebase Gen2 and lets it run onnodejs24. No workaround (Firestore trigger, blocking function, split codebase) needed.What
userCreate(Gen1auth.user().onCreate) →userCreated(Gen2onUserCreated, Eventarcgoogle.firebase.auth.user.v2.created). Same logic: skip users without email/phone, otherwise apply pending invites.firebase-functions^6.6.0→^7.4.0. v7 breaking changes checked: nofunctions.config()usage, rootfirebase-functionsimport still resolves to v2.functions/firebase-tools14.27.0→15.31.0(Gen2 auth triggers work in the Functions/Auth emulators from 15.30.2).engines.node22→24;.nvmrc(used by every CI workflow) and.claude/launch.json→ Node 24 so CI and emulators run the functions runtime.The Firebase CLI can't upgrade a function from Gen1 to Gen2 in place, hence the rename.
firebase deploy --only functionswill createuserCreatedand ask to delete the old Gen1userCreate(answer yes, or pass--force). A user who signs up in the seconds between the two steps could be handled by both (applying an invite twice is harmless) or by neither.Also in this PR
alertcallable readsrequest.data(was #1693)The root
firebase-functionsexport is v2 since v6, soalert'sonCall((data) => …)received aCallableRequest: the empty check never fired and the whole request (incl. the ExpressrawRequest) was sent as the OpsGenie body, breaking alerts from the web app. Now usesonCall/HttpsErrorfromfirebase-functions/v2/httpsandrequest.data. Newalert.spec.ts(empty data, missing OpsGenie env, valid payload posted); it fails 2/3 against the old code.Stop uploading legacy Runtime Config on deploy (was #1694)
Deploys printed the "Action required before March 2027"
functions.config()notice. The code reads config fromfunctions/.env*, but the CLI still fetched the project's leftover Runtime Config values and bundled them into each deploy (would fail once Runtime Config shuts down)."disallowLegacyRuntimeConfig": trueinfirebase.jsonskips that (supported by CLI 14.27, 15.30, 15.31); install docs updated. Optional cleanup:firebase functions:config:getto list leftover keys,firebase functions:config:unset <key>to remove them.Test plan
userCreatedunit tests: anonymous user → no-op; email user → pending-invite query (destinationUserInfo == email,status == emailSent)platform: gcfv2,eventType: google.firebase.auth.user.v2.createdemailSentinvite forjane@example.com, signed the user up in the Auth emulator →userCreatedran, invite becamecompleted, user added to the projectmembersalert.spec.ts),functionstsc,vite buildon Node 24firebase deploy --only functions --dry-run) no longer prints the Runtime Config deprecation notice🤖 Generated with Claude Code
Note
Medium Risk
Auth signup now depends on a new Gen2 function and a deploy that deletes the Gen1 trigger; a brief window could miss or double-handle invites, though duplicate invite application is described as harmless.
Overview
Upgrades Cloud Functions to Node 24 and bumps
firebase-functionsto v7 andfirebase-toolsto 15.31 so the stack matches Gen2 auth triggers and emulator support..nvmrcand.claude/launch.jsonnow usenode@24for CI and local emulators.Replaces the Gen1
userCreateauthonCreatehandler with Gen2userCreated(onUserCreatedfromfirebase-functions/v2/identity). Behavior is unchanged: anonymous users with no email/phone are skipped; otherwisecheckPendingInviteAndProcessThemruns. The rename is required because Firebase cannot migrate Gen1 → Gen2 in place—deploy will createuserCreatedand remove the old function.Tests move from
userCreate.spec.tstouserCreated.spec.ts, including a new case that email signups query pending invites (destinationUserInfo,status == emailSent).Reviewed by Cursor Bugbot for commit 0ba2db6. Configure here.