Skip to content

Functions: Node 24 with Gen2 auth trigger, fix alert callable, drop legacy Runtime Config - #1692

Open
HugoGresse wants to merge 3 commits into
mainfrom
feat/functions-node24-gen2-auth
Open

HugoGresse wants to merge 3 commits into
mainfrom
feat/functions-node24-gen2-auth

Conversation

@HugoGresse

@HugoGresse HugoGresse commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Closes #1678

Also includes the alert callable fix (was #1693) and the Runtime Config deprecation fix (was #1694).

Why

The upstream blocker is gone: firebase-functions 7.4.0 (2026-09-15) made 2nd gen Authentication triggers (onUserCreated / onUserDeleted) generally available (firebase/firebase-functions#1959, closing firebase/firebase-functions#1383). userCreate was the only Gen1 function, so moving it makes the whole codebase Gen2 and lets it run on nodejs24. No workaround (Firestore trigger, blocking function, split codebase) needed.

What

  • userCreate (Gen1 auth.user().onCreate) → userCreated (Gen2 onUserCreated, Eventarc google.firebase.auth.user.v2.created). Same logic: skip users without email/phone, otherwise apply pending invites.
  • firebase-functions ^6.6.0 → ^7.4.0. v7 breaking changes checked: no functions.config() usage, root firebase-functions import still resolves to v2.
  • functions/ firebase-tools 14.27.0 → 15.31.0 (Gen2 auth triggers work in the Functions/Auth emulators from 15.30.2).
  • engines.node 22 → 24; .nvmrc (used by every CI workflow) and .claude/launch.json → Node 24 so CI and emulators run the functions runtime.

⚠️ Deploy

The Firebase CLI can't upgrade a function from Gen1 to Gen2 in place, hence the rename. firebase deploy --only functions will create userCreated and ask to delete the old Gen1 userCreate (answer yes, or pass --force). A user who signs up in the seconds between the two steps could be handled by both (applying an invite twice is harmless) or by neither.

Also in this PR

alert callable reads request.data (was #1693)

The root firebase-functions export is v2 since v6, so alert's onCall((data) => …) received a CallableRequest: the empty check never fired and the whole request (incl. the Express rawRequest) was sent as the OpsGenie body, breaking alerts from the web app. Now uses onCall/HttpsError from firebase-functions/v2/https and request.data. New alert.spec.ts (empty data, missing OpsGenie env, valid payload posted); it fails 2/3 against the old code.

Stop uploading legacy Runtime Config on deploy (was #1694)

Deploys printed the "Action required before March 2027" functions.config() notice. The code reads config from functions/.env*, but the CLI still fetched the project's leftover Runtime Config values and bundled them into each deploy (would fail once Runtime Config shuts down). "disallowLegacyRuntimeConfig": true in firebase.json skips that (supported by CLI 14.27, 15.30, 15.31); install docs updated. Optional cleanup: firebase functions:config:get to list leftover keys, firebase functions:config:unset <key> to remove them.

Test plan

  • userCreated unit tests: anonymous user → no-op; email user → pending-invite query (destinationUserInfo == email, status == emailSent)
  • Built endpoint manifest: platform: gcfv2, eventType: google.firebase.auth.user.v2.created
  • End to end in the emulators on Node 24 (isolated demo project): seeded a project and an emailSent invite for jane@example.com, signed the user up in the Auth emulator → userCreated ran, invite became completed, user added to the project members
  • All Vitest suites on Node 24 (root 206, functions 148 incl. alert.spec.ts), functions tsc, vite build on Node 24
  • After deploy: sign up with an invited email in production and check the invite is applied
  • Deploy (or firebase deploy --only functions --dry-run) no longer prints the Runtime Config deprecation notice

🤖 Generated with Claude Code


Note

Medium Risk
Auth signup now depends on a new Gen2 function and a deploy that deletes the Gen1 trigger; a brief window could miss or double-handle invites, though duplicate invite application is described as harmless.

Overview
Upgrades Cloud Functions to Node 24 and bumps firebase-functions to v7 and firebase-tools to 15.31 so the stack matches Gen2 auth triggers and emulator support. .nvmrc and .claude/launch.json now use node@24 for CI and local emulators.

Replaces the Gen1 userCreate auth onCreate handler with Gen2 userCreated (onUserCreated from firebase-functions/v2/identity). Behavior is unchanged: anonymous users with no email/phone are skipped; otherwise checkPendingInviteAndProcessThem runs. The rename is required because Firebase cannot migrate Gen1 → Gen2 in place—deploy will create userCreated and remove the old function.

Tests move from userCreate.spec.ts to userCreated.spec.ts, including a new case that email signups query pending invites (destinationUserInfo, status == emailSent).

Reviewed by Cursor Bugbot for commit 0ba2db6. Configure here.

firebase-functions 7.4.0 made 2nd gen Authentication triggers generally
available. Replace the Gen1 auth.user().onCreate trigger (the only Gen1
function, which capped the runtime at nodejs22) with onUserCreated, so
the whole codebase is Gen2 and can run on nodejs24.

- userCreate (Gen1) -> userCreated (Gen2). The CLI cannot upgrade a
  function from Gen1 to Gen2 in place, so it is renamed; the deploy
  deletes the old userCreate.
- firebase-functions ^6.6.0 -> ^7.4.0; firebase-tools 14.27.0 ->
  15.31.0 (Gen2 auth triggers work in the emulators from 15.30.2).
- engines.node, .nvmrc and the local launch config -> 24.

Closes #1678

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cursor

cursor Bot commented Sep 26, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_58a7bdfa-4677-48e4-8ef2-ba07fd4e1752)

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Preview for ecb89c2 (sandbox project open-feedback-hugo, expires in 7 days): https://open-feedback-hugo--pr-1692-bu131zno.web.app

@cypress

cypress Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

open-feedback    Run #3104

Run Properties:  status check passed Passed #3104  •  git commit ecb89c275e: chore(functions): stop uploading legacy Runtime Config on deploy
Project open-feedback
Branch Review feat/functions-node24-gen2-auth
Run status status check passed Passed #3104
Run duration 02m 08s
Commit git commit ecb89c275e: chore(functions): stop uploading legacy Runtime Config on deploy
Committer Hugo Gresse
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 14
View all changes introduced in this branch ↗︎

HugoGresse and others added 2 commits September 26, 2026 15:43
The root firebase-functions export is v2 since v6, so the alert onCall
handler received a CallableRequest, not the payload: the empty check
never fired and the whole request (including the Express rawRequest)
was serialized as the OpsGenie body. Use the v2 onCall/HttpsError
imports and request.data, and cover the handler with a spec.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The functions read their configuration from functions/.env* files, not
functions.config(). The CLI still fetched the project's leftover Runtime
Config values and bundled them into every deploy, which prints the
"Action required before March 2027" deprecation notice and would break
deploys once Runtime Config shuts down. disallowLegacyRuntimeConfig
skips that step.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@HugoGresse HugoGresse changed the title Move Cloud Functions to Node 24 with a Gen2 auth trigger Functions: Node 24 with Gen2 auth trigger, fix alert callable, drop legacy Runtime Config Sep 26, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Move Cloud Functions to Node 24 (blocked by Gen1 userCreate auth trigger)

1 participant