FirebaseExtended / FirebaseExtended/reactfire

Permission error when accessing a cached firestore collection after logout/login

Aperta
#485 4 commenti 10 reazioni 0 assegnatari Vedi su GitHub
v5
Lingua principale
TypeScript
Stelle
3.6k
Fork
403
Merge medio
14h 53m
PR unite (30g)
5

Descrizione

### Version info

**React:** 17.0.2

**Firebase:** 9.4.0

**ReactFire:** 4.2.0

**Other (e.g. Node, browser, operating system) (if applicable):** Chrome, Windows 10

### Test case

Test cases seem challenging to produce since a firebase instance is involved.

### Steps to reproduce

1. Sign In (I used `GoogleAuthProvider`), or be already signed-in.
2. Read from a collection.
3. Sign Out
4. Sign In
5. Read from the same collection.

### Expected behavior

The same data is read.

### Actual behavior

`Uncaught FirebaseError: Missing or insufficient permissions.` is thrown.

This seems to be caused by the global cache of collections. The problem can be mitigated by:
* Refreshing the page after sign out
* Changing the `idField` passed to `useFirestoreCollectionData`. Any easy way to test this is to use `id-${auth.stsTokenManager.expirationTime}` as your `idField`, since `expirationTime` changes on every Sign Out/In cycle.

Note that waiting more than 30 seconds does not fix the problem. So, the cache resetting of the collection is insufficient to resolve the issue. I suspect that the collection is associated with the stale auth token which has been disabled due to logout.

A possible resolution might be to purge the cache on sign out.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Reproduce the sign-out/sign-in sequence with useFirestoreCollectionData and the same collection, then inspect how the global collection cache handles authentication changes. Compare the cached read with the workaround of changing idField after login. Done means the same collection can be read after reauthentication without a permission error, ideally with a regression test or documented reproduction.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
firebase, react, typescript
Ambito
authentication, databases
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.