firebase / firebase/firebase-functions

v2 Functions Auth Context does not carry tenant information when using Identity Platform

Open
#1,574 4 comments 0 reactions 0 assignees View on GitHub
api: firestore feature request
Dominant language
TypeScript
Stars
1.1k
Forks
232
Avg merge
20h 46m
Merged PRs (30d)
15

Description

### [REQUIRED] Version info
**node:**
20.14.0

**firebase-functions:**
5.0.1

**firebase-tools:**
13.11.2

**firebase-admin:**
12.1.1

### [REQUIRED] Test case
See below

### [REQUIRED] Steps to reproduce
1. Create a Firebase v2 Function with Auth Context that listens to a document
```
import { onDocumentCreatedWithAuthContext } from "firebase-functions/v2/firestore"

exports.syncUser = onDocumentCreatedWithAuthContext("users/{userId}", (event) => {
const { authType, authId } = event; // These are the only two strings related to auth and do not contain tenant information
console.log(authType, authId};
});
```
2. Authenticate client-side as a tentant-scoped user via Identify Platform
3. Observe that auth context ([as documented here](https://github.com/cloudevents/spec/blob/main/cloudevents/extensions/authcontext.md)) is not tenant aware.

### [REQUIRED] Expected behavior
Tenant id should be in Auth Context of v2 Functions. This seems to be a regression from v1 Functions where the tenantId is carried in context.

### [REQUIRED] Actual behavior
Auth Context of v2 Functions does not carry tenant information. This makes it impossible to access a tenant-scoped user's information unless tenantId is tracked outside of the auth stack because Firebase Auth is tenant specific and requires to be initiated with tenantId.

### Were you able to successfully deploy your functions?
Yes

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.