feat(cloud_functions): expose allowInsecureTokenAttachment for Apple debug builds - #18734
Conversation
…debug builds Physical devices cannot send Auth and App Check tokens to a Functions emulator on a LAN address unless the Apple SDK debug opt-in is set.
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. |
Description
Exposes
FirebaseFunctions.allowInsecureTokenAttachmentso a physical Apple device can send Auth, FCM, and App Check tokens to a Functions emulator on a LAN address.Since Apple SDK 12.17, Functions refuses those tokens over plain HTTP unless the host is loopback. A device cannot use the Mac's loopback, so
useFunctionsEmulator('192.168.1.x', 5001)fails withunauthenticatedwhen App Check is enforced. SDK 12.19.0, already pinned byfirebase_core, adds a debug-only opt-in. This PR forwards that flag from Dart throughcall()andstream(), and sets it on the AppleFunctionsinstance inside#if DEBUG. Android and web already attach the tokens, so the flag has no effect there. Profile and release builds ignore it because the Apple SDK does not compile the property in.Related Issues
Fixes #18732
Related to #18714
Checklist
Before you create this PR confirm that it meets all requirements listed below by checking the relevant checkboxes (
[x]).This will ensure a smooth and quick review process. Updating the
pubspec.yamland changelogs is not required.///).melos run analyze) does not report any problems on my PR.Breaking Change
Does your PR require plugin users to manually update their apps to accommodate your change?
Test plan
flutter testincloud_functions(firebase_functions_test.dart)flutter testincloud_functions_platform_interface(method_channel_https_callable_test.dart)dart analyzeoncloud_functionsandcloud_functions_platform_interfaceflutter runon a physical iOS device against a Functions emulator on a LAN IP with App Check enforced