Skip to content

fix(core, web): keep App Check registered for secondary Firebase apps - #18557

Merged
Lyokone merged 2 commits into
mainfrom
fix/issue-18556
Aug 11, 2026
Merged

fix(core, web): keep App Check registered for secondary Firebase apps#18557
Lyokone merged 2 commits into
mainfrom
fix/issue-18556

Conversation

@SelaseKay

@SelaseKay SelaseKay commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Description

On web, Firebase.initializeApp() activates App Check before other services so Auth can attach X-Firebase-AppCheck. The #11625 implementation did that with _services.remove('app-check'), which permanently dropped App Check from the registry after the first app.

For a secondary named app, Auth still ran ensurePluginInitialized (and accounts:lookup) without App Check being reactivated, so the App Check header was missing on reload when Auth enforcement was enabled.

This change keeps app-check registered, awaits its ensurePluginInitialized on every initializeApp, and still skips it in the parallel Future.wait so ordering is preserved.

Related Issues

Checklist

Before you create this PR confirm that it meets all requirements listed below by checking the relevant checkboxes ([x]).
This will ensure a smooth and quick review process. Updating the pubspec.yaml and changelogs is not required.

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • My PR includes unit or integration tests for all changed/updated/fixed behaviors (See Contributor Guide).
  • All existing and new tests are passing.
  • I updated/added relevant documentation (doc comments with ///).
  • The analyzer (melos run analyze) does not report any problems on my PR.
  • I read and followed the Flutter Style Guide.
  • I signed the CLA.
  • I am willing to follow-up on review comments in a timely manner.

Breaking Change

Does your PR require plugin users to manually update their apps to accommodate your change?

  • Yes, this is a breaking change.
  • No, this is not a breaking change.

The #11625 startup path removed app-check from the service registry after
the first initializeApp, so named apps never reactivated App Check before
Auth on reload.
@gemini-code-assist

Copy link
Copy Markdown
Contributor
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

@Lyokone
Lyokone merged commit 1345dbb into main Aug 11, 2026
110 checks passed
@Lyokone
Lyokone deleted the fix/issue-18556 branch August 11, 2026 11:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants