Skip to content

fix(appcheck,macos): fix how appAttestWithDeviceCheckFallback is working on fallback - #18568

Open
Lyokone wants to merge 1 commit into
mainfrom
fix/17057
Open

fix(appcheck,macos): fix how appAttestWithDeviceCheckFallback is working on fallback#18568
Lyokone wants to merge 1 commit into
mainfrom
fix/17057

Conversation

@Lyokone

@Lyokone Lyokone commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Description

AppleProvider.appAttestWithDeviceCheckFallback chose its provider on OS version alone, so on macOS 14+ it always installed AppAttestProvider and never fell back to DeviceCheck. Since App Attest also requires device support — commonly absent on macOS — every token request then failed with "The attestation provider AppAttestProvider is not supported on current platform and OS version", raised by the SDK at getToken time rather than at activation. AppAttestProvider(app:) is declared nullable but never returns nil in the current SDK, so nothing surfaced the problem earlier either.

The fix checks DCAppAttestService.shared.isSupported — the same capability the SDK checks — before selecting App Attest, and falls back to DeviceCheckProvider otherwise:

var appAttestProvider: (any AppCheckProvider)?
if #available(iOS 14.0, macOS 14.0, *), DCAppAttestService.shared.isSupported {
  appAttestProvider = AppAttestProvider(app: app)
}
delegateProvider = appAttestProvider ?? DeviceCheckProvider(app: app)

The ?? also covers the nullable initializer, so the fallback holds if a future SDK version starts returning nil. iOS behaviour is unchanged where App Attest is supported. Callers can drop Platform.isMacOS special-casing after this.

Not addressed here: DeviceCheck being unreliable on some macOS versions is upstream (firebase-ios-sdk#10095, still open). Separately, the appAttest case immediately above silently substitutes AppCheckDebugProvider when the OS is too old — shipping a debug provider in a release build seems worse than a clear error, but that is a behaviour change and is left out of this PR deliberately.

Related Issues

Checklist

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • My PR includes unit or integration tests for all changed/updated/fixed behaviors (See Contributor Guide).
  • All existing and new tests are passing.
  • I updated/added relevant documentation (doc comments with ///).
  • The analyzer (melos run analyze) does not report any problems on my PR.
  • I read and followed the Flutter Style Guide.
  • I signed the CLA.
  • I am willing to follow-up on review comments in a timely manner.

Breaking Change

  • Yes, this is a breaking change.
  • No, this is not a breaking change.

@gemini-code-assist

Copy link
Copy Markdown
Contributor
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[firebase_app_check]: MacOS : The attestation provider AppAttestProvider is not supported on current platform and OS version

3 participants