Skip to content

[NextJS] Use web frameworks' built-in auth cookie instead of custom implementation #243

Description

@jhuleatt

The Firebase CLI's web frameworks tooling sets an auth cookie: https://github.com/FirebaseExtended/firebase-framework-tools/blob/087035d86c65c5810ab71f889e4d6160398368aa/src/firebase-aware.ts#L32

This means we probably don't need the current custom implementation:

export async function POST(request) {

Activity

  1. ismaelaarab commented on Oct 7, 2023

    @ismaelaarab

    @jhuleatt

    Does this imply that the example is primarily designed for use with Firebase Hosting?

    If someone chooses to host their project on Vercel instead, will they need to implement additional custom logic in order to set the session on the server side?

  2. matallui commented on Oct 12, 2023

    @matallui

    Same question? ☝🏼

  3. leonam-okajima commented on Oct 31, 2023

    @leonam-okajima

    We really need clarification on this. Are the example and tutorial designed only for use with Firebase Hosting?

  4. EmanuelU commented on Nov 5, 2023

    @EmanuelU

    after a lot of digging I am fairly sure the __session cookie expected in the tutorial is a firebase only thing, not from the auth package but from the frameworks.

  5. josancamon19 commented on Nov 28, 2023

    @josancamon19

    Yup, thanks for asking this, I was close to giving up already, and just verified that indeed, it only works if you use firebase, either from emulators or not.

  6. WillZhao2021 commented on Nov 30, 2023

    @WillZhao2021

    Was anyone able to get the __session cookie after this project is deployed to Firebase hosting? It was working fine with my hosting emulator, but it stopped working after I deployed it. I checked the cookies tab, no cookie is set at all.

  7. Herohtar commented on Feb 27, 2024

    @Herohtar

    This issue should be marked as solved, because the file in question no longer exists and indeed it seems that they implemented the auth token parsing using the __session cookie:

    export async function getAuthenticatedAppForUser(session = null) {

    However, as a couple of the more recent comments indicate, the __session cookie doesn't actually appear to be set when trying to make this work in my own project, even when using Firebase Hosting. I'm not sure if this is something that changed with Firebase Auth or some other issue.

    I did notice that something that looks like an auth token appears to be stored in Indexed DB, so maybe that's where it is now. I'm not sure how you make use of that though.

    Edit: After doing a bit more digging, I believe the code in the repo is incomplete. It looks like the intention is for the client side part of the code to set the __session cookie itself and that it is not something that gets set automatically by Firebase Auth (and never was, as far as I can tell).

  8. raky291 commented on Dec 15, 2025

    @raky291

    The Firebase team should improve the documentation and the examples. The documentation is scattered across multiple pages and isn't very clear.

    We would greatly appreciate it if you could vote for better documentation here: https://firebase.uservoice.com/forums/948424-general/suggestions/48594224-full-example-of-firebaseserverapp-in-next-js-14-us

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions