Skip to content

App Check installation verification

Build 59 adds a server-verified App Check check-in for release testers. The Firebase App Check metrics graph remains the source for aggregate traffic, but it does not identify an individual device. This workflow maps a current build to an authenticated, pseudonymous installation without storing an App Check token or debug secret.

Deploy the diagnostic functions

From the repository root, authenticate to the intended Firebase project and confirm that the CLI reports myrecipes-e8640. Then build and deploy only the two diagnostic functions:

cd functions
npm run build
cd ..
firebase deploy --project myrecipes-e8640 \
  --only functions:verify_app_check_installation,functions:report_app_check_diagnostic_failure

The verification function requires Authentication and a valid App Check token. The failure-report function requires Authentication but deliberately does not enforce App Check: a failing installation must be able to identify itself. It is rate-limited, accepts bounded metadata, and never accepts or stores a token.

Tester procedure

  1. Install the designated build from TestFlight.
  2. Sign in and use a recipe and shopping-list screen.
  3. Open Account & Settings → App Check diagnostics.
  4. Tap Run verification.
  5. Confirm the screen says App Check: Verified.
  6. If it does not, tap Copy diagnostics and send the result to support.

Automatic checks also run after sign-in, on foreground resume, and after token refresh. Automatic checks are limited to once every five minutes per running installation.

Administrative report

Use the Firebase UID that has the admin custom claim. The report is read-only:

cd functions
npm run support:app-check-diagnostics -- \
  --project=myrecipes-e8640 \
  --actor-uid=ADMIN_FIREBASE_UID \
  --build=59

The JSON output separates server-verified and unverified installations. Match the abbreviated installation value to the tester's copied diagnostics. A record is verified only when the enforced function accepted the App Check token; the Flutter client cannot set its own verified status.

Release evidence

For issue #182, record:

  • exact build and Git commit;
  • diagnostic function deployment revisions and timestamps;
  • required tester/device/OS roster;
  • the report output with user identifiers redacted if copied outside the private repository;
  • latest verification time for every required installation;
  • any excluded or no-longer-supported installation and the product-owner decision;
  • staged enforcement time, post-enforcement canary result, and rollback owner.

Do not store or paste App Check tokens, debug tokens, Firebase ID tokens, or credentials in release evidence.