Skip to content

server: ensure Firestore composite index for (providerUserId, provider) on users collection #386

Description

@bpowers

Problem

The Apple OAuth no-email resolution path and getOrCreateUserFromVerifiedInfo use compound Firestore queries via findOneByScan({ providerUserId, provider }). These compound queries require a Firestore composite index on (providerUserId, provider) in the users collection. Without this index, these queries will fail at runtime with a Firestore error.

Why it matters

  • Correctness: Users signing in via Apple OAuth (especially those who choose to hide their email) will hit a runtime failure if the composite index is not deployed.
  • Reliability: The getOrCreateUserFromVerifiedInfo path is used for linking OAuth provider information to existing accounts, so this affects all OAuth providers when falling back to provider ID lookup.

Component(s) affected

  • src/server -- authentication/user resolution logic (authn.ts, models/table-firestore.ts)
  • Firestore infrastructure configuration

Possible approaches

  1. Add the composite index to firestore.indexes.json (or equivalent Firestore index configuration) and deploy it.
  2. Alternatively, document the required index so that any deployment runbook includes it.
  3. Consider adding a startup-time or integration-test check that verifies the required indexes exist.

Context

Identified during review of the server-side-auth branch, specifically the Apple OAuth fallback path introduced in commit 3383c05 ("server: fallback to email check when Apple provider lookup fails") and the provider info update path in commit 4bdccd4 ("server: update provider info when password user signs in with OAuth").

Activity

  1. added
    backendInvolves the Google App Engine node app
    on Jun 8, 2026
  2. bpowers commented on Jun 9, 2026

    @bpowers
    OwnerAuthor

    This describes the server-side-auth branch (commit fec5fc61), which was never merged.

    On main there is no providerUserId field or compound findOneByScan({ providerUserId, provider }) query -- the only compound scan is findOneByScan({ email }) in src/server/authn.ts. The Apple no-email fallback that needs the composite index (branch commits 3383c05d / 4bdccd49) isn't present. src/app/firebase.json configures only emulators, so there is no Firestore index management in the repo to add it to.

    Closing as not applicable to main. If server-side-auth lands, add the composite index as part of that work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendInvolves the Google App Engine node app

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions