docs(app-check): explain App Check during server rendering - #3775
Draft
armando-navarro wants to merge 1 commit into
Draft
armando-navarro wants to merge 1 commit into
armando-navarro wants to merge 1 commit into
Conversation
The App Check guide said nothing about server-rendered apps. angular#3773 stops AngularFire from creating an App Check instance during server rendering, so the new section explains that inject(AppCheck) is null there, that Firebase requests made while rendering carry no App Check token, and how to opt back in with APP_CHECK_ON_SERVER. It also shows a browser-only config for 21.0.0-rc.1 and earlier, where the guide's setup fails with "document is not defined".
tyler-reitz
approved these changes
Sep 28, 2026
tyler-reitz
left a comment
Collaborator
There was a problem hiding this comment.
Approved.
The null-on-server behavior is covered by the toBeNull() specs in app-check.spec.ts, and CI ran them green on this branch. I did not rerun the rc.1 document is not defined case; I confirmed from source that 21.0.0-rc.1's app-check.module.ts has no server skip, which is consistent with it.
Optional, not blocking: #3773's dev-mode warning links here, but the section never uses the warning's wording, so a reader arriving from the console has nothing to match.
One flag on the hold: this approval alone makes it mergeable. Branch protection is an aggregator, so the approval is the only real gate.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Caution
Do not merge until AngularFire 21.0.0 is ready to release
This documents behavior from #3773, which no published release contains yet. Merge it together with the 21.0.0 release.
Fixes #3774
Refs #3256
Adds a "Server-side rendering" section to
docs/app-check.mdfor the behavior #3773 introduced. #3773's development-mode warning links to this page.Changes
inject(AppCheck)returnsnullthere although its type saysAppCheck.appCheckTokenroute for products that enforce App Check.APP_CHECK_ON_SERVERopt-in in a fullapp.config.server.ts.provideAppCheckoff the server, withinject(AppCheck, { optional: true }).Verification
Followed the section literally in a new
ng new --ssrAngular 21 app:ng buildfails withReferenceError: document is not defined, as the section says.AppCheckisnullon the server, and App Check starts in the browser.mainafter fix(app-check)!: skip App Check during server rendering by default #3773, the Dependency Injection setup as written: the build succeeds andAppCheckisnullon the server.APP_CHECK_ON_SERVERsnippet as written: it compiles, and App Check runs on the server.