Skip to content

docs(app-check): explain App Check during server rendering - #3775

Draft
armando-navarro wants to merge 1 commit into
angular:mainfrom
armando-navarro:b32-app-check-ssr-docs
Draft

armando-navarro wants to merge 1 commit into
angular:mainfrom
armando-navarro:b32-app-check-ssr-docs

Conversation

@armando-navarro

Copy link
Copy Markdown
Collaborator

Caution

Do not merge until AngularFire 21.0.0 is ready to release

This documents behavior from #3773, which no published release contains yet. Merge it together with the 21.0.0 release.

Fixes #3774
Refs #3256

Adds a "Server-side rendering" section to docs/app-check.md for the behavior #3773 introduced. #3773's development-mode warning links to this page.

Changes

  • Explains that AngularFire does not create an App Check instance during server rendering, and that inject(AppCheck) returns null there although its type says AppCheck.
  • Explains that Firebase requests made during server rendering carry no App Check token, and links Firebase's recommended appCheckToken route for products that enforce App Check.
  • Shows the APP_CHECK_ON_SERVER opt-in in a full app.config.server.ts.
  • For 21.0.0-rc.1 and earlier, shows a browser-only config that keeps provideAppCheck off the server, with inject(AppCheck, { optional: true }).

Verification

Followed the section literally in a new ng new --ssr Angular 21 app:

  • 21.0.0-rc.1, the Dependency Injection setup as written: ng build fails with ReferenceError: document is not defined, as the section says.
  • 21.0.0-rc.1, the browser-only config: the build succeeds, AppCheck is null on the server, and App Check starts in the browser.
  • A canary built from main after fix(app-check)!: skip App Check during server rendering by default #3773, the Dependency Injection setup as written: the build succeeds and AppCheck is null on the server.
  • The same canary with the APP_CHECK_ON_SERVER snippet as written: it compiles, and App Check runs on the server.

The App Check guide said nothing about server-rendered apps. angular#3773
stops AngularFire from creating an App Check instance during server
rendering, so the new section explains that inject(AppCheck) is null
there, that Firebase requests made while rendering carry no App Check
token, and how to opt back in with APP_CHECK_ON_SERVER. It also shows
a browser-only config for 21.0.0-rc.1 and earlier, where the guide's
setup fails with "document is not defined".
@armando-navarro armando-navarro added this to the 21.0.0 milestone Sep 28, 2026
@armando-navarro armando-navarro added comp: app-check App Check (src/app-check). comp: docs Documentation. comp: ssr Server-side rendering, hydration, @angular/ssr interop. target: major This PR is targeted for the next major release type: chore Maintenance with no user-facing behavior change. labels Sep 28, 2026

@tyler-reitz tyler-reitz left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

The null-on-server behavior is covered by the toBeNull() specs in app-check.spec.ts, and CI ran them green on this branch. I did not rerun the rc.1 document is not defined case; I confirmed from source that 21.0.0-rc.1's app-check.module.ts has no server skip, which is consistent with it.

Optional, not blocking: #3773's dev-mode warning links here, but the section never uses the warning's wording, so a reader arriving from the console has nothing to match.

One flag on the hold: this approval alone makes it mergeable. Branch protection is an aggregator, so the approval is the only real gate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: app-check App Check (src/app-check). comp: docs Documentation. comp: ssr Server-side rendering, hydration, @angular/ssr interop. target: major This PR is targeted for the next major release type: chore Maintenance with no user-facing behavior change.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: the App Check guide does not cover server-side rendering

2 participants