fix: firebase user email actions changed - #244
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Transient verification failures become terminal, repeated query parameters can cause a 500 response, and the core reset workflow lacks coverage.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Adds a generic Firebase auth-action route that dispatches email verification and password-reset links to localized handlers.
Changes:
- Adds Firebase action routing with locale resolution and backward compatibility.
- Implements the password-reset form and error handling.
- Adds translations and unit tests for routing/error helpers.
- Applied Vercel React best practices during review.
| File | Description |
|---|---|
ResetPassword.tsx |
Implements the password-reset workflow. |
reset-password/page.tsx |
Exposes the reset-password route. |
reset-password-errors.ts |
Maps Firebase reset errors. |
reset-password-errors.spec.ts |
Tests error mapping. |
email-verification/page.tsx |
Redirects legacy action links. |
auth/action/page.tsx |
Adds the generic Firebase action entry point. |
auth-actions.ts |
Resolves action targets and locales. |
auth-actions.spec.ts |
Tests action resolution. |
AuthActionError.tsx |
Displays unsupported-action errors. |
messages/fr.json |
Adds French translations. |
messages/en.json |
Adds English translations. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| try { | ||
| const verifiedEmail = await app.auth().verifyPasswordResetCode(oobCode); |
|
*Lighthouse ran on https://mobilitydatabase-ehwi6nk5b-mobility-data.vercel.app/ * (Desktop)
*Lighthouse ran on https://mobilitydatabase-ehwi6nk5b-mobility-data.vercel.app/feeds * (Desktop)
*Lighthouse ran on https://mobilitydatabase-ehwi6nk5b-mobility-data.vercel.app/feeds/gtfs/mdb-2126 * (Desktop)
*Lighthouse ran on https://mobilitydatabase-ehwi6nk5b-mobility-data.vercel.app/feeds/gtfs_rt/mdb-2585 * (Desktop)
*Lighthouse ran on https://mobilitydatabase-ehwi6nk5b-mobility-data.vercel.app/feeds/gbfs/gbfs-flamingo_porirua * (Desktop)
|


Summary:
When a user requested a reset password action, the link coming from the reset password email was not correct
ex:
https://mobilitydatabase.org/email-verification?mode=resetPassword&oobCode=y&apiKey=xThis happened because when we changed the action link in the firebase console for the email verification, it auto applied it to all the actions
email-verificationpassword-resetThe solution was to include a generic action link
/auth/actionthat will redirect the user to the correct page depending on the mode firebase providesExpected behavior:
When a user needs to verify their email address or reset their password, the link given to them in the email should succeed
Testing tips:
Important
For the firebase dev environment we use
https://mobilitydatabase.org/auth/actionbecause there is no stable dev environment, all you need to do is replacehttps://mobilitydatabase.org/with the preview url and it will work. This is the link you will find in the emailTo Note
There are 2 more unaccounted firebase actions that we do not have pages for because we do not support them
Once this gets merged to production I will change the action urls in firebase console prod
Please make sure these boxes are checked before submitting your pull request - thanks!
yarn testto make sure you didn't break anything