From 789897c19e9d1001eca9f42f53392e12133a97b2 Mon Sep 17 00:00:00 2001 From: Armando Navarro Date: Thu, 24 Sep 2026 20:19:04 -0700 Subject: [PATCH 1/2] fix(auth): stop beforeAuthStateChanged from holding the app unstable AngularFire wrapped beforeAuthStateChanged so that registering the hook added a pending task, cleared only when the callback first runs. Firebase runs that callback only on a sign-in or sign-out, so for a visitor who does neither the app never became stable. Registered on the server, it failed ng build during route extraction and left server-rendered requests without a response. This restores the blockUntilFirst: false override from #3590, which #3613 dropped without comment while adding log-level overrides next to it. The callback still runs inside Angular's zone and injection context, and its returned promise still reaches Firebase, so a rejection still cancels the sign-in. A call outside an injection context now logs its per-call warning only at the verbose level, as onMessage does. Fixes #3748 --- src/auth/firebase.ts | 2 +- tools/build.ts | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/src/auth/firebase.ts b/src/auth/firebase.ts index 743ca90d8..5d359e54d 100644 --- a/src/auth/firebase.ts +++ b/src/auth/firebase.ts @@ -58,7 +58,7 @@ import { } from 'firebase/auth'; export const applyActionCode = ɵzoneWrap(_applyActionCode, true); -export const beforeAuthStateChanged = ɵzoneWrap(_beforeAuthStateChanged, true); +export const beforeAuthStateChanged = ɵzoneWrap(_beforeAuthStateChanged, false); export const checkActionCode = ɵzoneWrap(_checkActionCode, true); export const confirmPasswordReset = ɵzoneWrap(_confirmPasswordReset, true, 2); export const connectAuthEmulator = ɵzoneWrap(_connectAuthEmulator, true); diff --git a/tools/build.ts b/tools/build.ts index 2e5b2964f..46a1ed370 100644 --- a/tools/build.ts +++ b/tools/build.ts @@ -177,6 +177,8 @@ ${exportedZoneWrappedFns} indexedDBLocalPersistence: null, prodErrorMap: null, multiFactor: null, + // Its callback fires only on a sign-in or sign-out, so blocking would keep `ApplicationRef.isStable` false. + beforeAuthStateChanged: { blockUntilFirst: false }, linkWithCredential: { logLevel: LogLevel.VERBOSE }, linkWithPhoneNumber: { logLevel: LogLevel.VERBOSE }, linkWithPopup: { logLevel: LogLevel.VERBOSE }, From da1631a7ecf93dd3ae9506406f4d05574da82159 Mon Sep 17 00:00:00 2001 From: Armando Navarro Date: Sun, 27 Sep 2026 16:45:59 -0700 Subject: [PATCH 2/2] docs(auth): scope the beforeAuthStateChanged note to rc.1 and earlier Merging this change closes #3748, so the section's present-tense note would point at a closed issue. Also removed the false claim that the @angular/fire/auth import makes ng build hang: the guide registers the hook only in the browser, so its own build succeeds. --- docs/auth.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/docs/auth.md b/docs/auth.md index 0faef0072..31f6056c2 100644 --- a/docs/auth.md +++ b/docs/auth.md @@ -153,9 +153,7 @@ If you need a session the browser cannot read, use Firebase's [session cookies]( #### `beforeAuthStateChanged` from `firebase/auth` -One import in the code above is deliberately different from the rest of this guide. `beforeAuthStateChanged` comes from `firebase/auth` rather than `@angular/fire/auth`. AngularFire's version keeps the app marked as busy until its callback first runs, and this callback only runs when someone signs in or out. - -Importing it from `@angular/fire/auth` makes `ng build` hang during route extraction and fail with a timeout. That is a bug on our side, tracked in [#3748](https://github.com/angular/angularfire/issues/3748). Once the fix lands, this can be imported from `@angular/fire/auth` like everything else. +One import in the code above is deliberately different from the rest of this guide. `beforeAuthStateChanged` comes from `firebase/auth` rather than `@angular/fire/auth`. In AngularFire 21.0.0-rc.1 and earlier, AngularFire's version keeps the app marked as busy until its callback first runs, and this callback only runs when someone signs in or out ([#3748](https://github.com/angular/angularfire/issues/3748)). ### 3. Pass the cookie into the render