chore(deps): migrate firebase-admin to v14 (#141) - #142
Conversation
…es (#141) firebase-admin 14 removes the legacy namespace API — this repo already used modular entrypoints. The real change is architectural: the combined lib/firebase-admin.ts is split into firebase-admin-app/-db/-auth modules so Firestore-only routes (trade leads, audit, user/invitation records) no longer import firebase-admin/auth — whose jwks-rsa -> jose chain is the class of failure behind the nfl-picks Vercel ERR_REQUIRE_ESM outage. serverExternalPackages keeps firebase-admin out of the server bundle so Next does not rewrite its Node-specific dependency graph. A plain-Node import smoke check (npm run check:admin-import, wired into npm test) and a module-graph regression test guard the split and the runtime chain. The jose override is intentionally NOT applied yet: whether Vercel's Node 24 runtime tolerates jose@6 via require(esm) is verified in the Preview deployment for this PR (issue #141 tracks the checklist). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's GuideMigrates firebase-admin to v14 while isolating Auth from Firestore imports, externalizing the Admin package from Next.js server bundles, and adding dependency-tree regression checks aimed at preventing ERR_REQUIRE_ESM failures. Review the module boundaries and route import updates, the serverExternalPackages behavior, and the remaining required Vercel Preview runtime validation before merge. Sequence diagram for credential-free Firebase Admin import validationsequenceDiagram
participant Check as check-admin-import.mjs
participant Node as Node runtime
participant Package as firebase-admin@14
participant App as firebase-admin/app
participant Auth as firebase-admin/auth
participant Firestore as firebase-admin/firestore
Check->>Node: findPackageJSON(firebase-admin)
Node-->>Check: package version
Check->>Check: [version starts with 14.]
Check->>Package: import firebase-admin/app
Package-->>Check: initializeApp, cert, getApps
Check->>Package: import firebase-admin/auth
Package-->>Check: getAuth
Check->>Package: import firebase-admin/firestore
Package-->>Check: getFirestore
Check->>Node: console.log(server import chain OK)
Flow diagram for Firestore-only dependency isolationflowchart TD
Route[Firestore-only route or library]
DB[getFirebaseAdminDb]
App[getFirebaseAdminApp]
Firestore[firebase-admin/firestore]
AuthGraph[firebase-admin/auth\njwks-rsa -> jose]
Route --> DB
DB --> App
DB --> Firestore
DB -. does not import .-> AuthGraph
File-Level Changes
Assessment against linked issues
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
The Preview deployment reproduced the exact outage class: firebase-admin -> jwks-rsa (CJS) requires jose; unoverridden resolution picks jose@6.1.3 (ESM-only), and Vercel's externalized module loader rejects the ESM require even on Node 24 — both admin API routes 500'd at module load. Scoped override (matches the proven nfl-picks fix): jwks-rsa -> jose 5.10.0. Resolution now firebase-admin@14.5.0 -> jwks-rsa@4.1.0 -> jose@5.10.0. The graph regression test now asserts jose stays require-able. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Vercel Preview runtime validation — PASSED (after jose pin)Two-stage result — the failure reproduced exactly as predicted without the pin: Deploy
Deploy
Resolved tree: |
|
Verified that it works in preview. |
Summary
Migrates
firebase-admin^13.10.0->^14.5.0and splits the combinedlib/firebase-admin.tshelper into per-service modules so Firestore-only routes never import thefirebase-admin/auth(jwks-rsa -> jose) dependency graph — the failure class behind the nfl-picks VercelERR_REQUIRE_ESMoutage. Part of the coordinated fleet migration; follows the proven nfl-picks pattern and the rise-saba migration validated in a real Vercel Preview (spizeck/rise-saba#116).Closes #141
Changes
package.json:firebase-admin->^14.5.0; addscheck:admin-importscript wired intonpm test.lib/firebase-admin-app.ts— app initialization (unchanged semantics: env credentials, missing-credential error naming variables).lib/firebase-admin-db.ts—getFirebaseAdminDb(Firestore-only consumers import this alone).lib/firebase-admin-auth.ts—getFirebaseAdminAuth(auth-only consumers import this alone).lib/firebase-admin.ts; updated all 9 call sites.next.config.ts: addsserverExternalPackages: ["firebase-admin"]— keeps the Admin Node dependency graph out of the serverless bundle.scripts/check-admin-import.mjs— credential-free plain-Node entrypoint import check; asserts installed major is 14.tests/lib/firebase-admin-graph.test.ts— real-dependency-tree regression test (no mocks): entrypoint imports,require("firebase-admin/auth")without ERR_REQUIRE_ESM, source-level guard that Firestore-only modules never import the Auth graph.joseoverride yet, deliberately:firebase-admin@14.5.0resolvesjwks-rsa@4.1.0 -> jose@6.1.3(ESM-only). Whether Vercel's Node 24 runtime tolerates this via require(esm) is verified in this PR's Preview deployment; the scopedjwks-rsa -> jose@5.10.0override (the nfl-picks fix) will be applied if the failure reproduces.Verification
npm ci/npm installclean (firebase-admin@14.5.0,jwks-rsa@4.1.0,jose@6.1.3unoverridden)npm run check:react-versionsnpx tsc --noEmitnpm run lintnpm test(376 pass incl. new graph suite;check:admin-importprintsfirebase-admin@14.5.0: server import chain OK)npm run test:rules(needs Java 21+) — no rules changes in this PRnpm run buildnpm run check:md-linksGET /api/admin/mewithout token -> 401 with admin module graph loaded;POST /api/admin/invitations/acceptwith invalid bearer -> verifyIdToken executes; runtime logs free of ERR_REQUIRE_ESM/joseRisk / deployment notes
No secrets, credentials, or private data were committed.
Preview-only validation; no production deployment. If the Preview runtime reproduces ERR_REQUIRE_ESM, the scoped
jose@5.10.0override gets added and redeployed before merge.Summary by Sourcery
Upgrade Firebase Admin to v14 and isolate its service dependency graphs to ensure reliable server-side imports.
Bug Fixes:
Enhancements:
Build:
Tests:
Chores: