Firebase Auth token refresh behavior on Flutter Web when app is backgrounded
29K reputation · 04 Apr 2024, 00:12 UTC
Goal
Determine whether the Firebase Auth plugin for Flutter automatically refreshes ID tokens on the Web platform when the browser tab is sent to the background, and how to detect token expiration client‑side to enforce least‑privilege access.
Constraints & Uncertainty
The plugin does not expose the token expiration timestamp directly; developers must call getIdTokenResult() to read expirationTime. No configuration exists for a timeout on token refresh attempts, and the current behavior appears to differ between mobile and Web. Additionally, least‑privilege access via custom claims cannot be read client‑side, requiring server‑side verification.
Specific Questions
- Does Firebase Auth for Flutter Web automatically refresh the ID token when the tab is backgrounded, or must the app manually trigger a refresh?
- What is the recommended way to detect token expiration on the client so that the app can proactively request a new token or redirect to re‑authentication?
- Given that custom claims are not exposed client‑side, how can a Flutter app reliably enforce least‑privilege permissions without server‑side checks?