Skip to content

fix(push): wire SW FCM_TOKEN_REFRESH relay and harden lifecycle - #934

Merged
llinsss merged 1 commit into
DogStark:mainfrom
neymer2:feature/push-notification-lifecycle
Aug 28, 2026
Merged

fix(push): wire SW FCM_TOKEN_REFRESH relay and harden lifecycle#934
llinsss merged 1 commit into
DogStark:mainfrom
neymer2:feature/push-notification-lifecycle

Conversation

@neymer2

@neymer2 neymer2 commented Aug 26, 2026

Copy link
Copy Markdown
  • Add window message listener for FCM_TOKEN_REFRESH posted by the service worker so token rotation works through both channels: a. Firebase SDK onTokenRefresh (existing) b. SW postMessage relay (new)
  • Add messagingRef to hold the active Messaging instance; cleared by unsubscribe() and unmount so the SW listener is a no-op when idle
  • Add userIdRef / vapidKeyRef so fetchAndRegisterToken has zero useCallback deps (no stale closures, no unnecessary re-subscriptions)
  • unsubscribe() clears messagingRef to prevent orphaned token rotations after logout

Tests (24 total, all passing):

  • Add 5 gap tests: SW relay rotation, SW listener removed on unmount, requestPermission when already granted, unsubscribe with null userId, deleteToken failure does not swallow removeDeviceToken
  • Fix loading-state test to wrap requestPermission() in act(), removing three React act() warnings

Docs: update push-notifications.md with dual-channel rotation diagram, new behaviour-guarantee rows, security note for message listener, and contributor guidance on messagingRef

closes #869

- Add window message listener for FCM_TOKEN_REFRESH posted by the
  service worker so token rotation works through both channels:
  a. Firebase SDK onTokenRefresh (existing)
  b. SW postMessage relay (new)
- Add messagingRef to hold the active Messaging instance; cleared by
  unsubscribe() and unmount so the SW listener is a no-op when idle
- Add userIdRef / vapidKeyRef so fetchAndRegisterToken has zero
  useCallback deps (no stale closures, no unnecessary re-subscriptions)
- unsubscribe() clears messagingRef to prevent orphaned token rotations
  after logout

Tests (24 total, all passing):
- Add 5 gap tests: SW relay rotation, SW listener removed on unmount,
  requestPermission when already granted, unsubscribe with null userId,
  deleteToken failure does not swallow removeDeviceToken
- Fix loading-state test to wrap requestPermission() in act(), removing
  three React act() warnings

Docs: update push-notifications.md with dual-channel rotation diagram,
new behaviour-guarantee rows, security note for message listener, and
contributor guidance on messagingRef
@drips-wave

drips-wave Bot commented Aug 26, 2026

Copy link
Copy Markdown

@neymer2 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@llinsss
llinsss merged commit ec83960 into DogStark:main Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Frontend] Complete push-notification permission and token lifecycle

2 participants