Skip to content

Added firebase in Content Security Policy and implemented firestore transport fallback - #33

Merged
prathmesh796 merged 1 commit into
mainfrom
ui
Sep 9, 2026
Merged

prathmesh796 merged 1 commit into
mainfrom
ui

Conversation

@prathmesh796

Copy link
Copy Markdown
Owner

Description

next.config.js blocked Firebase in the Content Security Policy. Firestore requests were rejected by the browser, causing TypeError: Failed to fetch.

Changes

  • Firebase, Firestore, Google APIs, and Analytics domains to connect-src.
  • Implemented a Firestore transport fallback and explicit listener error handling.

Copilot AI lite review requested due to automatic review settings September 9, 2026 05:04
@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
getlancer Ready Ready Preview Sep 9, 2026 5:04am UTC

@prathmesh796
prathmesh796 merged commit 9a5791a into main Sep 9, 2026
5 checks passed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The CSP change is overly permissive (*.googleapis.com) and should be tightened or environment-gated to preserve CSP’s security value.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Updates the Next.js app’s security headers and Firestore client initialization to prevent CSP-blocked Firebase/Firestore network requests and to improve resilience/observability of realtime listeners.

Changes:

  • Expanded connect-src CSP allowlist to include Firebase/Firestore/Google APIs and Analytics endpoints.
  • Switched Firestore initialization to initializeFirestore with long-polling auto-detection enabled.
  • Added explicit onSnapshot error callbacks for message/conversation/chat listeners.
File summaries
File Description
next.config.mjs Expands CSP connect-src to allow Firebase/Firestore/Google APIs/Analytics network calls.
lib/firebase.ts Initializes Firestore via initializeFirestore with long-polling fallback enabled.
hooks/useMessages.tsx Adds onSnapshot error callback for message listener.
hooks/useConversations.tsx Adds onSnapshot error callback for conversations listener.
hooks/useChat.tsx Adds onSnapshot error callback for chat message listener.
Review details

Suppressed comments (3)

hooks/useMessages.tsx:32

  • This listener error log lacks the conversationId, making it harder to diagnose which subscription failed when multiple conversations are active.
        console.error("Unable to listen for messages", error);

hooks/useConversations.tsx:33

  • This listener error log lacks the userId, which makes it difficult to identify which user’s conversation list subscription failed in logs.
        console.error("Unable to listen for conversations", error);

hooks/useChat.tsx:32

  • This listener error log lacks the conversationId, which makes it hard to trace failures when multiple chat listeners are active.
        console.error("Unable to listen for chat messages", error);
  • Files reviewed: 5/5 changed files
  • Comments generated: 4
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread next.config.mjs
{
key: 'Content-Security-Policy',
value: "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://getlancer.1a3c2f86a3386038e3a37e793a2777b5.r2.cloudflarestorage.com; font-src 'self' data:; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com; object-src 'none'; base-uri 'self';",
value: "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://getlancer.1a3c2f86a3386038e3a37e793a2777b5.r2.cloudflarestorage.com; font-src 'self' data:; connect-src 'self' https://challenges.cloudflare.com https://firestore.googleapis.com https://*.googleapis.com https://*.firebaseio.com https://*.firebaseapp.com https://www.google-analytics.com https://region1.google-analytics.com https://analytics.google.com https://firebaselogging.googleapis.com; frame-src 'self' https://challenges.cloudflare.com; object-src 'none'; base-uri 'self';",
Comment thread hooks/useChat.tsx
Comment on lines +31 to +34
(error) => {
console.error("Unable to listen for chat messages", error);
}
);
Comment on lines +32 to +35
(error) => {
console.error("Unable to listen for conversations", error);
}
);
Comment thread hooks/useMessages.tsx
Comment on lines +31 to +34
(error) => {
console.error("Unable to listen for messages", error);
}
);

This branch was successfully deployed

1 active deployment
Preview — 04fd46ae Deployed Sep 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants