fix(users): console-created users use the Firebase uid as doc ID
create_user wrote the profile with .add() (random doc ID). On first login the
FlutterFlow app looks for users/{uid}, doesn't find it, and creates a second,
bare doc - so every console-created user ended up duplicated, and devices
assigned in the console pointed at the doc the app never reads.
Now the profile is written to users/{uid} with created_time set, and the email
is lowercased to match what Firebase Auth stores. If the Firestore write
fails, the just-created Auth account is deleted so no orphan is left.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -64,7 +64,9 @@ flashed into NVS and the firmware uses it as its MQTT id. Legacy docs only have
|
||||
- `PUT /api/devices/{id}` when the body contains `user_list`
|
||||
(`devices.service.update_device`)
|
||||
- Users are resolved by the **`uid` field** (a query), **never by doc ID**. Console-
|
||||
created users get random doc IDs (`.add()`); FlutterFlow uses the uid as the doc ID.
|
||||
created users used to get random doc IDs (`.add()`) — fixed 2026-09-30, the Console
|
||||
now writes `users/{uid}` like FlutterFlow does — but older docs may still have a
|
||||
random ID, so keep resolving by the `uid` field.
|
||||
- A user is refused when `status == "blocked"`.
|
||||
- Lookups are cached in-process for 60 s (`mqtt/app_users.py`). Assign/unassign,
|
||||
update, block/unblock and delete call `invalidate(uid)`. If you add a new code path
|
||||
|
||||
Reference in New Issue
Block a user