Firebase sendSignInLinkToEmail with Custom SMTP does not work

Viewed 71

When using passwordless signin across any SDK (I'm using JS-web version 8 and iOS/Android with react-native-firebase) the link that is generated does not use the link url in the action settings if you've configured custom SMTP settings for email templates with a custom domain.

My custom domain for example is prod.fun.stuff and is already setup with Firebase Hosting and I've added it for the email templates as well.

When you use the sendSignInLinkToEmail method, you pass it an action code settings object. Here's an example of what I'm using:

const actionCodeSettings = {
    url: 'https://prod.fun.stuff/links/confirmEmail',
    handleCodeInApp: true,
    iOS: {
      bundleId: 'com.stuff.fun'
    },
    android: {
      packageName: 'com.stuff.fun'
    },
    dynamicLinkDomain: 'prod.fun.stuff'
  }

In my iOS app I've configured Universal Links properly to handle links in the app that use this domain:

# fun.entitlements
applinks:prod.fun.stuff

I use Mailgun as my email service and have configured its SMTP server settings for my domain mg.fun.stuff to send all my emails. While enabled, the login link is actually sent with:

http://email.mg.fun.stuff/e/someCrazyEncodedString...

What's unexpected is the login link is not the same domain as the actionCodeSettings I passed sendSignInLinkToEmail, and also that the protocol is http instead of https

but if I disable the custom SMTP server the login link that is sent to users is actually more intelligible:

https://prod.fun.stuff/?link=https://fun-stuff.firebaseapp.com/__/auth/action?apiKey%3DgeneratedAPIKey%26mode%3DsignIn%26oobCode%3DgeneratedoobCode%26continueUrl%3Dhttps://prod.fun.stuff/links/confirmEmail%26lang%3Den&apn=com.stuff.fun&amv=1&ibi=com.stuff.fun&ifl=https://fun-stuff.firebaseapp.com/__/auth/action?apiKey%3DgeneratedAPIKey%26mode%3DsignIn%26oobCode%3DgeneratedoobCodeQ%26continueUrl%3Dhttps://prod.stuff.fun/links/confirmEmail%26lang%3Den

It seems that with a custom SMTP server Firebase auth the login link has to be handled and decrypted by the custom server before it returns the proper redirect urls which can be handled.

This is an issue because when the user clicks on the link it doesn't get handled by the app, it instead opens the phone's browser.

Here are my Firebase SMTP settings:

enter image description here

Is there something I've possibly configured wrong with my email server? Or is this expected behavior when using a custom SMTP server? Should I handle the email server CNAME as another Universal link in the app?

0 Answers
Related