Phase 5 · Data, State & Device CapabilitiesModule 36~62 min read

Firebase & Backend Services

Add authentication, Firestore, Storage, Functions, security rules, emulators, and cost-aware repositories without coupling the UI.

What you'll learn

Add authentication, Firestore, Storage, Functions, security rules, emulators, and cost-aware repositories without coupling the UI. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.

By the end of this lesson, you'll be able to:

  • Apply Project environments in a production-shaped Flutter feature
  • Apply Authentication in a production-shaped Flutter feature
  • Apply Firestore in a production-shaped Flutter feature
  • Apply Storage in a production-shaped Flutter feature

Core mental model

Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.

ConceptWhat it meansDecision rule
Security ruleServer-enforced authorization for Firebase data accessTreat client checks as UX only and prove rules with emulator tests
Document modelFirestore data is organized around document reads and indexed queriesModel for bounded query patterns instead of relational joins
EnvironmentDevelopment, staging, and production use isolated backend resourcesMake accidental cross-environment writes structurally difficult

Professional workflow

Work in small vertical slices and keep behavior observable from the first iteration.

  1. Define the repository-isolated Firebase feature boundary: user goal, inputs, visible states, ownership, and expected failures.
  2. Build the smallest working vertical slice with typed data and explicit dependencies.
  3. Represent loading, empty, success, and failure behavior where the feature can encounter them.
  4. Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
  5. Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
  6. Refactor only after behavior is protected by repeatable evidence.

Protect the frame

Keep build methods predictable, move side effects to explicit owners, and measure before introducing caches, isolates, or architectural layers.

Guided Flutter lab

Build a focused repository-isolated Firebase feature slice

This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.

lib/data/firestore_course_repository.dart
class FirestoreCourseRepository implements CourseRepository {
  FirestoreCourseRepository(this.db);
  final FirebaseFirestore db;

  @override
  Stream<List<Course>> watchCourses() {
    return db.collection('courses')
        .where('published', isEqualTo: true)
        .orderBy('title')
        .snapshots()
        .map((snapshot) => [
          for (final doc in snapshot.docs) Course.fromJson(doc.id, doc.data()),
        ]);
  }
}

Production practice

Contract

Define the repository-isolated Firebase feature inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.

Verification

Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.

Operations

Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.

Common failure mode

Hiding an insecure rule behind a disabled button does not authorize data; a modified client can call Firebase directly.

Independent workshop

Extend the guided lab into a review-ready repository-isolated Firebase feature feature that fits the running course portfolio app.

Your finished workshop must include:

  • Project environments
  • Authentication
  • Firestore
  • Storage
  • Security rules
  • Automated verification and a short design note

Definition of done

Demonstrate the happy path, an empty or unavailable state, and at least one failure path. Add an automated check and a short note explaining one design decision.

Recap & quick check

Key takeaways

  • Security rule: Treat client checks as UX only and prove rules with emulator tests
  • Document model: Model for bounded query patterns instead of relational joins
  • Environment: Make accidental cross-environment writes structurally difficult

Quick check

1. Which rule best applies to Security rule?

2. Which rule best applies to Document model?

3. Which rule best applies to Environment?

Next: Notifications, Background Work & Deep Links