CI-001D1: provision empty staging Firestore boundary - #670
Merged
Conversation
✅ Deploy Preview for luminous-fox-7c393f ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
Author
|
Independent second-pass review completed against head No blocking findings.
GitHub does not accept approval from the pull request author, so this comment records the user-requested self-review evidence before merge. |
This was referenced Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Provisioned the empty staging Firestore boundary and recorded its verified state. The
(default)database in club-ownedrun-mprc-stagingis Firestore Native, Standard edition,us-west2, delete-protected, PITR disabled, and still contains zero root collections. Only exact Rules and indexes from sourceee16bd16220ab58bd3a2add80dd2f39a1d514dd7were deployed.Closes #669.
Provider change
firestore.googleapis.comonly inrun-mprc-staging.(default)with the reviewed irreversible location and protection settings.firestore:rules,firestore:indexeswith Node 20 and lockfile Firebase CLI 15.24.0.fe3f53302db76df5febf7e9d242d82a6b6bec0c0b574ecc8253f1034f1a77dba.Verification
npm run test:rules— 5 suites, 418/418 tests passed under Node 20.19.5, Java 21.0.12, Firebase CLI 15.24.0.npm run test:firebase-hosting— 7/7 passed.npm run test:staging-authority— 6/6 passed.mail,stripeEvents, andauditEventsdocuments each returned 403.listCollectionIdsreadback returned zero collections and no pagination token./eventsUI rendered the normal empty state with no browser error. The only console warning was the already-documented disabled App Check boundary.3ffadcf2ac8cc760.git diff --checkpassed.Safety review
run-mprc-stagingand the club account explicitly.runmprc@gmail.comaccess token; no token value appears in source, this pull request, or issue evidence.Officer impact: Staging now has a protected empty database boundary. Officers still do not sign in, enter data, run commands, edit Firebase, or use staging as an application backend.
Officer documentation:
OFFICER_START_HERE.md,docs/officers/PUBLISH_AND_CHECK.md, anddocs/officers/README.md; engineering truth is updated inSYSTEM_DESIGN.md,SECURITY.md,IMPLEMENTATION_PLAN.md,OPERATIONS_RUNBOOK.md,README.md, andGITHUB_ISSUES.md.Deployment evidence: Website — staging Hosting version
3ffadcf2ac8cc760unchanged and direct/eventsempty UI verified. Firebase — empty delete-protected staging database, exact active Rules digest, exact index definitions, all indexes READY, three anonymous denials, and zero root collections verified. Provider surfaces — only the staging Firestore API/database/Rules/indexes changed; Auth, Functions, App Check, Storage, outside providers, production Firebase, Netlify, GitHub Pages, DNS, andrunmprc.comwere unchanged.