Skip to content

CI-001D2: record staging Auth deployment evidence - #673

Merged
daliu merged 1 commit into
mainfrom
codex/issue-671-staging-auth-evidence
Aug 26, 2026
Merged

CI-001D2: record staging Auth deployment evidence#673
daliu merged 1 commit into
mainfrom
codex/issue-671-staging-auth-evidence

Conversation

@daliu

@daliu daliu commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Outcome

Records the completed CI-001D2 provider phase after the reviewed Auth source reached exact main. The docs now distinguish source, live Auth configuration, disposable sign-in proof, cleanup, and the remaining incomplete backend.

Officer impact: Backup officers can verify the staging Auth boundary from redacted issue/PR evidence without signing in, running commands, handling credentials, or treating narrow Auth proof as a usable member backend.

Officer documentation: OFFICER_START_HERE.md, docs/officers/README.md, docs/officers/SYSTEM_MAPS.md, and docs/officers/PUBLISH_AND_CHECK.md.

Deployment evidence: Exact source 42542303d043f87a8f1a04be2f0b4f2a88e0318c passed exact-main CI run 33011780449; Firebase CLI 15.24.0 deployed Auth only to run-mprc-staging using runmprc@gmail.com. Readback proved instrumentless Identity Platform with billing disabled, password-required email/password, improved email privacy, only the two staging domains, and no anonymous/phone/native federated/OIDC/SAML providers. Disposable API and browser sign-in/sign-out passed without email/SMS. Final Auth users and Firestore root collections were zero. Hosting stayed 3ffadcf2ac8cc760; Functions/App Check remained unavailable; runmprc.com remained Netlify.

Checks

  • Protected workflow/security command: 113/113 passed
  • CI-001D2 focused tests: 5/5 passed within that command
  • Markdown fences: 10/10 files balanced
  • git diff --check: passed
  • Added-text credential-shape scan: 0 matches
  • Live post-cleanup provider readback: passed
  • Staging browser login, account guard, sign-out, and cleanup: passed

Residual risk

The current Firebase CLI Auth deployment path initializes Firebase Authentication with the instrumentless Identity Platform subtype and is subject to its no-billing daily limit. This PR attaches no billing instrument and enables no enterprise provider. Trusted Functions, App Check, roles/profiles/private-data flows, outside-provider sandboxes, reusable keyless deploy authority, rollback proof, and production remain unavailable.

Closes #671

@netlify

netlify Bot commented Aug 26, 2026

Copy link
Copy Markdown

Deploy Preview for luminous-fox-7c393f ready!

Name Link
🔨 Latest commit 966ba10
🔍 Latest deploy log https://app.netlify.com/projects/luminous-fox-7c393f/deploys/6a8f5586857b650007ab29b2
😎 Deploy Preview https://deploy-preview-673--luminous-fox-7c393f.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@daliu

daliu commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Self-review completed against exact base 42542303d043f87a8f1a04be2f0b4f2a88e0318c and head 966ba101caf9ed3c186891a1e09219a6041f2f54.

Findings: none.

Review notes:

  • Scope is exactly ten engineering/officer Markdown files; no executable source, Firebase configuration, workflow, dependency, lockfile, secret, or provider state changes in this PR.
  • Every live claim matches the redacted CI-001D2 — Initialize and prove staging email/password Auth #671 evidence: exact account/project/scope, provider/privacy/domain readback, instrumentless billing-disabled subtype, disposable API/browser proof, zero-user/zero-record cleanup, unchanged Hosting, unavailable Functions/App Check, and untouched production.
  • The officer procedure names purpose, approver, prerequisites, steps, expected result, stop conditions, success proof, undo, escalation, Mermaid map, and text alternative. It requires no terminal, sign-in, credential, console edit, or private-data handling.
  • The wording does not overstate staging: Auth is available only for issue-scoped disposable engineering checks; roles, profiles, Functions, App Check, outside providers, reusable authority, and production remain unavailable.
  • Local protected workflow/security command passed 113/113; Markdown fences balanced 10/10; git diff --check passed; added-text credential-shape scan found 0 matches.

Residual risk: the one-time Auth path is not reusable protected deployment authority, and the instrumentless Identity Platform subtype carries its current no-billing usage ceiling. No billing instrument or enterprise provider was added.

@daliu
daliu merged commit 38c3f4b into main Aug 26, 2026
9 checks passed
@daliu
daliu deleted the codex/issue-671-staging-auth-evidence branch August 26, 2026 21:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI-001D2 — Initialize and prove staging email/password Auth

1 participant