Skip to content

CI-001D4: record staging App Check monitoring checkpoint - #678

Merged
daliu merged 3 commits into
mainfrom
codex/issue-676-staging-app-check-evidence
Aug 26, 2026
Merged

CI-001D4: record staging App Check monitoring checkpoint#678
daliu merged 3 commits into
mainfrom
codex/issue-676-staging-app-check-evidence

Conversation

@daliu

@daliu daliu commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Outcome

Records the live no-billing staging App Check monitoring checkpoint after the reviewed source guard was merged and deployed. The documentation now distinguishes provider registration and exact Hosting publication from the still-pending browser Auth, enforcement, denial, and replay proofs.

Progresses #676; does not close it.

Officer impact: Officers can verify the current staging checkpoint without signing in, running commands, handling credentials, or mistaking monitoring for protection. Staging remains engineering-only and is not a usable member backend.

Officer documentation: OFFICER_START_HERE.md, docs/officers/README.md, docs/officers/PUBLISH_AND_CHECK.md, and docs/officers/SYSTEM_MAPS.md.

Deployment evidence: Website — exact merged source bce911a7083201cfe2141edaa9660f210287bf57 is live at run-mprc-staging.web.app as Hosting version 8556fc51210bdc66; root and direct Events returned 200, the empty Events UI rendered at 1280×720, and the browser reported no warning/error. Firebase — exactly one score-based key is restricted to the two staging hosts and registered to the one web app with a one-hour token lifetime; Authentication and Firestore read UNENFORCED with replay protection off; users and root collections are zero; billing is disabled; no Functions-related API or Function exists. Provider/production — production Firebase Hosting, runmprc.com, Netlify, DNS, and production data are unchanged.

Evidence

  • Source guard: PR CI-001D4: guard staging App Check Hosting deploy #677, merge bce911a7083201cfe2141edaa9660f210287bf57.
  • Exact-main CI: run 33018136439, all five required jobs passed.
  • Guarded Hosting artifact: 61 files, manifest SHA-256 157e2048aa86d45cec1111e091643870d18ced808ef88d610ec70aae1bbe1ace.
  • Provider readback was repeated before this PR and matched the recorded project/account, key/domain/config, monitoring, zero-count, billing, and Functions state.
  • No key, provider locator, access token, user identifier, or provider response body is included.

Explicitly pending

  • Explicit approval for the live browser submission of one made-up disposable email/password.
  • New browser sign-up/sign-in/sign-out and empty Firestore proof.
  • Atomic Authentication/Firestore ENFORCED readback with replay protection still off.
  • Missing-token denial and continued token-bearing browser success.
  • Cleanup, final zero-count/provider/production readback, and CI-001D4 — Configure and verify no-billing staging App Check #676 completion evidence.
  • Functions remain separately billing-gated and were not enabled or deployed.

Verification

  • Node 20.19.5: 34/34 staging authority, Auth, profile-Function, and Hosting contract tests passed.
  • git diff --check passed.
  • All changed Markdown fences are balanced and the officer index anchor matches its procedure heading.
  • Changed-line sensitive-pattern review found no token, key, user identifier, or credential value.

@netlify

netlify Bot commented Aug 26, 2026

Copy link
Copy Markdown

Deploy Preview for luminous-fox-7c393f ready!

Name Link
🔨 Latest commit 654b36a
🔍 Latest deploy log https://app.netlify.com/projects/luminous-fox-7c393f/deploys/6a8f6ab4da6bdd00087cee9e
😎 Deploy Preview https://deploy-preview-678--luminous-fox-7c393f.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@daliu

daliu commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Self-review completed on f194be2e195fa630f93cf12cdb0342949070f910: no findings.

  • Scope is documentation only and starts from exact deployed/merged base bce911a7083201cfe2141edaa9660f210287bf57.
  • Provider claims match fresh redacted readback: one restricted score key, one matching one-hour web-app config, Auth/Firestore UNENFORCED with replay off, Hosting version 8556fc51210bdc66, billing false, users/root collections zero, and no Functions-related API/Function.
  • Language consistently separates source, CI, provider registration, Hosting publication, monitoring, pending enforcement/denial/replay, Functions, and production.
  • Officer procedure includes purpose, approver, prerequisites, steps, expected result, stop conditions, success proof, undo, escalation, an updated Mermaid map, and a text alternative.
  • No key, provider locator, token, credential, user identifier, private response, or production data appears in the diff.
  • Node 20 guard suite passed 34/34; diff, fence, anchor, and changed-line sensitive-pattern checks passed.

Officer impact: backup officers can verify the monitoring checkpoint without terminal access or provider sign-in and cannot mistake it for enforced protection.

Officer documentation: OFFICER_START_HERE.md, docs/officers/README.md, docs/officers/PUBLISH_AND_CHECK.md, docs/officers/SYSTEM_MAPS.md.

Deployment evidence: exact source/CI/Hosting/provider/public-browser/zero-count/billing/Functions/unchanged-production states are recorded separately; the disposable Auth, enforcement, missing-token, token-bearing replay, cleanup, and completion-evidence states remain explicitly pending.

@daliu daliu closed this Aug 26, 2026
@daliu daliu reopened this Aug 26, 2026
@daliu

daliu commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Final self-review at exact head 654b36ab24f4bcb243c92656e0ed75047a0ac315: no findings. The diff is documentation-only; source/provider/production states remain distinct; officer procedure completeness, Mermaid/text alternative, anchors, Markdown fences, and changed-line credential patterns were rechecked. Node 20.19.5 staging guards pass 34/34. Both delayed CI runs completed all five jobs successfully: https://github.com/Run-MPRC/Run-MPRC.github.io/actions/runs/33020511116 and https://github.com/Run-MPRC/Run-MPRC.github.io/actions/runs/33020513664. Netlify preview, header, and redirect checks are green; Pages-changed is neutral because this is documentation-only.

@daliu
daliu merged commit 14286c9 into main Aug 26, 2026
14 checks passed
@daliu
daliu deleted the codex/issue-676-staging-app-check-evidence branch August 26, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant