docs: reconcile current staging App Check status - #680
Merged
Conversation
✅ Deploy Preview for luminous-fox-7c393f ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
Author
|
Self-review of exact head 39d0172 found no findings. The four documentation corrections preserve the historical #671 boundary, state the current #676 Auth/Firestore enforcement accurately, keep callable Functions and outside-provider isolation unavailable, and make no provider, billing, production, user, or data change. |
This was referenced Aug 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #676.
Outcome
Reconciles four remaining current-state passages with the completed staging App Check enforcement evidence. The prior completion PR correctly recorded the provider/browser result, but a README safety paragraph, the runbook inventory, the Auth-slice diagram text, and the officer Auth review still carried pre-#676 wording.
The correction keeps the historical #671 boundary explicit while making the current state unambiguous: App Check is enforced for staging Authentication and Firestore, but Functions, callable enforcement, outside-provider isolation, and a usable member backend remain unavailable.
This is documentation-only. It performs no Firebase, Hosting, provider, billing, IAM, Functions, production, DNS, Netlify, GitHub Pages, user, or data mutation.
Verification
Officer impact: Backup officers now see one consistent distinction between the historical #671 Auth checkpoint and the current #676 App Check-enforced staging state. They still do not sign in, run commands, configure providers, attach billing, or handle credentials.
Officer documentation:
docs/officers/PUBLISH_AND_CHECK.md; matching engineering state corrected inREADME.md,OPERATIONS_RUNBOOK.md, andSYSTEM_DESIGN.md.Deployment evidence: Website — unchanged at staging Hosting version
8556fc51210bdc66. Firebase — the post-merge readback still shows Authentication and FirestoreENFORCED, one staging web app, zero disposable users/records after cleanup, billing disabled, and no deployed Functions. Provider/production — no provider or production mutation is part of this pull request;runmprc.comremains unchanged.