Skip to content

docs: reconcile current staging App Check status - #680

Merged
daliu merged 1 commit into
mainfrom
codex/issue-676-app-check-doc-consistency
Aug 27, 2026
Merged

docs: reconcile current staging App Check status#680
daliu merged 1 commit into
mainfrom
codex/issue-676-app-check-doc-consistency

Conversation

@daliu

@daliu daliu commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #676.

Outcome

Reconciles four remaining current-state passages with the completed staging App Check enforcement evidence. The prior completion PR correctly recorded the provider/browser result, but a README safety paragraph, the runbook inventory, the Auth-slice diagram text, and the officer Auth review still carried pre-#676 wording.

The correction keeps the historical #671 boundary explicit while making the current state unambiguous: App Check is enforced for staging Authentication and Firestore, but Functions, callable enforcement, outside-provider isolation, and a usable member backend remain unavailable.

This is documentation-only. It performs no Firebase, Hosting, provider, billing, IAM, Functions, production, DNS, Netlify, GitHub Pages, user, or data mutation.

Verification

  • Node 20 focused staging contract suite: 34/34 passed.
  • Documentation diff check and Markdown fence balance passed.
  • Targeted stale-state scan confirms the current inventory and rollout paragraphs no longer call App Check unavailable.
  • Manual review found no authorization or App Check overclaim, secret/PII disclosure, provider mutation, production fallback, or officer procedure regression.

Officer impact: Backup officers now see one consistent distinction between the historical #671 Auth checkpoint and the current #676 App Check-enforced staging state. They still do not sign in, run commands, configure providers, attach billing, or handle credentials.

Officer documentation: docs/officers/PUBLISH_AND_CHECK.md; matching engineering state corrected in README.md, OPERATIONS_RUNBOOK.md, and SYSTEM_DESIGN.md.

Deployment evidence: Website — unchanged at staging Hosting version 8556fc51210bdc66. Firebase — the post-merge readback still shows Authentication and Firestore ENFORCED, one staging web app, zero disposable users/records after cleanup, billing disabled, and no deployed Functions. Provider/production — no provider or production mutation is part of this pull request; runmprc.com remains unchanged.

@netlify

netlify Bot commented Aug 27, 2026

Copy link
Copy Markdown

Deploy Preview for luminous-fox-7c393f ready!

Name Link
🔨 Latest commit 39d0172
🔍 Latest deploy log https://app.netlify.com/projects/luminous-fox-7c393f/deploys/6a8fb0e0925f7e0008675083
😎 Deploy Preview https://deploy-preview-680--luminous-fox-7c393f.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@daliu

daliu commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

Self-review of exact head 39d0172 found no findings. The four documentation corrections preserve the historical #671 boundary, state the current #676 Auth/Firestore enforcement accurately, keep callable Functions and outside-provider isolation unavailable, and make no provider, billing, production, user, or data change.

@daliu
daliu merged commit 1f27b06 into main Aug 27, 2026
9 checks passed
@daliu
daliu deleted the codex/issue-676-app-check-doc-consistency branch August 27, 2026 03:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant