diff --git a/docs/google-provider-inventory.md b/docs/google-provider-inventory.md index bf22a7a..32643cc 100644 --- a/docs/google-provider-inventory.md +++ b/docs/google-provider-inventory.md @@ -37,7 +37,10 @@ The repository enforces this mapping in The installed runtime identifiers match the table: Dev points to `who-need-help-development`, Prod points to `who-need-help-production`, and -Test has its own Web OAuth client while all Firebase/FCM values remain empty. +Test points to `who-need-help-staging`. The Test `.env` contains the validated +Firebase Android and server-side FCM settings, but the currently running Test +container must be replaced by a verified Test release before it can consume +those values. ## Current registrations @@ -70,18 +73,26 @@ Test has its own Web OAuth client while all Firebase/FCM values remain empty. - Android: `Who Need Help Staging Android` (`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`), package `org.whoneedhelp.mobile.staging`. -- Firebase is not connected to `who-need-help-staging`; the current Firebase - project list contains only Dev and Prod. +- [Firebase project](https://console.firebase.google.com/project/who-need-help-staging/settings/general): + Firebase is enabled on the existing Test Google Cloud project. No separate + Google Cloud project was created. +- Firebase Android app: `Who Need Help Test`, package + `org.whoneedhelp.mobile.staging`, app ID + `1:340523338913:android:f6f7f7780c1b4a6258f4e0`. - [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging): - no service accounts were present, so Test has no FCM sender registration. + `wnh-test-fcm-sender@who-need-help-staging.iam.gserviceaccount.com` has the + `Firebase Cloud Messaging API Admin` role. The FCM API is enabled and the + account has exactly one active user-managed key. The key material is stored + only in ignored, mode-`0600` provider/runtime configuration and is not + documented here. - The Google Cloud project has a billing account linked. The console showed `$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation is not a pricing guarantee. - The only supported Test callback is `https://test.whoneedhelp.com/auth/google/callback`. -- The 2026-08-28 read-only check also found one callback for a retired public - hostname. It is not part of the environment contract and remains pending - external provider cleanup. Do not recreate or use it. +- The retired `https://staging.whoneedhelp.com/auth/google/callback` entry was + removed from the Test Web OAuth client on 2026-08-28. Do not recreate or use + it. ### Prod @@ -129,9 +140,10 @@ Relevant validated importers: - [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh) - [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh) -The Dev and Prod FCM sender accounts being present proves registration only; -delivery still requires the matching environment configuration and an actual -device smoke test. Test currently has OAuth but no Firebase/FCM registration. +An FCM sender account and runtime configuration prove registration only; +delivery still requires the matching deployed environment and an actual +device smoke test. Test is registered and configured, but its running +container and Android build have not yet completed that delivery smoke test. The ignored `tmp/environment-access/*.env` files are historical snapshots, not live configuration. In particular, its old Dev snapshot still references the