diff --git a/README.md b/README.md index 850daa0..56c0d10 100644 --- a/README.md +++ b/README.md @@ -788,6 +788,7 @@ and no fallback provider. Recommendations require a human moderator action. - [Architecture](docs/architecture.md) - [Trust and safety](docs/trust-safety.md) - [Operations runbook](docs/operations.md) +- [Google provider inventory for Dev, Test, and Prod](docs/google-provider-inventory.md) - [Performance measurement](docs/performance.md) - [Implementation verification and known limits](docs/verification.md) - [Verified dependency baseline](docs/dependency-baseline.md) diff --git a/docs/google-provider-inventory.md b/docs/google-provider-inventory.md new file mode 100644 index 0000000..168543e --- /dev/null +++ b/docs/google-provider-inventory.md @@ -0,0 +1,135 @@ +# Google provider inventory + +Verified read-only on 2026-08-28 against the authenticated Google Cloud and +Firebase consoles, the local Dev `.env`, the installed Test and Prod `.env` +files over SSH, and the repository environment validators. No secret values +were read into this document. This is an inventory, not a source of secrets. + +## Environment contract + +Who Need Help has exactly three deployment environments: + +| Environment | Public origin | Android build/package | Google project | +| --- | --- | --- | --- | +| Dev | `https://whoneedhelp.imalto.site` | `development` / `org.whoneedhelp.mobile.development` | `Who Need Help Development` / `who-need-help-development` / `299749044449` | +| Test | `https://test.whoneedhelp.com` | `staging` / `org.whoneedhelp.mobile.staging` | `Who Need Help Staging` / `who-need-help-staging` / `340523338913` | +| Prod | `https://whoneedhelp.com` | `release` / `org.whoneedhelp.mobile` | `Who Need Help Production` / `who-need-help-production` / `184178014037` | + +`staging` is only the existing Google display name and Android build/package +label for **Test**. It is not a fourth environment. Reuse the three project IDs +above; do not create another Google Cloud or Firebase project for these +environments. + +The repository enforces this mapping in +[`scripts/validate-android-environment.sh`](../scripts/validate-android-environment.sh). + +The installed runtime identifiers match the table: Dev points to +`who-need-help-development`, Prod points to `who-need-help-production`, and +Test has its own Web OAuth client while all Firebase/FCM values remain empty. + +## Current registrations + +### Dev + +- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-development) + - Web: `Who Need Help Development Web` + (`299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com`) + - origin: `https://whoneedhelp.imalto.site` + - callback: `https://whoneedhelp.imalto.site/auth/google/callback` + - Android: `Who Need Help Development Android` + (`299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com`) +- [Firebase project](https://console.firebase.google.com/project/who-need-help-development/settings/general): + Spark, shown as `No-cost ($0/month)` at verification time. +- Firebase Android app: `Who Need Help Development`, package + `org.whoneedhelp.mobile.development`, app ID + `1:299749044449:android:284bfd48e072ca29e307a0`. +- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-development): + - `wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com` + is enabled for FCM HTTP v1; + - the Firebase Admin SDK service account exists and has no user-managed key. + +### Test + +- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-staging) + - Web: `Who Need Help Staging Web` + (`340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com`) + - origin: `https://test.whoneedhelp.com` + - callback: `https://test.whoneedhelp.com/auth/google/callback` + - Android: `Who Need Help Staging Android` + (`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`), + package `org.whoneedhelp.mobile.staging`. +- Firebase is not connected to `who-need-help-staging`; the current Firebase + project list contains only Dev and Prod. +- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging): + no service accounts were present, so Test has no FCM sender registration. +- The Google Cloud project has a billing account linked. The console showed + `$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation + is not a pricing guarantee. +- The Web OAuth client also contains the old callback + `https://staging.whoneedhelp.com/auth/google/callback`. It is not part of the + three-environment contract. Do not rely on or remove it until the owner + explicitly chooses the cleanup. + +### Prod + +- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-production) + - Web: `Who Need Help Production Web` + (`184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com`) + - origin: `https://whoneedhelp.com` + - callback: `https://whoneedhelp.com/auth/google/callback` + - Android clients: `Who Need Help Android Upload`, + `Who Need Help Android Play RSA 1`, `Who Need Help Android Play RSA 2`, and + `Who Need Help Android Play ML-DSA`. +- [Firebase project](https://console.firebase.google.com/project/who-need-help-production/settings/general): + Spark, shown as `No-cost ($0/month)` at verification time. +- Firebase Android app: `Who Need Help Production`, package + `org.whoneedhelp.mobile`, app ID + `1:184178014037:android:18b3996444c3bebce361dc`. +- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-production): + - `who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com` is + enabled for FCM HTTP v1; + - the Firebase Admin SDK service account exists and has no user-managed key. +- [Google Play app](https://play.google.com/console/u/0/developers/5283023225403815420/app/4972430103169452589/app-dashboard) + is the production Android application. +- Four Android OAuth clients currently exist while the local Play identity + inventory records three Play signing identities. The purpose of the fourth + client has not been verified; do not delete or merge any of them based only + on their similar names. + +## Configuration ownership + +Each checkout keeps one ignored `.env`. Provider secrets must remain there or +in the ignored provider files consumed by the import scripts; never copy them +into this document or commit them. + +| Capability | Runtime configuration | +| --- | --- | +| Web Google sign-in | `GOOGLE_OAUTH_CLIENT_ID`, `GOOGLE_OAUTH_CLIENT_SECRET` | +| Android Google sign-in | `GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS` | +| Public Firebase Android config | four `WNH_FIREBASE_*` values | +| Server-side FCM | `FCM_PROJECT_ID` and exactly one service-account source | +| Android App Links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` | + +Relevant validated importers: + +- [`scripts/import-firebase-android-config.sh`](../scripts/import-firebase-android-config.sh) +- [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh) +- [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh) + +The Dev and Prod FCM sender accounts being present proves registration only; +delivery still requires the matching environment configuration and an actual +device smoke test. Test currently has OAuth but no Firebase/FCM registration. + +The ignored `tmp/environment-access/*.env` files are historical snapshots, not +live configuration. In particular, its old Dev snapshot still references the +historical `who-need-help-dev-firebase` setup and must not be used to recreate or +overwrite the current Dev configuration. + +## Do not recreate + +- Do not create a fourth environment called Staging. +- Do not create another Firebase project for Dev or Prod. +- Do not place OAuth client secrets, Firebase API keys, service-account JSON, + private keys, or key IDs in documentation. +- Do not delete an OAuth client, callback, Firebase app, fingerprint, or service + account until its active environment and signing identity have been verified.