Document Google provider environments

This commit is contained in:
SimpleTest 2026-08-28 16:22:53 +03:00
parent 72fd99e09a
commit a9b78ec374
2 changed files with 136 additions and 0 deletions

View File

@ -788,6 +788,7 @@ and no fallback provider. Recommendations require a human moderator action.
- [Architecture](docs/architecture.md) - [Architecture](docs/architecture.md)
- [Trust and safety](docs/trust-safety.md) - [Trust and safety](docs/trust-safety.md)
- [Operations runbook](docs/operations.md) - [Operations runbook](docs/operations.md)
- [Google provider inventory for Dev, Test, and Prod](docs/google-provider-inventory.md)
- [Performance measurement](docs/performance.md) - [Performance measurement](docs/performance.md)
- [Implementation verification and known limits](docs/verification.md) - [Implementation verification and known limits](docs/verification.md)
- [Verified dependency baseline](docs/dependency-baseline.md) - [Verified dependency baseline](docs/dependency-baseline.md)

View File

@ -0,0 +1,135 @@
# Google provider inventory
Verified read-only on 2026-08-28 against the authenticated Google Cloud and
Firebase consoles, the local Dev `.env`, the installed Test and Prod `.env`
files over SSH, and the repository environment validators. No secret values
were read into this document. This is an inventory, not a source of secrets.
## Environment contract
Who Need Help has exactly three deployment environments:
| Environment | Public origin | Android build/package | Google project |
| --- | --- | --- | --- |
| Dev | `https://whoneedhelp.imalto.site` | `development` / `org.whoneedhelp.mobile.development` | `Who Need Help Development` / `who-need-help-development` / `299749044449` |
| Test | `https://test.whoneedhelp.com` | `staging` / `org.whoneedhelp.mobile.staging` | `Who Need Help Staging` / `who-need-help-staging` / `340523338913` |
| Prod | `https://whoneedhelp.com` | `release` / `org.whoneedhelp.mobile` | `Who Need Help Production` / `who-need-help-production` / `184178014037` |
`staging` is only the existing Google display name and Android build/package
label for **Test**. It is not a fourth environment. Reuse the three project IDs
above; do not create another Google Cloud or Firebase project for these
environments.
The repository enforces this mapping in
[`scripts/validate-android-environment.sh`](../scripts/validate-android-environment.sh).
The installed runtime identifiers match the table: Dev points to
`who-need-help-development`, Prod points to `who-need-help-production`, and
Test has its own Web OAuth client while all Firebase/FCM values remain empty.
## Current registrations
### Dev
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-development)
- Web: `Who Need Help Development Web`
(`299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com`)
- origin: `https://whoneedhelp.imalto.site`
- callback: `https://whoneedhelp.imalto.site/auth/google/callback`
- Android: `Who Need Help Development Android`
(`299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com`)
- [Firebase project](https://console.firebase.google.com/project/who-need-help-development/settings/general):
Spark, shown as `No-cost ($0/month)` at verification time.
- Firebase Android app: `Who Need Help Development`, package
`org.whoneedhelp.mobile.development`, app ID
`1:299749044449:android:284bfd48e072ca29e307a0`.
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-development):
- `wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com`
is enabled for FCM HTTP v1;
- the Firebase Admin SDK service account exists and has no user-managed key.
### Test
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-staging)
- Web: `Who Need Help Staging Web`
(`340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com`)
- origin: `https://test.whoneedhelp.com`
- callback: `https://test.whoneedhelp.com/auth/google/callback`
- Android: `Who Need Help Staging Android`
(`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`),
package `org.whoneedhelp.mobile.staging`.
- Firebase is not connected to `who-need-help-staging`; the current Firebase
project list contains only Dev and Prod.
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging):
no service accounts were present, so Test has no FCM sender registration.
- The Google Cloud project has a billing account linked. The console showed
`$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation
is not a pricing guarantee.
- The Web OAuth client also contains the old callback
`https://staging.whoneedhelp.com/auth/google/callback`. It is not part of the
three-environment contract. Do not rely on or remove it until the owner
explicitly chooses the cleanup.
### Prod
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-production)
- Web: `Who Need Help Production Web`
(`184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com`)
- origin: `https://whoneedhelp.com`
- callback: `https://whoneedhelp.com/auth/google/callback`
- Android clients: `Who Need Help Android Upload`,
`Who Need Help Android Play RSA 1`, `Who Need Help Android Play RSA 2`, and
`Who Need Help Android Play ML-DSA`.
- [Firebase project](https://console.firebase.google.com/project/who-need-help-production/settings/general):
Spark, shown as `No-cost ($0/month)` at verification time.
- Firebase Android app: `Who Need Help Production`, package
`org.whoneedhelp.mobile`, app ID
`1:184178014037:android:18b3996444c3bebce361dc`.
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-production):
- `who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com` is
enabled for FCM HTTP v1;
- the Firebase Admin SDK service account exists and has no user-managed key.
- [Google Play app](https://play.google.com/console/u/0/developers/5283023225403815420/app/4972430103169452589/app-dashboard)
is the production Android application.
- Four Android OAuth clients currently exist while the local Play identity
inventory records three Play signing identities. The purpose of the fourth
client has not been verified; do not delete or merge any of them based only
on their similar names.
## Configuration ownership
Each checkout keeps one ignored `.env`. Provider secrets must remain there or
in the ignored provider files consumed by the import scripts; never copy them
into this document or commit them.
| Capability | Runtime configuration |
| --- | --- |
| Web Google sign-in | `GOOGLE_OAUTH_CLIENT_ID`, `GOOGLE_OAUTH_CLIENT_SECRET` |
| Android Google sign-in | `GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS` |
| Public Firebase Android config | four `WNH_FIREBASE_*` values |
| Server-side FCM | `FCM_PROJECT_ID` and exactly one service-account source |
| Android App Links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` |
Relevant validated importers:
- [`scripts/import-firebase-android-config.sh`](../scripts/import-firebase-android-config.sh)
- [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh)
- [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh)
The Dev and Prod FCM sender accounts being present proves registration only;
delivery still requires the matching environment configuration and an actual
device smoke test. Test currently has OAuth but no Firebase/FCM registration.
The ignored `tmp/environment-access/*.env` files are historical snapshots, not
live configuration. In particular, its old Dev snapshot still references the
historical `who-need-help-dev-firebase` setup and must not be used to recreate or
overwrite the current Dev configuration.
## Do not recreate
- Do not create a fourth environment called Staging.
- Do not create another Firebase project for Dev or Prod.
- Do not place OAuth client secrets, Firebase API keys, service-account JSON,
private keys, or key IDs in documentation.
- Do not delete an OAuth client, callback, Firebase app, fingerprint, or service
account until its active environment and signing identity have been verified.