who_need_help/docs/google-provider-inventory.md
SimpleTest 319cdb970b
Some checks are pending
Quality / full-local-gates (push) Waiting to run
Document test Firebase and OAuth configuration
2026-08-28 19:45:24 +03:00

8.5 KiB

Google provider inventory

Verified read-only on 2026-08-28 against the authenticated Google Cloud and Firebase consoles, the local Dev .env, the installed Test and Prod .env files over SSH, and the repository environment validators. No secret values were read into this document. This is an inventory, not a source of secrets.

Environment contract

Who Need Help has exactly three deployment environments:

Environment Public origin Android build/package Google project
Dev https://whoneedhelp.imalto.site development / org.whoneedhelp.mobile.development Who Need Help Development / who-need-help-development / 299749044449
Test https://test.whoneedhelp.com staging / org.whoneedhelp.mobile.staging Who Need Help Staging / who-need-help-staging / 340523338913
Prod https://whoneedhelp.com release / org.whoneedhelp.mobile Who Need Help Production / who-need-help-production / 184178014037

staging is only the existing Google display name and Android build/package label for Test. It is not a fourth environment. Reuse the three project IDs above; do not create another Google Cloud or Firebase project for these environments.

The active promotion workflow is:

  1. Develop and verify on Dev (whoneedhelp.imalto.site).
  2. Promote the exact candidate to Test (test.whoneedhelp.com) and repeat the application, provider, and browser checks there.
  3. Promote that exact verified candidate to Prod only after explicit operator approval.

The previous Build Week restriction on changing Test has ended. Test is the normal pre-production verification environment; Prod is never updated as an implicit consequence of a Dev or Test deployment.

The repository enforces this mapping in scripts/validate-android-environment.sh.

The installed runtime identifiers match the table: Dev points to who-need-help-development, Prod points to who-need-help-production, and Test points to who-need-help-staging. The Test .env contains the validated Firebase Android and server-side FCM settings, but the currently running Test container must be replaced by a verified Test release before it can consume those values.

Current registrations

Dev

  • Google OAuth clients
    • Web: Who Need Help Development Web (299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com)
    • origin: https://whoneedhelp.imalto.site
    • callback: https://whoneedhelp.imalto.site/auth/google/callback
    • Android: Who Need Help Development Android (299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com)
  • Firebase project: Spark, shown as No-cost ($0/month) at verification time.
  • Firebase Android app: Who Need Help Development, package org.whoneedhelp.mobile.development, app ID 1:299749044449:android:284bfd48e072ca29e307a0.
  • IAM service accounts:
    • wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com is enabled for FCM HTTP v1;
    • the Firebase Admin SDK service account exists and has no user-managed key.

Test

  • Google OAuth clients
    • Web: Who Need Help Staging Web (340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com)
    • origin: https://test.whoneedhelp.com
    • callback: https://test.whoneedhelp.com/auth/google/callback
    • Android: Who Need Help Staging Android (340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com), package org.whoneedhelp.mobile.staging.
  • Firebase project: Firebase is enabled on the existing Test Google Cloud project. No separate Google Cloud project was created.
  • Firebase Android app: Who Need Help Test, package org.whoneedhelp.mobile.staging, app ID 1:340523338913:android:f6f7f7780c1b4a6258f4e0.
  • IAM service accounts: wnh-test-fcm-sender@who-need-help-staging.iam.gserviceaccount.com has the Firebase Cloud Messaging API Admin role. The FCM API is enabled and the account has exactly one active user-managed key. The key material is stored only in ignored, mode-0600 provider/runtime configuration and is not documented here.
  • The Google Cloud project has a billing account linked. The console showed $0.00 estimated charges for 2026-08-01 through 2026-08-28; this observation is not a pricing guarantee.
  • The only supported Test callback is https://test.whoneedhelp.com/auth/google/callback.
  • The retired https://staging.whoneedhelp.com/auth/google/callback entry was removed from the Test Web OAuth client on 2026-08-28. Do not recreate or use it.

Prod

  • Google OAuth clients
    • Web: Who Need Help Production Web (184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com)
    • origin: https://whoneedhelp.com
    • callback: https://whoneedhelp.com/auth/google/callback
    • Android clients: Who Need Help Android Upload, Who Need Help Android Play RSA 1, Who Need Help Android Play RSA 2, and Who Need Help Android Play ML-DSA.
  • Firebase project: Spark, shown as No-cost ($0/month) at verification time.
  • Firebase Android app: Who Need Help Production, package org.whoneedhelp.mobile, app ID 1:184178014037:android:18b3996444c3bebce361dc.
  • IAM service accounts:
    • who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com is enabled for FCM HTTP v1;
    • the Firebase Admin SDK service account exists and has no user-managed key.
  • Google Play app is the production Android application.
  • Four Android OAuth clients currently exist while the local Play identity inventory records three Play signing identities. The purpose of the fourth client has not been verified; do not delete or merge any of them based only on their similar names.

Configuration ownership

Each checkout keeps one ignored .env. Provider secrets must remain there or in the ignored provider files consumed by the import scripts; never copy them into this document or commit them.

Capability Runtime configuration
Web Google sign-in GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET
Android Google sign-in GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS
Public Firebase Android config four WNH_FIREBASE_* values
Server-side FCM FCM_PROJECT_ID and exactly one service-account source
Android App Links ANDROID_APP_LINKS_PACKAGE_NAME, ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS

Relevant validated importers:

An FCM sender account and runtime configuration prove registration only; delivery still requires the matching deployed environment and an actual device smoke test. Test is registered and configured, but its running container and Android build have not yet completed that delivery smoke test.

The ignored tmp/environment-access/*.env files are historical snapshots, not live configuration. In particular, its old Dev snapshot still references the historical who-need-help-dev-firebase setup and must not be used to recreate or overwrite the current Dev configuration.

Do not recreate

  • Do not create a fourth environment called Staging.
  • Do not create another Firebase project for Dev or Prod.
  • Do not place OAuth client secrets, Firebase API keys, service-account JSON, private keys, or key IDs in documentation.
  • Do not delete an OAuth client, callback, Firebase app, fingerprint, or service account until its active environment and signing identity have been verified.