161 lines
8.5 KiB
Markdown
161 lines
8.5 KiB
Markdown
# Google provider inventory
|
|
|
|
Verified read-only on 2026-08-28 against the authenticated Google Cloud and
|
|
Firebase consoles, the local Dev `.env`, the installed Test and Prod `.env`
|
|
files over SSH, and the repository environment validators. No secret values
|
|
were read into this document. This is an inventory, not a source of secrets.
|
|
|
|
## Environment contract
|
|
|
|
Who Need Help has exactly three deployment environments:
|
|
|
|
| Environment | Public origin | Android build/package | Google project |
|
|
| --- | --- | --- | --- |
|
|
| Dev | `https://whoneedhelp.imalto.site` | `development` / `org.whoneedhelp.mobile.development` | `Who Need Help Development` / `who-need-help-development` / `299749044449` |
|
|
| Test | `https://test.whoneedhelp.com` | `staging` / `org.whoneedhelp.mobile.staging` | `Who Need Help Staging` / `who-need-help-staging` / `340523338913` |
|
|
| Prod | `https://whoneedhelp.com` | `release` / `org.whoneedhelp.mobile` | `Who Need Help Production` / `who-need-help-production` / `184178014037` |
|
|
|
|
`staging` is only the existing Google display name and Android build/package
|
|
label for **Test**. It is not a fourth environment. Reuse the three project IDs
|
|
above; do not create another Google Cloud or Firebase project for these
|
|
environments.
|
|
|
|
The active promotion workflow is:
|
|
|
|
1. Develop and verify on Dev (`whoneedhelp.imalto.site`).
|
|
2. Promote the exact candidate to Test (`test.whoneedhelp.com`) and repeat the
|
|
application, provider, and browser checks there.
|
|
3. Promote that exact verified candidate to Prod only after explicit operator
|
|
approval.
|
|
|
|
The previous Build Week restriction on changing Test has ended. Test is the
|
|
normal pre-production verification environment; Prod is never updated as an
|
|
implicit consequence of a Dev or Test deployment.
|
|
|
|
The repository enforces this mapping in
|
|
[`scripts/validate-android-environment.sh`](../scripts/validate-android-environment.sh).
|
|
|
|
The installed runtime identifiers match the table: Dev points to
|
|
`who-need-help-development`, Prod points to `who-need-help-production`, and
|
|
Test points to `who-need-help-staging`. The Test `.env` contains the validated
|
|
Firebase Android and server-side FCM settings, but the currently running Test
|
|
container must be replaced by a verified Test release before it can consume
|
|
those values.
|
|
|
|
## Current registrations
|
|
|
|
### Dev
|
|
|
|
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-development)
|
|
- Web: `Who Need Help Development Web`
|
|
(`299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com`)
|
|
- origin: `https://whoneedhelp.imalto.site`
|
|
- callback: `https://whoneedhelp.imalto.site/auth/google/callback`
|
|
- Android: `Who Need Help Development Android`
|
|
(`299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com`)
|
|
- [Firebase project](https://console.firebase.google.com/project/who-need-help-development/settings/general):
|
|
Spark, shown as `No-cost ($0/month)` at verification time.
|
|
- Firebase Android app: `Who Need Help Development`, package
|
|
`org.whoneedhelp.mobile.development`, app ID
|
|
`1:299749044449:android:284bfd48e072ca29e307a0`.
|
|
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-development):
|
|
- `wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com`
|
|
is enabled for FCM HTTP v1;
|
|
- the Firebase Admin SDK service account exists and has no user-managed key.
|
|
|
|
### Test
|
|
|
|
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-staging)
|
|
- Web: `Who Need Help Staging Web`
|
|
(`340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com`)
|
|
- origin: `https://test.whoneedhelp.com`
|
|
- callback: `https://test.whoneedhelp.com/auth/google/callback`
|
|
- Android: `Who Need Help Staging Android`
|
|
(`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`),
|
|
package `org.whoneedhelp.mobile.staging`.
|
|
- [Firebase project](https://console.firebase.google.com/project/who-need-help-staging/settings/general):
|
|
Firebase is enabled on the existing Test Google Cloud project. No separate
|
|
Google Cloud project was created.
|
|
- Firebase Android app: `Who Need Help Test`, package
|
|
`org.whoneedhelp.mobile.staging`, app ID
|
|
`1:340523338913:android:f6f7f7780c1b4a6258f4e0`.
|
|
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging):
|
|
`wnh-test-fcm-sender@who-need-help-staging.iam.gserviceaccount.com` has the
|
|
`Firebase Cloud Messaging API Admin` role. The FCM API is enabled and the
|
|
account has exactly one active user-managed key. The key material is stored
|
|
only in ignored, mode-`0600` provider/runtime configuration and is not
|
|
documented here.
|
|
- The Google Cloud project has a billing account linked. The console showed
|
|
`$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation
|
|
is not a pricing guarantee.
|
|
- The only supported Test callback is
|
|
`https://test.whoneedhelp.com/auth/google/callback`.
|
|
- The retired `https://staging.whoneedhelp.com/auth/google/callback` entry was
|
|
removed from the Test Web OAuth client on 2026-08-28. Do not recreate or use
|
|
it.
|
|
|
|
### Prod
|
|
|
|
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-production)
|
|
- Web: `Who Need Help Production Web`
|
|
(`184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com`)
|
|
- origin: `https://whoneedhelp.com`
|
|
- callback: `https://whoneedhelp.com/auth/google/callback`
|
|
- Android clients: `Who Need Help Android Upload`,
|
|
`Who Need Help Android Play RSA 1`, `Who Need Help Android Play RSA 2`, and
|
|
`Who Need Help Android Play ML-DSA`.
|
|
- [Firebase project](https://console.firebase.google.com/project/who-need-help-production/settings/general):
|
|
Spark, shown as `No-cost ($0/month)` at verification time.
|
|
- Firebase Android app: `Who Need Help Production`, package
|
|
`org.whoneedhelp.mobile`, app ID
|
|
`1:184178014037:android:18b3996444c3bebce361dc`.
|
|
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-production):
|
|
- `who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com` is
|
|
enabled for FCM HTTP v1;
|
|
- the Firebase Admin SDK service account exists and has no user-managed key.
|
|
- [Google Play app](https://play.google.com/console/u/0/developers/5283023225403815420/app/4972430103169452589/app-dashboard)
|
|
is the production Android application.
|
|
- Four Android OAuth clients currently exist while the local Play identity
|
|
inventory records three Play signing identities. The purpose of the fourth
|
|
client has not been verified; do not delete or merge any of them based only
|
|
on their similar names.
|
|
|
|
## Configuration ownership
|
|
|
|
Each checkout keeps one ignored `.env`. Provider secrets must remain there or
|
|
in the ignored provider files consumed by the import scripts; never copy them
|
|
into this document or commit them.
|
|
|
|
| Capability | Runtime configuration |
|
|
| --- | --- |
|
|
| Web Google sign-in | `GOOGLE_OAUTH_CLIENT_ID`, `GOOGLE_OAUTH_CLIENT_SECRET` |
|
|
| Android Google sign-in | `GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS` |
|
|
| Public Firebase Android config | four `WNH_FIREBASE_*` values |
|
|
| Server-side FCM | `FCM_PROJECT_ID` and exactly one service-account source |
|
|
| Android App Links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` |
|
|
|
|
Relevant validated importers:
|
|
|
|
- [`scripts/import-firebase-android-config.sh`](../scripts/import-firebase-android-config.sh)
|
|
- [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh)
|
|
- [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh)
|
|
|
|
An FCM sender account and runtime configuration prove registration only;
|
|
delivery still requires the matching deployed environment and an actual
|
|
device smoke test. Test is registered and configured, but its running
|
|
container and Android build have not yet completed that delivery smoke test.
|
|
|
|
The ignored `tmp/environment-access/*.env` files are historical snapshots, not
|
|
live configuration. In particular, its old Dev snapshot still references the
|
|
historical `who-need-help-dev-firebase` setup and must not be used to recreate or
|
|
overwrite the current Dev configuration.
|
|
|
|
## Do not recreate
|
|
|
|
- Do not create a fourth environment called Staging.
|
|
- Do not create another Firebase project for Dev or Prod.
|
|
- Do not place OAuth client secrets, Firebase API keys, service-account JSON,
|
|
private keys, or key IDs in documentation.
|
|
- Do not delete an OAuth client, callback, Firebase app, fingerprint, or service
|
|
account until its active environment and signing identity have been verified.
|