Skip to content

Security: close Firestore privilege escalation and tenant reassignment - #24

Merged
mekado11 merged 2 commits into
mainfrom
fix/firestore-authority-isolation
Sep 23, 2026
Merged

mekado11 merged 2 commits into
mainfrom
fix/firestore-authority-isolation

Conversation

@mekado11

Copy link
Copy Markdown
Owner

Scope

Focused repair for the Firestore privilege-escalation and cross-tenant access paths identified in the supplied production rules. Based on current main; independent of exercise-workflow PR #23.

  • Replace browser-editable profile super-admin authority with the boolean Firebase Auth custom claim is_super_admin.
  • Remove public-email admin bootstrap and silent tenant backfilling from the client.
  • Allowlist safe profile creation/updates; prevent self-assigned tenant IDs, roles, approval, entitlements and forged identity.
  • Preserve bounded same-company user administration.
  • Preserve approved same-company CRUD across 36 tenant-scoped aliases while preventing ownership reassignment/removal.
  • Restrict company reads and metadata writes; close personal-record cross-tenant/ownership transfers.
  • Keep the V2 namespace inaccessible to all browser clients, including genuinely claimed legacy super admins.
  • Remove unsafe company reconciliation/recreation and access-code lookup paths.

Important behavior and deployment changes

This is an unmerged review PR, not authorization to deploy Firestore rules or modify production users.

  • Existing global administrators need independently approved Auth claims. The old profile flag and VITE_SUPER_ADMIN_EMAIL are not sufficient.
  • Existing company assignments and roles must be audited before rollout. Freezing a previously forged value does not make it trustworthy.
  • New-company creation remains supported through UID-bound ownership and a one-time assignment.
  • Access-code self-service joining is explicitly paused; trusted operator provisioning is required until a separately reviewed invitation service exists.
  • Missing-company recovery no longer creates or relinks from cached profile data.
  • Frontend and rules rollout must be coordinated. A Vercel build does not deploy Firebase rules.
  • Do not merge-and-deploy blindly. V2 activation, memberships, server credentials and live acceptance remain separate gates.

Verification

  • 29 Firebase emulator tests pass: 10 new rules scenarios, one new actual-app/browser scenario, and 18 existing V2/identity scenarios.
  • Rules tests cover all 36 tenant-scoped aliases, registration/self-escalation, same-company CRUD/admin positives, cross-tenant negatives, company ownership, personal-record transfers, batched attacks and nested V2 evidence/audit denial.
  • Actual React application tested with Firebase Auth/Firestore emulators: ordinary profile creation despite matching the former admin email variable, denied privilege writes, correct effective identity despite forged profile fields, and explicit paused-join UI.
  • Desktop and mobile screenshots inspected; CI uploads profile-security-browser.
  • 68 domain tests, 34 existing security/client tests, V2 compilation and changed-client-file lint pass.
  • Production build passes; existing legacy bundle-size warning remains.
  • Emulator compilation now clears stale generated files before tests, avoiding cross-branch test contamination.

Boundaries

No production rules, credentials, custom claims, accounts, memberships or customer data were changed. No production-readiness verdict is claimed; live connector access remains blocked. Existing dependency, storage, granular legacy RBAC, rate-limit and audit/retention work is outside this focused change.

The detailed deployment gate and compatibility matrix are in docs/v2/firestore-security-fix.md.

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hubcys Ready Ready Preview Sep 23, 2026 6:35pm UTC

@mekado11
mekado11 merged commit 14a40cb into main Sep 23, 2026
5 checks passed

This branch was successfully deployed

1 active deployment
Preview — d4b1743a Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant