|
| 1 | +# Security |
| 2 | + |
| 3 | +What Hoverboard protects for you, and what you set in your own Firebase project and GitHub repository. |
| 4 | + |
| 5 | +## What Hoverboard does |
| 6 | + |
| 7 | +- **Firestore rules.** Visitors can only read your content. You change it in the Firebase console or with `./hb firestore-*`. Signed-in visitors can write only their own bookmarks, notification settings and feedback. The subscribe and partner forms can only add documents, with checked fields and sizes, and nobody can read them from the site. Export them with [`./hb firestore-csv`](01-configure-app.md#subscribers-and-partner-leads). |
| 8 | +- **Storage rules.** The site can't read or write your Storage bucket. |
| 9 | +- **Content.** Links in your config and content can only be `https:`, `http:`, `mailto:` or a path on your site. The site drops other links, such as `javascript:` ones, even when they come straight from the Firebase console. Markdown is sanitized before it is shown, and the build sanitizes the hero illustration. |
| 10 | +- **Headers.** `firebase.json` sends `Strict-Transport-Security`, `Referrer-Policy`, `Permissions-Policy` and other headers on every page, and every page has a [Content Security Policy](01-configure-app.md#content-security-policy). |
| 11 | +- **Sign-out.** Signing out deletes the copy of the visitor's data that the site keeps in the browser for offline use. |
| 12 | +- **Logs.** The functions don't log emails, push tokens or user IDs. |
| 13 | +- **Deploys.** GitHub Actions deploy without a service account key, with only the roles a deploy needs. See [Deploying to Firebase with Github Actions](04-deploy.md#deploying-to-firebase-with-github-actions). |
| 14 | + |
| 15 | +The functions run as the project's default compute service account, which has the Editor role. Only code you deploy runs as it. |
| 16 | + |
| 17 | +## What you set |
| 18 | + |
| 19 | +Do these once when you set up a site, and check them again before the event. |
| 20 | + |
| 21 | +1. **Run `./hb doctor`.** It checks most of the settings below. |
| 22 | +1. **API keys.** Restrict the Firebase web app's browser key to your site's domains and to the APIs the site uses. Use a separate key for Google Maps, restricted to your domain and the Maps JavaScript API. `./hb doctor` checks both keys. See [Deploying to Firebase with Github Actions](04-deploy.md#deploying-to-firebase-with-github-actions). |
| 23 | +1. **Authorized domains.** In the Firebase console under **Authentication** > **Settings** > **Authorized domains**, keep only your site's domains. Remove `localhost`: local development uses the emulators, not your project. Preview deploys add their own domain. Remove the domains of previews that no longer exist. |
| 24 | +1. **Email enumeration protection.** Turn it on under **Authentication** > **Settings** > **User actions**, so sign-in doesn't tell anyone which emails have accounts. New projects have it on (verify). |
| 25 | +1. **Budgets.** Set a spend cap and a budget alert, so abuse can't run up a large bill. See [Spend cap and budget](02-firebase.md#spend-cap-and-budget). |
| 26 | +1. **Service account keys.** You don't need any. `./hb doctor` warns about keys and about the old `github-action-*` accounts. Delete them, and the GitHub secrets that held them. |
| 27 | +1. **Repository access.** Anyone who can push a branch can deploy to your live site and read your Firestore data. Only give write access to people you would trust with the Firebase console. |
| 28 | +1. **Repository settings.** On GitHub, under **Settings**: |
| 29 | + - **Advanced Security**: turn on Dependabot alerts, secret scanning, push protection and private vulnerability reporting. |
| 30 | + - **Actions** > **General**: set the workflow permissions to read, and turn off "Allow GitHub Actions to create and approve pull requests" unless you use release-please. |
| 31 | + - **Rules**: add a ruleset for `main` that requires a pull request and the `build`, `test` and `lint` checks, and blocks force pushes. |
| 32 | + |
| 33 | +## What `./hb doctor` checks |
| 34 | + |
| 35 | +- Your Node.js version, Firebase login, project and site config. |
| 36 | +- No service account key files in the repository root. |
| 37 | +- The Blaze plan, and that every function is deployed as 2nd gen. |
| 38 | +- The Realtime Database is off. |
| 39 | +- The GitHub deploy setup and its roles, as `./hb setup-github` sets them. |
| 40 | +- Service account keys, and old `github-action-*` accounts. |
| 41 | +- The browser API key and the Maps key: which sites and APIs they allow. |
| 42 | + |
| 43 | +Each problem comes with what to change. Some checks need an API turned on in your project, and say so. |
| 44 | + |
| 45 | +## Reporting a vulnerability |
| 46 | + |
| 47 | +To report a vulnerability in Hoverboard, see the [security policy](../../.github/SECURITY.md). |
0 commit comments