Skip to content

security: claims crawler #100

@mfreeman451

Description

@mfreeman451

Write a small program that runs in GCP to crawl through user claims and validate that everyone has the correct claims. If someone every compromised a back-end API key they could use it to change their claims in firebase and access other user accounts. We can hope and wish that that never happens, but I'd also like to know if it did ahead of time.

  • Claims crawler runs out of cron in GCP
  • Keeps state using firestore - 3 days worth?
  • Reports to Slack

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions