What to build
This slice implements ADR 0002 in #122. A guest's first save signs them in anonymously, and their custom yields and saved calculations live in Firestore under the same rules as any account. When the guest later signs in with Google or an email link, the anonymous user is linked to that sign-in, so nothing is copied. People who only use the calculator never get an anonymous user.
Anonymous users can write without a verified account, so the project needs abuse limits:
- Per user: the rules cap the size and number of each user's records.
- Project-wide: App Check; Firebase Auth's limit on new anonymous sign-ups from one IP address, kept low; and the free plan's hard quotas, which stop writes instead of billing.
A bot exhausting the free quota is an accepted risk (ADR 0002).
Two edge cases need handling:
- The first save happens offline. Anonymous sign-in needs the network, so the save is kept in the browser and written to Firestore once sign-in succeeds.
- The credential already belongs to an account. Firebase cannot link it. While still signed in as the guest, the app reads the guest's custom yields and saved calculations, then signs in to the existing account and writes them there.
Acceptance criteria
Blocked by
What to build
This slice implements ADR 0002 in #122. A guest's first save signs them in anonymously, and their custom yields and saved calculations live in Firestore under the same rules as any account. When the guest later signs in with Google or an email link, the anonymous user is linked to that sign-in, so nothing is copied. People who only use the calculator never get an anonymous user.
Anonymous users can write without a verified account, so the project needs abuse limits:
A bot exhausting the free quota is an accepted risk (ADR 0002).
Two edge cases need handling:
Acceptance criteria
Blocked by