Skip to content

Guests save with anonymous sign-in and keep their data on sign-in #125

Description

@paccloud

What to build

This slice implements ADR 0002 in #122. A guest's first save signs them in anonymously, and their custom yields and saved calculations live in Firestore under the same rules as any account. When the guest later signs in with Google or an email link, the anonymous user is linked to that sign-in, so nothing is copied. People who only use the calculator never get an anonymous user.

Anonymous users can write without a verified account, so the project needs abuse limits:

  • Per user: the rules cap the size and number of each user's records.
  • Project-wide: App Check; Firebase Auth's limit on new anonymous sign-ups from one IP address, kept low; and the free plan's hard quotas, which stop writes instead of billing.

A bot exhausting the free quota is an accepted risk (ADR 0002).

Two edge cases need handling:

  • The first save happens offline. Anonymous sign-in needs the network, so the save is kept in the browser and written to Firestore once sign-in succeeds.
  • The credential already belongs to an account. Firebase cannot link it. While still signed in as the guest, the app reads the guest's custom yields and saved calculations, then signs in to the existing account and writes them there.

Acceptance criteria

  • Using only the calculator creates no anonymous user
  • A guest's first save creates an anonymous user and stores the record in Firestore
  • An offline first save is kept in the browser and written to Firestore after anonymous sign-in succeeds, and it survives a reload in between
  • Signing in with a new Google or email credential links it to the anonymous user, and the data stays in place
  • Signing in with a credential that already has an account copies the guest's records into that account, and none are lost or duplicated
  • A guest cannot submit yields; the submit action asks them to sign in
  • App Check is enforced for Firestore, and it works against the emulators in development
  • The rules cap each record's size and each user's record count, and rules tests prove that writes over the caps are refused
  • The anonymous sign-up limit per IP address is set low, and the setting is documented
  • The project stays on the free plan, or the docs say what replaces its hard quotas
  • Unused anonymous users can be cleaned up by a documented step that deletes their Firestore documents along with the Auth user
  • Emulator tests cover the link path, the existing-account copy path and the offline first save

Blocked by

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions