landing.html:641 and :648 initialise Firebase Auth and call signInWithPopup. The production deployment is served from sparky-na2c.onrender.com, which is not in the Firebase project's authorized domains list, so the popup is rejected and sign-in cannot succeed on the URL users actually visit.
This is a configuration change in the Firebase console rather than a code change, which is why there is no PR attached to this issue.
Should be
- Add
sparky-na2c.onrender.com to Firebase Authentication -> Settings -> Authorized domains.
- Then decide which deployment is canonical (see the deployment consolidation issue) and remove the others so this cannot drift again.
- Surface the underlying
auth/unauthorized-domain error to the user instead of failing silently.
Found in the 2026-08-16 audit (30-agent sweep, 481 findings). Every line reference was verified against main at the time of filing.
landing.html:641and:648initialise Firebase Auth and callsignInWithPopup. The production deployment is served fromsparky-na2c.onrender.com, which is not in the Firebase project's authorized domains list, so the popup is rejected and sign-in cannot succeed on the URL users actually visit.This is a configuration change in the Firebase console rather than a code change, which is why there is no PR attached to this issue.
Should be
sparky-na2c.onrender.comto Firebase Authentication -> Settings -> Authorized domains.auth/unauthorized-domainerror to the user instead of failing silently.Found in the 2026-08-16 audit (30-agent sweep, 481 findings). Every line reference was verified against
mainat the time of filing.