Residual items from the security/code review (#38) that are not fixed, with why:
- Passcode and "requests are never self-granted" are client-side gates. The paired kid device holds its own Firebase credentials, can read the passcode hash, and the "parent mode" rule has no passcode check (rules can't run PBKDF2). Fully fixing this needs a server (e.g. a Cloud Function that verifies the passcode with lockout and performs privileged writes), which the project deliberately doesn't have. Documented in the README and at the top of
firestore.rules.
linkedDeviceUids self-add. Any signed-in device can add itself to another family's linkedDeviceUids if it knows the parent uid. Proposed redesign: per-device linkedDevices/{uid} docs created only through the pairing transaction.
- Whole-list overwrite races in limit/allow-list edits (two editors overwrite each other) - would need field-level array ops or transactions.
- Bedtime calls: Android may not consult call screening for numbers saved in Contacts (needs verifying on a device, possibly
READ_CONTACTS); text muting depends on how each messaging app builds its notifications. Needs real-device testing.
- Notification counts include re-posts of the same notification key (kid and parent counters).
- First-app-after-unlock attribution depends on event ordering between
USER_PRESENT and the first window event.
- Clock rollback on the kid device can extend the temporary unlock / lockout windows; App Check isn't enabled.
- Crashlytics collection is on by default (documented); the opt-in notification digest is stored in plaintext app prefs.
Residual items from the security/code review (#38) that are not fixed, with why:
firestore.rules.linkedDeviceUidsself-add. Any signed-in device can add itself to another family'slinkedDeviceUidsif it knows the parent uid. Proposed redesign: per-devicelinkedDevices/{uid}docs created only through the pairing transaction.READ_CONTACTS); text muting depends on how each messaging app builds its notifications. Needs real-device testing.USER_PRESENTand the first window event.