Skip to content

Residual security and reliability items from the #38 review #39

Description

@jsconu

Residual items from the security/code review (#38) that are not fixed, with why:

  1. Passcode and "requests are never self-granted" are client-side gates. The paired kid device holds its own Firebase credentials, can read the passcode hash, and the "parent mode" rule has no passcode check (rules can't run PBKDF2). Fully fixing this needs a server (e.g. a Cloud Function that verifies the passcode with lockout and performs privileged writes), which the project deliberately doesn't have. Documented in the README and at the top of firestore.rules.
  2. linkedDeviceUids self-add. Any signed-in device can add itself to another family's linkedDeviceUids if it knows the parent uid. Proposed redesign: per-device linkedDevices/{uid} docs created only through the pairing transaction.
  3. Whole-list overwrite races in limit/allow-list edits (two editors overwrite each other) - would need field-level array ops or transactions.
  4. Bedtime calls: Android may not consult call screening for numbers saved in Contacts (needs verifying on a device, possibly READ_CONTACTS); text muting depends on how each messaging app builds its notifications. Needs real-device testing.
  5. Notification counts include re-posts of the same notification key (kid and parent counters).
  6. First-app-after-unlock attribution depends on event ordering between USER_PRESENT and the first window event.
  7. Clock rollback on the kid device can extend the temporary unlock / lockout windows; App Check isn't enabled.
  8. Crashlytics collection is on by default (documented); the opt-in notification digest is stored in plaintext app prefs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions