Skip to content

Security: 47096/puff

Security

SECURITY.md

Security

Firebase (optional cloud sync)

The web apiKey in app.js is public client config (normal for Firebase web apps). Real protection is server-side rules.

Before production:

  1. In Firebase Console → Firestore → Rules, lock reads/writes to request.auth.uid == userId (and only the fields you need).
  2. Restrict Google sign-in to your OAuth client and authorized domains.
  3. Turn off any open collection writes; prefer custom claims / App Check if you scale.

Puff’s sw.js does not cache Firestore or identity traffic.

Reporting

Open a GitHub issue for security concerns, or contact the maintainer via datafying.

App notes

  • API keys and stats stay on-device unless the user enables cloud sync (GDPR consent).
  • Microphone is requested only for the blow gesture and is not uploaded by this app.

There aren't any published security advisories