Has anyone here dealt with Firebase's authentication / authorization model in production?
[0] - https://www.firebase.com/docs/security/quickstart.html
"By default, your app has rules which grants every request full read and write permissions to your database"
I've been using Firebase a while, and so I didn't fully think through the experience for users unfamiliar with firebase.
By necessity, this repo use of firebase is somewhat opinionated. I intend to add comments and docs to explain the architecture and how to set it up to work with different kinds of persistent data (ie - shared and public data as well as user related docs). And, of course, to set up secure separate docs for different users.