# Firebase Auth + Firestore + Hosting
URL: https://wwadd.dev/stacks/firebase-auth-firestore-hosting
Last verified: 2026-09-30

A managed backend workflow for client apps with document data, authentication, and live updates; security rules and query costs are part of the design.

## When to use it
- The data fits documents and known query patterns
- A client app needs authentication and live document subscriptions
- The team accepts managed services and plans read, write, and storage budgets

## How the pieces fit
Firebase Authentication identifies users; Firestore stores documents and provides subscriptions; Hosting serves the frontend. Design queries and indexes together with security rules. Rules must authorize every client operation; privileged server SDKs require their own authorization. Test denied reads and writes in emulators, limit listeners and pagination, and add server functions for trusted operations. Hosting a static frontend does not provide server rendering automatically.

## The tech and its role
- Firebase Authentication: User identity and sign-in
- Cloud Firestore: Document storage, queries, listeners, and security rules
- Firebase Hosting: Frontend delivery

## Real-world examples
- FriendlyChat web codelab: The official teaching project demonstrates a Firebase-backed web chat. Learning example; inspect its current code and configuration before reuse. (source: https://github.com/firebase/codelab-friendlychat-web)
- Firebase JavaScript quickstarts: Official web samples illustrate individual Firebase services. These are separate examples, not a single production architecture. (source: https://github.com/firebase/quickstart-js)

## Skip if
Skip if relational joins and reporting drive the data model, strict self-hosting is required, or a document-query cost model is unsuitable.

## Testing and shipping
- [Test the behavior users depend on](https://wwadd.dev/moves/testing-shipping/test-user-behavior)
- [Check keyboard access and automated accessibility](https://wwadd.dev/moves/testing-shipping/keyboard-accessibility-check)
- [Investigate flaky browser tests](https://wwadd.dev/moves/testing-shipping/diagnose-flaky-tests)
- [Verify the production build before release](https://wwadd.dev/moves/testing-shipping/verify-built-release)
- [Keep secrets out of browser bundles](https://wwadd.dev/moves/testing-shipping/keep-secrets-server-side)
- [Make CI validate the same release inputs](https://wwadd.dev/moves/testing-shipping/ci-release-gates)
- [Capture errors with useful context](https://wwadd.dev/moves/testing-shipping/error-reporting-context)
- [Prepare rollback before publishing](https://wwadd.dev/moves/testing-shipping/plan-release-rollback)

