Security

Bashyal Team takes a least-privilege approach to the website and to application backends that share the same Firebase project. This page describes that approach in public language. It does not publish internal rule files, administrator identities, private keys, or a vulnerability walkthrough.

Transport

The production site is intended to run on HTTPS at aadarshabashyal.com.np. Hosting headers are configured for MIME sniffing protection, a referrer policy, a permissions policy, and a content security policy that still allows the Firebase client SDK to function when it is enabled.

Authentication

Public visitors do not need an account. Administrator access uses email and password. Passwords are never stored in website source code and are never written in plaintext. Password reset, when Firebase is connected, is handled by Firebase’s own email flow.

Authorization

A signed-in user is not an administrator by default. The website checks a role on the user profile, and Firestore security rules check that same role independently in production. Hiding an /admin URL is not the access-control layer. Client-side flags such as a value in localStorage are not trusted on the Firebase rules layer.

Published application documents can be read by anyone. Unpublished applications, deletion requests, contact messages, audit logs, and private store identifiers (including AdMob unit IDs) are not publicly readable.

Account deletion requests

Anyone may submit a deletion request without signing in, which is required so that a user who uninstalled an app can still start the process. The form does not delete Firebase Authentication users from the browser. Requests enter a review queue. Ownership is verified before a request is marked completed. An email address typed into a public form is not treated as proof of ownership.

Because this project targets Firebase Spark (no Cloud Functions), automatic server-side deletion of Authentication users is not performed by an unattended public API. An authorized administrator completes the deletion against the application data model and records the outcome. That limitation is intentional and documented rather than hidden behind a button that pretends to wipe accounts instantly.

Data minimization

Forms collect only the fields needed to respond or to identify an application. Government ID is not requested. Audit logs record events, administrator IDs, timestamps, and non-secret metadata — not passwords or tokens.

Updates

Dependencies and rules should be reviewed when the site is deployed and when a new application is added. If you believe you have found a security issue, email contact.bashyalteam@gmail.com rather than opening a public issue with exploit details.

Related: Privacy policy · Account deletion