diff --git a/firestore-semantic-search/CHANGELOG.md b/firestore-semantic-search/CHANGELOG.md index d877176f..c71f75c8 100644 --- a/firestore-semantic-search/CHANGELOG.md +++ b/firestore-semantic-search/CHANGELOG.md @@ -1,3 +1,7 @@ +## Version 0.1.11 + +docs: correct the query function App Check and Firebase Auth claims (the Callable Function does not enforce either by default) + ## Version 0.1.10 chore: bump runtime to Node.js 22 diff --git a/firestore-semantic-search/POSTINSTALL.md b/firestore-semantic-search/POSTINSTALL.md index 4517ab10..0f5bd294 100644 --- a/firestore-semantic-search/POSTINSTALL.md +++ b/firestore-semantic-search/POSTINSTALL.md @@ -64,7 +64,7 @@ The response contains** only document IDs**, not the full data, since the extens ## Example client integration -Now that you have an index with data in it, you can run text similarity search queries directly from your client application. Note that this Callable Function is protected by App Check and requires that you are signed in with a [Firebase Auth](https://firebase.google.com/docs/auth) call the Function from your client application. +Now that you have an index with data in it, you can run text similarity search queries directly from your client application. Note that this Callable Function does not enforce [App Check](https://firebase.google.com/docs/app-check) or [Firebase Auth](https://firebase.google.com/docs/auth) by default, so any client with your Firebase project configuration is able to call it. The function only ever returns document IDs (never document contents), so your Firestore Security Rules continue to govern access to the underlying documents. If you need to restrict access to the query function itself, enable App Check enforcement and/or add your own authentication checks. ```js import firebase from "firebase"; diff --git a/firestore-semantic-search/PREINSTALL.md b/firestore-semantic-search/PREINSTALL.md index 0903f87e..c6e6010a 100644 --- a/firestore-semantic-search/PREINSTALL.md +++ b/firestore-semantic-search/PREINSTALL.md @@ -8,7 +8,7 @@ Once installed, the extension does the following: 2. Provides a secure API endpoint to query similar documents (given an input document) that can be used by client applications 3. (Optional) Backfills existing data from target collection(s) -The query API endpoint is deployed as a Firebase Callable Function, and requires that you are signed in with a Firebase Auth user to successfully call the Function from your client application. +The query API endpoint is deployed as a Firebase Callable Function. Note that this function does not enforce Firebase Authentication or [App Check](https://firebase.google.com/docs/app-check) by default, so any client with your Firebase project configuration is able to call it. The function only ever returns document IDs (never document contents), so your Firestore Security Rules continue to govern access to the underlying documents. If you want to restrict who can call the query function itself, enable App Check enforcement and/or add your own authentication checks after installing the extension. ### Embeddings models diff --git a/firestore-semantic-search/README.md b/firestore-semantic-search/README.md index be26ebaf..4d638ce9 100644 --- a/firestore-semantic-search/README.md +++ b/firestore-semantic-search/README.md @@ -16,7 +16,7 @@ Once installed, the extension does the following: 2. Provides a secure API endpoint to query similar documents (given an input document) that can be used by client applications 3. (Optional) Backfills existing data from target collection(s) -The query API endpoint is deployed as a Firebase Callable Function, and requires that you are signed in with a Firebase Auth user to successfully call the Function from your client application. +The query API endpoint is deployed as a Firebase Callable Function. Note that this function does not enforce Firebase Authentication or [App Check](https://firebase.google.com/docs/app-check) by default, so any client with your Firebase project configuration is able to call it. The function only ever returns document IDs (never document contents), so your Firestore Security Rules continue to govern access to the underlying documents. If you want to restrict who can call the query function itself, enable App Check enforcement and/or add your own authentication checks after installing the extension. ### Embeddings models diff --git a/firestore-semantic-search/extension.yaml b/firestore-semantic-search/extension.yaml index 9dd7c4b1..82578e70 100644 --- a/firestore-semantic-search/extension.yaml +++ b/firestore-semantic-search/extension.yaml @@ -1,5 +1,5 @@ name: firestore-semantic-search -version: 0.1.10 +version: 0.1.11 specVersion: v1beta icon: icon.png