
Igangværende
Slået op
Milestone 1 – Technical Governance & Structural Audit (Cap 25h) 1) GitHub Governance Review • Org structure • Repo setup • Role & permission validation • Branch protection rules • Workflow strategy (PR, code review flow) • Secret exposure validation ⸻ 2) Firebase & Infra Review • Auth configuration • Firestore rules • Storage permissions • IAM roles • API key exposure • Environment structure • Cloud messaging config ⸻ 3) Admin Panel Structural & Security Review • Role-based access control validation (Admin vs Staff) • Server-side authorization enforcement (not only UI-level) • Data write/update/delete permission checks • Sensitive operations validation (approve/decline, manage users, etc.) • Validation of input sanitization • Logging & traceability checks • Risk of privilege escalation ⸻ 4) High-Level Code & Architecture Review • Modularization quality • Separation of concerns • Dependency management • Hardcoded logic • Scalability red flags • Early technical debt indicators
Projekt-ID: 40273944
8 forslag
Projekt på afstand
Aktiv 5 dage siden
Fastsæt dit budget og din tidsramme
Bliv betalt for dit arbejde
Oprids dit forslag
Det er gratis at skrive sig op og byde på jobs
8 freelancere byder i gennemsnit $23 USD/time på dette job

Good to see this project, I will conduct a full technical governance and structural audit across your GitHub organization, Firebase infrastructure, admin panel, and codebase. The review will cover org structure, repo permissions, branch protection, secret exposure, Firestore rules, IAM roles, admin panel authorization enforcement, and code architecture quality - with a structured report and prioritized action items for each area. One critical area I will focus on is validating that server-side authorization in your admin panel truly enforces the same restrictions shown in the UI. In many Firebase-based setups, Firestore security rules and Cloud Function checks do not fully mirror frontend role distinctions between Admin and Staff. This creates privilege escalation paths that only surface under targeted testing, not normal usage. I will map each sensitive operation to its backend enforcement to identify any gaps. Questions: 1) How many repositories and Firebase projects are in scope for this milestone? 2) Is the admin panel built with a specific framework (React, Angular, Vue) and does it use Firebase Auth for session management? 3) Are there any existing security policies or prior audit reports I should review as a baseline? Looking forward to discussing further. Best regards, Faizan
$19 USD på 40 dage
3,8
3,8

Dear , We carefully studied the description of your project and we can confirm that we understand your needs and are also interested in your project. Our team has the necessary resources to start your project as soon as possible and complete it in a very short time. We are 25 years in this business and our technical specialists have strong experience in Security, Cloud Security, GitHub, Risk Assessment, Data Protection and other technologies relevant to your project. Please, review our profile https://www.freelancer.com/u/tangramua where you can find detailed information about our company, our portfolio, and the client's recent reviews. Please contact us via Freelancer Chat to discuss your project in details. Best regards, Sales department Tangram Canada Inc.
$25 USD på 5 dage
3,2
3,2

❤️❤️❤️ Hello, there❤️❤️❤️ I can run a full technical governance and security audit across all milestones. I will review GitHub rules, workflows, permissions, and secret exposure risks. I will audit Firebase auth, rules, IAM, APIs, and environment security. I will validate admin panel access control and prevent privilege escalation. My rate is $22 per hour with a 25-hour cap, delivered within 7 days.
$22 USD på 25 dage
0,0
0,0

Hi, I’ve led similar reviews across GitHub orgs, Firebase stacks, and admin panels in production SaaS environments over the past 8+ years. For GitHub I’ll assess org permissions, branch protection, PR flow, workflow enforcement, and secret exposure risk (including Actions secrets and token scopes). On Firebase/infra I’ll review Auth providers, Firestore/Storage rules, IAM bindings, API key exposure patterns, and Cloud Messaging configuration to identify privilege drift or misconfigured rules. For the admin panel I’ll validate true server-side RBAC enforcement, check write/delete paths, sensitive operations (approve/manage users), input sanitization, and privilege escalation vectors. I’ll also evaluate logging depth and traceability. Architecture review will focus on separation of concerns, modular boundaries, dependency hygiene, hardcoded logic, and early scalability debt signals. Cap 25h is realistic for a high-signal assessment with a prioritized risk report. Do you want findings delivered as a risk matrix (severity/impact/mitigation) or narrative technical report? Thank you
$20 USD på 40 dage
0,0
0,0

Hello, I can perform a comprehensive technical governance and structural audit covering GitHub, Firebase infrastructure, the admin panel, and the overall code architecture. I will review repository governance, roles and permissions, branch protection, PR workflows, and check for potential secret exposure. On the infrastructure side, I will analyze Firebase authentication, Firestore rules, storage permissions, IAM roles, API key safety, and environment configuration. I will also validate the admin panel’s role-based access control, server-side authorization, data permissions, input validation, and privilege escalation risks. Finally, I will conduct a high-level code and architecture review to identify security gaps, scalability risks, and early technical debt, and provide a clear report with actionable recommendations.
$25 USD på 30 dage
0,0
0,0

Chicago, Brazil
Betalingsmetode verificeret
Medlem siden mar. 3, 2026
$10-30 USD
£20-250 GBP
₹37500-75000 INR
$10-50 USD
$10-30 USD
$60 USD
$500-1000 USD
₹600-1500 INR
$250-750 USD
$250-750 USD
$10-50 USD
$250-750 USD
$250-750 CAD
₹12500-37500 INR
$10-30 USD
₹12500-37500 INR
$10-60 USD
min £36 GBP / time
$250-750 USD
$250-750 CAD