What you'll learn
Add authentication, Firestore, Storage, Functions, security rules, emulators, and cost-aware repositories without coupling the UI. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.
By the end of this lesson, you'll be able to:
- Apply Project environments in a production-shaped Flutter feature
- Apply Authentication in a production-shaped Flutter feature
- Apply Firestore in a production-shaped Flutter feature
- Apply Storage in a production-shaped Flutter feature
Core mental model
Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.
| Concept | What it means | Decision rule |
|---|---|---|
| Security rule | Server-enforced authorization for Firebase data access | Treat client checks as UX only and prove rules with emulator tests |
| Document model | Firestore data is organized around document reads and indexed queries | Model for bounded query patterns instead of relational joins |
| Environment | Development, staging, and production use isolated backend resources | Make accidental cross-environment writes structurally difficult |
Professional workflow
Work in small vertical slices and keep behavior observable from the first iteration.
- Define the repository-isolated Firebase feature boundary: user goal, inputs, visible states, ownership, and expected failures.
- Build the smallest working vertical slice with typed data and explicit dependencies.
- Represent loading, empty, success, and failure behavior where the feature can encounter them.
- Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
- Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
- Refactor only after behavior is protected by repeatable evidence.
Protect the frame
Guided Flutter lab
Build a focused repository-isolated Firebase feature slice
This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.
class FirestoreCourseRepository implements CourseRepository {
FirestoreCourseRepository(this.db);
final FirebaseFirestore db;
@override
Stream<List<Course>> watchCourses() {
return db.collection('courses')
.where('published', isEqualTo: true)
.orderBy('title')
.snapshots()
.map((snapshot) => [
for (final doc in snapshot.docs) Course.fromJson(doc.id, doc.data()),
]);
}
}Production practice
Contract
Define the repository-isolated Firebase feature inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.
Verification
Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.
Operations
Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.
Common failure mode
Independent workshop
Extend the guided lab into a review-ready repository-isolated Firebase feature feature that fits the running course portfolio app.
Your finished workshop must include:
- Project environments
- Authentication
- Firestore
- Storage
- Security rules
- Automated verification and a short design note
Definition of done
Recap & quick check
Key takeaways
- Security rule: Treat client checks as UX only and prove rules with emulator tests
- Document model: Model for bounded query patterns instead of relational joins
- Environment: Make accidental cross-environment writes structurally difficult
Quick check
1. Which rule best applies to Security rule?
2. Which rule best applies to Document model?
3. Which rule best applies to Environment?
Next: Notifications, Background Work & Deep Links