Client and admin login
Sign in with Firebase, then let TuPagina verify access.
Clients and admins use Firebase Authentication for identity. Cloudflare and D1 remain responsible for Role routing, dashboard authorization, audit events, and TuPagina business state.
Email login
Passwordless-ready foundation remains; this MVP uses Firebase email/password and Google sign-in.
Firebase AuthSession model nextRole routing via D1
Provider login
No custom OAuthNo passwords in D1Preview preserved
Audience
Can browse pages, directories, sign up, and checkout.
Client
Can reach the protected dashboard after Firebase sign-in and D1 mapping.
Admin
Admin access must come from Cloudflare/D1 authorization, not frontend-only controls.