Auth authorized domains not configured or too permissive

Authorized Domains are not enabled or are not meticulously specified in the Firebase console. This feature restricts OAuth redirect flows to trusted domains, preventing attackers from using the Firebase project with malicious redirect URIs.