Personal Catalogue: React & Firebase — Chapter 1, Exercise 3 ===================================================================== TASK Given that barcode scanning is deferred and nothing else in the shared spec needs a real, secret-holding API call, explain why this variant might not need any Cloud Functions at all for its first release — and name the one real thing that would change that answer once barcode scanning is eventually picked up. SOLUTION Cloud Functions exist, in this project family, for exactly one real reason: to hold a secret (a third-party API key, most obviously) that must never reach the browser, and to run whatever logic actually needs that secret on Firebase's own servers instead of the client's. The site's own Food Tracker (React + Firebase) course needed one from its very first backend chapter because its shared spec calls for real, immediate third-party lookups — Open Food Facts for barcode scans, TheMealDB for recipes — both requiring a server-side call the browser shouldn't make directly. This project's own shared spec, for its first release, has no such requirement. Every feature in scope for v1 — adding an item manually, tagging books, searching the collection, marking things used — is pure read/write against this app's own Firestore data, with no external service and no secret involved anywhere. Barcode scanning, the one feature that would need a real lookup against an external service (an ISBN or UPC database), is explicitly deferred past this course's own first release. Without it, there's genuinely nothing here that needs a trusted, secret-holding server-side function — the whole app can run on the client SDK plus Security Rules alone, more purely "BaaS" than its own Food Tracker sibling ever managed to be. The one real thing that changes this answer is exactly that deferred feature landing: the moment barcode scanning is picked up, a real lookup service (an ISBN API for books, a UPC database for CDs/DVDs/ Blu-rays) enters the picture, and whatever API key that service needs becomes a real secret that has no safe home in browser-shipped code. At that point, a Cloud Function proxying the lookup — the exact role it plays in the Food Tracker sibling today — becomes necessary here too. WHY THIS WORKS AS AN ANSWER ---------------------------- It identifies the actual, narrow reason Cloud Functions exist in this project family (holding a real secret) rather than treating them as a generic "backend logic" catch-all, correctly traces why this project's own deferred-barcode-scanning scope avoids that need for now, and names the precise, concrete trigger — a real external lookup with a real API key — that would reopen the question later.