Personal Catalogue: React & Firebase — Chapter 9, Exercise 3 ===================================================================== TASK Explain, for each of CORS, PM2, and a reverse proxy, precisely why this course never needed to build it — tying each answer back to a specific earlier architectural decision rather than a general "Firebase handles it" claim. SOLUTION CORS: Cross-Origin Resource Sharing is a browser-enforced policy that governs whether a plain fetch()/XHR request from one origin is allowed to read a response from a different origin. This app never makes that kind of request — the Firestore client SDK, initialized back in Chapter 1, talks to Firestore's own backend using its own long-lived connection and protocol, not a same-origin-restricted browser fetch call the way the MongoDB sibling's own React app talks to its Express API. With no cross-origin fetch of that kind ever happening, there was never a CORS policy of this app's own to configure in the first place. PM2: PM2 exists to keep a long-running Node process alive, restart it if it crashes, and survive a server reboot. This course made the real decision, back in Chapter 3, to have no backend server process of its own at all — React talks directly to Firestore, a fully managed service Firebase itself keeps running. There is no process belonging to this project for PM2 to supervise. Reverse proxy: An nginx reverse proxy in the MongoDB sibling's own setup exists to put a real public domain and TLS certificate in front of a raw Node process listening on a plain port, and to avoid exposing that Node process directly to the internet. This course has no Node process to protect or terminate TLS in front of — Firebase Hosting, configured in this very chapter, already serves the built frontend directly over HTTPS from Firebase's own infrastructure, with no internal service address that would ever need a proxy sitting in front of it. In all three cases, the common thread is the same: each of these tools solves a problem created specifically by running a backend server process of one's own. Chapter 3's decision to never run one didn't just simplify the app's own runtime architecture — it also eliminated every production concern that only exists because a server process exists. WHY THIS WORKS AS AN ANSWER ---------------------------- It explains the real purpose each tool actually serves before explaining why this app doesn't have the underlying problem that tool solves, ties every answer back to the specific Chapter 3 decision rather than a vague "Firebase is managed," and identifies the shared root cause connecting all three rather than treating them as three unrelated coincidences.