Prepare NoteFormer for a new computer
A Google login identifies a person and lab. It cannot install Windows software, open microphones or choose a disk folder without the operator’s permission.
1. Connect the lab’s Google service
- Use a lab-owned project in the Firebase console. Register a Web app and copy its public Firebase configuration. Never put a service-account private key or Google password into the website.
- Enable Authentication → Google. Add
noteformer.comandwww.noteformer.comto Authentication’s authorized domains. Addlocalhostonly for local development. - Create Firestore in the lab’s chosen region, deploy the repository’s Firestore rules and indexes, then provision
bootstrap/authorizedLabOwnerswith anemailsarray containing the approved lab owner’s lowercase Google email. Knowing a lab ID does not grant membership. - Configure Firebase App Check with a reCAPTCHA Enterprise key for these domains. Verify real requests before enabling enforcement. A key being present is not proof that enforcement is enabled.
- Set the public Firebase values in NoteFormer’s hosted environment. The website reads them from its public configuration endpoint, so every new computer uses the same project. No local configuration file is needed on recording computers.
Hosted setting names
VITE_FIREBASE_API_KEY VITE_FIREBASE_AUTH_DOMAIN VITE_FIREBASE_PROJECT_ID VITE_FIREBASE_STORAGE_BUCKET VITE_FIREBASE_MESSAGING_SENDER_ID VITE_FIREBASE_APP_ID VITE_FIREBASE_APP_CHECK_SITE_KEY
2. Confirm lab isolation before opening access
Test the authorized owner, an invited recorder, a viewer and an unrelated Google account. The unrelated account must not read or write any lab data. Metadata synchronization must reject a recording root belonging to another lab.
Hosting access is separate from Firebase authentication. An owner-only hosted site cannot be reached by arbitrary Google lab accounts. Publish to the intended audience only after the account and database checks pass.
3. Choose browser recording or a verified Windows package
Browser recording needs no installer. The operator signs in, selects the root folder, grants microphone access and validates the connected channels. All channels start disabled. Keep the tab open and the computer awake.
The optional Windows Station provides the current native model and local OCR. Public download links use the newest release. The owner deployment panel lists every checksum-verified catalog package so an older Station can receive a required bridge update and Standard and NVIDIA computers receive compatible packages.
Approve a production release only after code signing or administrator approval, package-integrity verification and the appropriate update or clean-machine test. Do not disable Windows security to make it run. Configure the selected package’s HTTPS URL, version and expected SHA-256, then explicitly enable either approved distribution or beta testing. Neither setting authorizes Windows installation. The operator must run the package explicitly; Google sign-in never installs software.
Application-update setting names
NOTEFORMER_STATION_CODE_UPDATE_URL NOTEFORMER_STATION_CODE_UPDATE_VERSION NOTEFORMER_STATION_CODE_UPDATE_SHA256 NOTEFORMER_STATION_CODE_UPDATE_BASES NOTEFORMER_STATION_CODE_UPDATE_BYTES NOTEFORMER_STATION_RELEASE_APPROVED=true
For an explicitly offered test build, keep release approval false and set NOTEFORMER_STATION_BETA_DOWNLOAD_ENABLED=true. Every updated ZIP must have a matching version, byte count and checksum.
NOTEFORMER_STATION_RELEASES_JSON retains immutable deployment choices for owners while the newest valid package remains the refresh default and the public download target. NOTEFORMER_STATION_DOWNLOAD_FOLDER_URL remains a browsing fallback.
4. Verify acquisition before research use
- Check the proposal status immediately above the spectrograms. P marks a model proposal; solid boxes pass the model threshold and dashed boxes are review candidates. Neither is a manually confirmed label. Model errors or an unavailable helper are reported here rather than hidden behind an empty event lane.
- Use the actual microphones, not redirected Remote Desktop audio. Confirm channel routing and the delivered sample rate.
- Record, stop and play back the saved WAV. Check its duration, timestamps and
bird-id / mic / YYYYMMDDlocation. - Test internet loss and reconnection: audio must continue and queued metadata must synchronize without duplication or cross-lab mixing.
- Run the required 24-hour acquisition soak. A short input check is not an endurance certificate.
- Validate the live model for the chosen channel load. Otherwise use recording-only mode; these files remain marked for later analysis.
Video-file recording, offline page reload recovery, and unattended restart recovery are not certified in this release. Google Drive backup is optional metadata-only functionality and requests separate consent when used.