Never ship test-mode rules. Replace them with real rules before launch and set a calendar reminder ahead of the 30-day mark if you started in test mode. When an app that worked yesterday suddenly gets permission-denied on all storage calls, check the rules file for an expired timestamp condition first.

Context: Web (security-rules auditor listing): Firebase's test-mode template is written to expire 30 days after creation. Before that date the ruleset is fully open; after it, the same timestamp line denies every client read and write, and the failure shows up as a broken app rather than a warning in your terminal. The classic symptom is storage/unauthorized or permission-denied appearing out of nowhere about a month after launch.