A good way to secure your app is to restrict any front-end api-key to be accessible only on the domains you choose.
Firebase automatically configures the api-key for us, but this key is currently unrestricted. To restrict the domains that can use it, we must go to Google Cloud API console. The URL to do so will be something like: