Whats the diference between Firestore Rules and Firestorage Rules?










1















I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:






match /users/userID 

/// FUNCTIONS BELLOW ///

function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;





However when I tried to add the same rules under Firestorage, the access is constantly denied.






service firebase.storage 
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();


/// FUNCTIONS BELLOW ///

function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;







Does the Firestorage get method work differently then the Firestore get method?
Any assistance would be much appreciated.










share|improve this question


























    1















    I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:






    match /users/userID 

    /// FUNCTIONS BELLOW ///

    function isAdmin()
    return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;





    However when I tried to add the same rules under Firestorage, the access is constantly denied.






    service firebase.storage 
    match /b/bucket/o
    match /allPaths=**
    allow read: if isAdmin();
    allow write: if isAdmin();


    /// FUNCTIONS BELLOW ///

    function isAdmin()
    return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;







    Does the Firestorage get method work differently then the Firestore get method?
    Any assistance would be much appreciated.










    share|improve this question
























      1












      1








      1


      1






      I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:






      match /users/userID 

      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;





      However when I tried to add the same rules under Firestorage, the access is constantly denied.






      service firebase.storage 
      match /b/bucket/o
      match /allPaths=**
      allow read: if isAdmin();
      allow write: if isAdmin();


      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;







      Does the Firestorage get method work differently then the Firestore get method?
      Any assistance would be much appreciated.










      share|improve this question














      I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:






      match /users/userID 

      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;





      However when I tried to add the same rules under Firestorage, the access is constantly denied.






      service firebase.storage 
      match /b/bucket/o
      match /allPaths=**
      allow read: if isAdmin();
      allow write: if isAdmin();


      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;







      Does the Firestorage get method work differently then the Firestore get method?
      Any assistance would be much appreciated.






      match /users/userID 

      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;





      match /users/userID 

      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;





      service firebase.storage 
      match /b/bucket/o
      match /allPaths=**
      allow read: if isAdmin();
      allow write: if isAdmin();


      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;







      service firebase.storage 
      match /b/bucket/o
      match /allPaths=**
      allow read: if isAdmin();
      allow write: if isAdmin();


      /// FUNCTIONS BELLOW ///

      function isAdmin()
      return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;








      firebase firebase-realtime-database google-cloud-firestore






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 15 '18 at 16:09









      Claudio TelesClaudio Teles

      63




      63






















          2 Answers
          2






          active

          oldest

          votes


















          1














          There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.



          • Cloud Firestore Security Rules


          Security rules provide access control and data validation in a simple yet expressive format.




          • Storage Security
            Rules


          Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.




          • Firebase Realtime Database Security Rules


          Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.







          share|improve this answer
































            0














            Im guessing you are talking about Firebase Cloud Storage and Firestore



            The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property



            service firebase.storage 
            match /b/bucket/o
            match /allPaths=**
            allow read: if isAdmin();
            allow write: if isAdmin();


            /// FUNCTIONS BELLOW ///

            function isAdmin()
            return auth.token.admin === true








            share|improve this answer






















              Your Answer






              StackExchange.ifUsing("editor", function ()
              StackExchange.using("externalEditor", function ()
              StackExchange.using("snippets", function ()
              StackExchange.snippets.init();
              );
              );
              , "code-snippets");

              StackExchange.ready(function()
              var channelOptions =
              tags: "".split(" "),
              id: "1"
              ;
              initTagRenderer("".split(" "), "".split(" "), channelOptions);

              StackExchange.using("externalEditor", function()
              // Have to fire editor after snippets, if snippets enabled
              if (StackExchange.settings.snippets.snippetsEnabled)
              StackExchange.using("snippets", function()
              createEditor();
              );

              else
              createEditor();

              );

              function createEditor()
              StackExchange.prepareEditor(
              heartbeatType: 'answer',
              autoActivateHeartbeat: false,
              convertImagesToLinks: true,
              noModals: true,
              showLowRepImageUploadWarning: true,
              reputationToPostImages: 10,
              bindNavPrevention: true,
              postfix: "",
              imageUploader:
              brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
              contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
              allowUrls: true
              ,
              onDemand: true,
              discardSelector: ".discard-answer"
              ,immediatelyShowMarkdownHelp:true
              );



              );













              draft saved

              draft discarded


















              StackExchange.ready(
              function ()
              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53323490%2fwhats-the-diference-between-firestore-rules-and-firestorage-rules%23new-answer', 'question_page');

              );

              Post as a guest















              Required, but never shown

























              2 Answers
              2






              active

              oldest

              votes








              2 Answers
              2






              active

              oldest

              votes









              active

              oldest

              votes






              active

              oldest

              votes









              1














              There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.



              • Cloud Firestore Security Rules


              Security rules provide access control and data validation in a simple yet expressive format.




              • Storage Security
                Rules


              Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.




              • Firebase Realtime Database Security Rules


              Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.







              share|improve this answer





























                1














                There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.



                • Cloud Firestore Security Rules


                Security rules provide access control and data validation in a simple yet expressive format.




                • Storage Security
                  Rules


                Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.




                • Firebase Realtime Database Security Rules


                Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.







                share|improve this answer



























                  1












                  1








                  1







                  There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.



                  • Cloud Firestore Security Rules


                  Security rules provide access control and data validation in a simple yet expressive format.




                  • Storage Security
                    Rules


                  Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.




                  • Firebase Realtime Database Security Rules


                  Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.







                  share|improve this answer















                  There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.



                  • Cloud Firestore Security Rules


                  Security rules provide access control and data validation in a simple yet expressive format.




                  • Storage Security
                    Rules


                  Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.




                  • Firebase Realtime Database Security Rules


                  Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.








                  share|improve this answer














                  share|improve this answer



                  share|improve this answer








                  edited Nov 15 '18 at 16:16

























                  answered Nov 15 '18 at 16:11









                  Alex MamoAlex Mamo

                  46.1k82965




                  46.1k82965























                      0














                      Im guessing you are talking about Firebase Cloud Storage and Firestore



                      The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property



                      service firebase.storage 
                      match /b/bucket/o
                      match /allPaths=**
                      allow read: if isAdmin();
                      allow write: if isAdmin();


                      /// FUNCTIONS BELLOW ///

                      function isAdmin()
                      return auth.token.admin === true








                      share|improve this answer



























                        0














                        Im guessing you are talking about Firebase Cloud Storage and Firestore



                        The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property



                        service firebase.storage 
                        match /b/bucket/o
                        match /allPaths=**
                        allow read: if isAdmin();
                        allow write: if isAdmin();


                        /// FUNCTIONS BELLOW ///

                        function isAdmin()
                        return auth.token.admin === true








                        share|improve this answer

























                          0












                          0








                          0







                          Im guessing you are talking about Firebase Cloud Storage and Firestore



                          The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property



                          service firebase.storage 
                          match /b/bucket/o
                          match /allPaths=**
                          allow read: if isAdmin();
                          allow write: if isAdmin();


                          /// FUNCTIONS BELLOW ///

                          function isAdmin()
                          return auth.token.admin === true








                          share|improve this answer













                          Im guessing you are talking about Firebase Cloud Storage and Firestore



                          The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property



                          service firebase.storage 
                          match /b/bucket/o
                          match /allPaths=**
                          allow read: if isAdmin();
                          allow write: if isAdmin();


                          /// FUNCTIONS BELLOW ///

                          function isAdmin()
                          return auth.token.admin === true









                          share|improve this answer












                          share|improve this answer



                          share|improve this answer










                          answered Nov 15 '18 at 16:19









                          Jack WoodwardJack Woodward

                          63149




                          63149



























                              draft saved

                              draft discarded
















































                              Thanks for contributing an answer to Stack Overflow!


                              • Please be sure to answer the question. Provide details and share your research!

                              But avoid


                              • Asking for help, clarification, or responding to other answers.

                              • Making statements based on opinion; back them up with references or personal experience.

                              To learn more, see our tips on writing great answers.




                              draft saved


                              draft discarded














                              StackExchange.ready(
                              function ()
                              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53323490%2fwhats-the-diference-between-firestore-rules-and-firestorage-rules%23new-answer', 'question_page');

                              );

                              Post as a guest















                              Required, but never shown





















































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown

































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown







                              這個網誌中的熱門文章

                              What does pagestruct do in Eviews?

                              Dutch intervention in Lombok and Karangasem

                              Channel Islands