Whats the diference between Firestore Rules and Firestorage Rules?
I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:
match /users/userID
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
However when I tried to add the same rules under Firestorage, the access is constantly denied.
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
Does the Firestorage get method work differently then the Firestore get method?
Any assistance would be much appreciated.
firebase firebase-realtime-database google-cloud-firestore
add a comment |
I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:
match /users/userID
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
However when I tried to add the same rules under Firestorage, the access is constantly denied.
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
Does the Firestorage get method work differently then the Firestore get method?
Any assistance would be much appreciated.
firebase firebase-realtime-database google-cloud-firestore
add a comment |
I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:
match /users/userID
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
However when I tried to add the same rules under Firestorage, the access is constantly denied.
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
Does the Firestorage get method work differently then the Firestore get method?
Any assistance would be much appreciated.
firebase firebase-realtime-database google-cloud-firestore
I have files I want to make sure to keep secure, once the admin uploads a file into the storage, only he and the user he is sharing the file with has access to the links to download that file. Hence under firestore rules I added the following:
match /users/userID
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
However when I tried to add the same rules under Firestorage, the access is constantly denied.
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
Does the Firestorage get method work differently then the Firestore get method?
Any assistance would be much appreciated.
match /users/userID
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
match /users/userID
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return get(/databases/$(database)/documents/users/$(request.auth.uid)).data.IsAdmin;
firebase firebase-realtime-database google-cloud-firestore
firebase firebase-realtime-database google-cloud-firestore
asked Nov 15 '18 at 16:09
Claudio TelesClaudio Teles
63
63
add a comment |
add a comment |
2 Answers
2
active
oldest
votes
There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.
- Cloud Firestore Security Rules
Security rules provide access control and data validation in a simple yet expressive format.
- Storage Security
Rules
Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.
- Firebase Realtime Database Security Rules
Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.
add a comment |
Im guessing you are talking about Firebase Cloud Storage and Firestore
The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return auth.token.admin === true
add a comment |
Your Answer
StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53323490%2fwhats-the-diference-between-firestore-rules-and-firestorage-rules%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
2 Answers
2
active
oldest
votes
2 Answers
2
active
oldest
votes
active
oldest
votes
active
oldest
votes
There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.
- Cloud Firestore Security Rules
Security rules provide access control and data validation in a simple yet expressive format.
- Storage Security
Rules
Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.
- Firebase Realtime Database Security Rules
Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.
add a comment |
There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.
- Cloud Firestore Security Rules
Security rules provide access control and data validation in a simple yet expressive format.
- Storage Security
Rules
Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.
- Firebase Realtime Database Security Rules
Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.
add a comment |
There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.
- Cloud Firestore Security Rules
Security rules provide access control and data validation in a simple yet expressive format.
- Storage Security
Rules
Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.
- Firebase Realtime Database Security Rules
Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.
There are no Firestorage Rules, there are actually rules for Cloud Firestore which is the new database from Google, Firebase Storage which is used to store images, audio, video, or other user-generated content and Fireabse realtime database which is also a NoSQL database.
- Cloud Firestore Security Rules
Security rules provide access control and data validation in a simple yet expressive format.
- Storage Security
Rules
Storage Security Rules are used to determine who has read and write access to files stored in Cloud Storage, as well as how files are structured and what metadata they contain.
- Firebase Realtime Database Security Rules
Firebase Realtime Database Rules determine who has read and write access to your database, how your data is structured, and what indexes exist. These rules live on the Firebase servers and are enforced automatically at all times.
edited Nov 15 '18 at 16:16
answered Nov 15 '18 at 16:11
Alex MamoAlex Mamo
46.1k82965
46.1k82965
add a comment |
add a comment |
Im guessing you are talking about Firebase Cloud Storage and Firestore
The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return auth.token.admin === true
add a comment |
Im guessing you are talking about Firebase Cloud Storage and Firestore
The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return auth.token.admin === true
add a comment |
Im guessing you are talking about Firebase Cloud Storage and Firestore
The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return auth.token.admin === true
Im guessing you are talking about Firebase Cloud Storage and Firestore
The issue with your Cloud Storage rules is that you cannot access the Firestore database. If you need to carry over data to assist with authorising a write you could look at custom claims Which you could access with auth.token.admin === true in your security rules for example that looks at the users auth token for an admin property
service firebase.storage
match /b/bucket/o
match /allPaths=**
allow read: if isAdmin();
allow write: if isAdmin();
/// FUNCTIONS BELLOW ///
function isAdmin()
return auth.token.admin === true
answered Nov 15 '18 at 16:19
Jack WoodwardJack Woodward
63149
63149
add a comment |
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53323490%2fwhats-the-diference-between-firestore-rules-and-firestorage-rules%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown