FireBase Rule not working with auth.uid

Viewed 439

I`m trying to set a Firebase rule that will grant access to R/W, if the $uid is equal to auth.uid.

This is an example of my DB structure:

enter image description here

The first rule configuration I tried:

{
"rules": {
      "$uid" : {
        ".read": "$uid === auth.uid",
        ".write": "$uid === auth.uid"
      }
    }
}

I also have tried this way (include the path of the root):

{
    "rules": {
        "AppName-46ed8":{
            "$uid" : {
                ".read": "$uid === auth.uid",
                ".write": "$uid === auth.uid"
                    }
                }
            }
}

I`m following the Firebase instructions and this rules pass the simulator.

I`m not getting the instance with snapshot from Firebase when these rules are in place.

If I use the default "Unsafe" rules as follows, everything works as it should (but is open to threat of hacking):

    {
    "rules": {
        ".read": true, ".write":true
             }
     }

Please advice.

1 Answers

The follow it should work:

These rules require authentication

Allow only authenticated content owners access to their data

{
  "rules": {
    ".read": "auth != false",
    ".write": "auth != false",
    "Users": {
      "$id":{
        ".read": "auth.uid == $id",
        ".write": "auth.uid == $id",
      }
    },
  }
}
Related