I want something like this:
firebase.auth().currentUser.canWrite();
This should return true or false based on the security rules I have made in Firebase Console.
I want something like this:
firebase.auth().currentUser.canWrite();
This should return true or false based on the security rules I have made in Firebase Console.
First you need to restrict access to your realtime database using custom claims and security rules (since by default, you restrict or allow read/write permissions for all users).
Then, on the client, check that a given user has access to the db by parsing the id token and checking the custom claims (refer to example in section "Access custom claims on the client" from the link above. Example is written in JS, but there should be no problem converting it to e.g. Swift). Further, you could easily wrap this functionality (check for valid claims) in your own canWrite() extension on the FIRUser object which returns true or false depending on if token has the correct claims.
Okay, I went through the suggestion, and after analyzing everything I've found a sweet workaround. Now let me first tell you that I wanted to restrict users other than the admin/s from seeing UI buttons like 'Add new Item', 'Delete item' etc., so that they cannot modify the database.
for example, I want only the user with credentials admin@admin.com to have access to buttons and pages that allow modification in database.
Ps. This is an Ionic project.
In my app.component.ts file:
import { Events } from 'ionic-angular';
export class MyApp{
admins: any;
constructor(public events: Events){
this.initializeApp();
this.admins =[
{email: 'admin@admin.com'},
{email: 'another_admin@admin.com'}
//You may add more users whom you want to give admin privilege..
];
// Now subscribe to an event to check if the logged-in user is an admin user or not!
events.subscribe('check:admin', (email) => {
var isAdmin = false;
this.admins.forEach((x) => {
if(email === x.email)
isAdmin = true;
});
return isAdmin;
});
}
}
In my home.ts file: This can be any page in your project, not necessarily homepage.
import { Events } from 'ionic-angular';
export class HomePage{
// Now declare and initialize a boolean variable. This will be true if the logged-in (currentUser) user is an admin.
isAdmin = this.events.publish('check:admin', firebase.auth().currentUser.email)[0];
// this.events.publish() returns an array, hence the weird workaround of '[0]'.
constructor(private events: Events){}
}
Now in my home.html page:
<button *ngIf="isAdmin">Add new Item</button>
Here, the 'Add new Item' button will only show if the variable 'isAdmin' is true. This way, we can have control over which UI elements to display to which type of users..
Hope this helps. Thanks!
A possible way to check whether user has access to the database is to try to read (or write) any value from the database.
For example, I have a "dummy" node, and I try to read the value. If the operation is not successful, this means that I'm dealing with a permission issue:
dummyNode.addListenerForSingleValueEvent(new ValueEventListener() {
@Override
public void onDataChange(DataSnapshot dataSnapshot) {
// read access successfully tested.
}
@Override
public void onCancelled(DatabaseError firebaseError) {
Log.v(TAG,"firebaseError:"+firebaseError);
//Common Error here: Transaction at /F failed: DatabaseError: Permission denied
}
});