Using User Claims in Firebase Storage rules

Viewed 444

Is it possible to use custom claims in Firebase Storage rules? It looks like those values are not accessible from there.

Here's my rule:

match /b/{bucket}/o {    
  match /{userId}/files/{fileName} {
    allow read: if request.auth.token.admin == true;
  }
}

Those rules throw an error:

Error: simulator.rules line [13], column [20]. Property admin is undefined on object.

I previously set the userClaims this way:

await admin.auth().setCustomUserClaims(user.uid, {
        groupToken: 'abecadlo',
        admin: true
    });
1 Answers

The following rule should take the warning away:

    match /b/{bucket}/o {    
      match /{userId}/files/{fileName} {
        allow read: if "admin" in request.auth.token && request.auth.token.admin == true;
      }
    }
Related