Using the user's email in Firestore Rules?

Viewed 552

In a firestore database, I am using email only as authentication. The database has the following structure:

companies
jobs
users

For sake of readability (and for customer's peace of mind), I am using the email address as the Document ID for the users collection. A user document looks like this:

document id: tbogard@gmail.com
fields
  name_first: Terry
  name_last: Bogard
  jobs_read: ["job_A"]
  jobs_readwrite: ["job_B, job_C"]

When I try to grab the request token in the rules, it gives me errors (search for ***):

rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {

    // Helper functions
    function userExists(){ 
      // *** Function not found error: Name: [exists]. ***
      return exists(/databases/$(database)/documents/users/$(request.auth.token.email));
    }
    function userData(){
      // *** Function [get] called with malformed path: /databases/(default)/documents/users/ ***
      return get(/databases/$(database)/documents/users/$(request.auth.token.email)).data;
    }

    // For now, let's keep it simple, and enforce the User read/readwrite rules on Jobs.
    match /jobs/{jobId}{
      allow read: if userExists() && (jobId in userData().jobs_read || jobId in userData().jobs_readwrite);
      allow write: if userExists() && jobId in userData().jobs_readwrite;
    }

    // Only allow Users to see their own profile and companies they belong to.
    match /companies/{companyId}{
      allow read: if userExists() && userData().email in resource.data.employees;
      allow write: if false;
    }
    match /users/{userId}{
      allow read: if userExists() && userData().email == resource.data.email;
      allow write: if false;
    }
  }
}

I'm guessing request.auth.token.email is returning something like an optional? I can't find anything in the documentation explaining how the functions get/exists, which require a path, handle this. Is there a way that I could make the Firestore UID for each user the email address instead of the random string, or can I fix these rules some way?

0 Answers
Related