I have a react + firebase app. In the user's collection I have a permissions object where I track what the user has access to. Then in my react app, I have the following:
// Login component
const userRecord = await Firebase.login(email,password)
store.user = await this.fetchUser(userRecord.uid)
For admin-only views, I wrap them in a withAuthorization HOC, where I check for store.user.permissions.admin
// Not exactly this, but this is the general idea
{store.user.permissions.admin && <RestrictedView />
My question is, could the user change the value of permissions in chrome to gain access to the restricted views? If so, is there a better approach? I may eventually use customClaims, but would like to use the above for now.
Thank you in advance!