Firebase security rules cross project

Viewed 451

Project A has Firebase Authentication and Project B has Firebase Firestore. Both Authentication and Firestore are working correctly using: https://firebase.google.com/docs/projects/multiprojects (Web)

However when writing the following Project B Firestore Security Rules:

rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    match /users/{uid} {
      allow get: if request.auth.uid == uid;
    }
  }
}

I get an error:

Missing or insufficient permissions

Because the Authentication data is with Project A, there is no auth with the Project B Firestore request.

How do I give Project B the authentication information from Project A using JavaScript/Web?

1 Answers

Bluntly, you are "separating your microservices" in completely the wrong way. Authentication is FUNDAMENTALLY tied to functionality, and inseparable - it is NOT a "micro-service". Even if you choose to use Cloud Functions to provide your "micro-service API", there is absolutely no reason whatever to use separate projects and databases BEHIND the Cloud Functions, and every reason to keep them the same.

What you are describing sounds far more like an attempt to hack another service than to create a viable solution, and Firestore is specifically built to resist such attempts.

Related