firestore.rules
match /databases/{database} {
match /documents/board/{boardId}/{document=**} {
allow read: if (resource.data.creatorId == request.auth.uid);
query 1 (works)
this.db
.collection("board")
.where("creatorId", "==", app.auth().currentUser.uid).onSnapshot(...)
query 2 (doesnt work, returns FirebaseError: Missing or insufficient permissions)
this.db
.collection("board")
.where("creatorId", "==", app.auth().currentUser.uid)
.where(app.firestore.FieldPath.documentId(), "in", boardIds).onSnapshot(...)
This doesn't make any sense to me. Query 2 is a subset of Query 1 and yet, unlike Query 1, violates the security rules.
Does anyone know why?