I integrated Firebase into my app. The user details in my database are stored as users -> uid -> key: name, value: name of the user, key: dept, value: department of the user, key: done, value: false
Now if a user does a particular activity (or work) in his/her app, the value of the key done will be changed to true. I don't want any malicious user to create an account and change the value of the done key to true. What will be the most secured security rule in that case?