Good day! Wrote rules for Firestore:
rules_version = '2';
service cloud.firestore {
match /databases/{database}/documents {
function isSignIn() {
return request.auth.uid != null
}
function isAdmin() {
return exists(/databases/$(database)/documents/admins/$(request.auth.uid))
}
function isPublished() {
return resource.data.published == true
}
match /instructions/{instructionId} {
allow list:
if isSignIn()
&& (isPublished() || isAdmin())
&& request.query.limit <= 10
}
}
}
I know that rules are not filters. I want to achieve a condition under which an administrator can view both published posts and unpublished posts, while regular users can only see published posts. The presence of a check for published forces the condition to be set at the application level.
firestore.collection("instructions")
.whereEqualTo("published", true)
.limit(10)
.get()
Which, in principle, is logical if we want to show only published posts to ordinary users.
How can I make the administrator see all records?
I have only one option - to remove the condition isPublished () || isAdmin () and make a separate view for the administrator without a publication condition. In this case, verification will have to be done on the client side, which is not good.
What can you advise?