I am building a project where I want users to be authenticated to read or write any data in my firebase Realtime Database. I also want to enforce other rules in other nodes of my DB.
After reading the docs, I'm under the impression that the basic way to do this would be to use auth != null in every leaf of my rules tree and combine it with the specific rule I want to enforce. For instance,
{
"rules": {
"rooms": {
"1": {
".read": "auth!=null && !data.exists()"
},
"2": {
".read": "auth!=null"
}
}
}
}
I feel like this will make my rules hard to read and tiresome to write. I was looking for a way to overcome this problem and I thought I would be able to use overlapping statements to achieve this, as described here https://firebase.google.com/docs/database/security/core-syntax#overlapping_statements. For instance,
{
"rules": {
"$route": {
".read": "auth != null",
".write": "auth != null"
},
"rooms": {
"1": {
".read": "!data.exists()"
},
"2": {
".read": "true"
}
}
}
}
}
However, when using the testing tool without authentication to perform a read on /rooms/2, it appears that the query is only tested against the second set of rules, allowing the operation. From my understanding, both rules sets should have been tested, and the first one should have rejected the operation.
I have three questions :
- Is what I am trying to achieve a bad practice ? Should I be enforcing the rules at leaf level ?
- What did I misunderstand about overlapping statements ? I'm not seeing the difference between my example and the docs
- Is there a way to achieve this ?
Thanks for your help !