If rules are implemented in the app code itself and compared to the data children in the database, why do we still need security rules?
Case example: The host of a group chat can kick users out. How do we know he is the host and can kick them out? Well, by adding a child where it specifies that he IS the host of the groupchat and make sure that data is known to all group chat members. (it could be his unique "displayName" as a value to the key "Host")
From the case example above, why would one want to add a security rule to this? There is already a "logic" rule used by the app in communication with the database "host" child.
I am fairly new to security rules. I did some reading but reached no answer for my question. I apologise if something is obvious here.