I am building a desktop application and use the Firebase SDK. I am doing experiments with the Realtime Database and the Storage service of Firebase. The realtime database contains all the meta data, and the storage contains the actual files.
The database scheme looks like this:
-+ users/
|
+ -- + sd798f7a98dsf79879/ <-- user.uid
|
+ -- + projects/
|
+---- Project1/
| ...
+---- Project2/
...
The storage scheme looks similar. In the desktop app I can quickly calculate the total size of all files the user has in the storage since this information is stored in the realtime database. And if a user wants to upload more data than his plan allows, I could refuse the upload in the client.
But this is not 100% secure, as this is a client check that could be hacked. I am not too worried if someone could temporarily go over his limit, but I would like to ensure that I can make use of a soft and hard limit.
Given my situation using the database in a desktop application, could you recommend an alternative approach?