I understand it's not good to set your read and writes to all users on Firebase; But what if you leave your reads to all and your writes to only authenticated users?
What is the worst thing that could happen? Is it easy for someone to gain access to the firebase project? I'm currently using cloud firestore.
Sorry if this seems a little dumb, I'm new to this:
Thanks, Jacob
EDIT: Current Rules:
service cloud.firestore {
match /databases/{database}/documents {
match /{document=**} {
allow read: if true;
allow write: if request.auth != null;
}
}
}