Im new to Firebase Firestore and I want to define the security Rules. My datastructure is very simpel as you can see in the picture.
Every user has his own document with subcollections. I want that a user can only read and write his own documents (including documents in subcollection), so my rules should look something like this:
service cloud.firestore {
match /databases/{database}/documents {
match /users/{userId} {
allow read, update, delete: if request.auth != null && request.auth.uid == userId;
allow create: if request.auth != null;
}
}
}
With this code, will the user be able to read and write documents in subcollection too? Is there anything else thats important what I need to add to the security rules or is this all I need to do?
