I don't know if my question is inside the proximity of what I should be asking on stack overflow but if so...
Why do we need to write security rules in 'Firebase "Rules"' when I can literally just go into my client code and say:
db.collection("users").get().then(res=> {
res.docs.map(user => {
if (user.data().uid !== auth.currentUser.uid) {
// do something I'm about to put in this code snippet
}
})
})
Like, can someone just get in my client-side code and write whatever they want and that's why we need to write code in the security rules within the Firebase console?
It also confuses me why we need Firebase functions when we can simply do the logic on the client-side although I can understand some stuff needs to be done server-side.
But just for the scope of this question, can someone explain to me clearly why we can't just write our security inside of our code to make things work?
Hopefully I was thorough with the info. Thanks.