Odd database structure for Firestore security rules - Need RecommendationsWhat's the difference between Cloud Firestore and the Firebase Realtime Database?Firestore security rules for public and private fieldsFirestore security rules - How to add collections wildcardsFirestore Security RulesFirestore rule on condition from a different collectionCloud Firestore RuleDoes firestore rule simulator account for existing documents actual collections?Firestore write security rule for specific user using auth namesFirestore Rules: validate data does not have fieldFirestore Security Rules: 'request.auth.uid' Is Null With Android Request

What is the offset in a seaplane's hull?

Schwarzchild Radius of the Universe

What typically incentivizes a professor to change jobs to a lower ranking university?

Could a US political party gain complete control over the government by removing checks & balances?

What do you call something that goes against the spirit of the law, but is legal when interpreting the law to the letter?

How to use Pandas to get the count of every combination inclusive

DOS, create pipe for stdin/stdout of command.com(or 4dos.com) in C or Batch?

N.B. ligature in Latex

Need help identifying/translating a plaque in Tangier, Morocco

Why is an old chain unsafe?

What is the command to reset a PC without deleting any files

Can you lasso down a wizard who is using the Levitate spell?

Draw simple lines in Inkscape

Motorized valve interfering with button?

The use of multiple foreign keys on same column in SQL Server

How can the DM most effectively choose 1 out of an odd number of players to be targeted by an attack or effect?

Can an x86 CPU running in real mode be considered to be basically an 8086 CPU?

What is the white spray-pattern residue inside these Falcon Heavy nozzles?

Why are 150k or 200k jobs considered good when there are 300k+ births a month?

I’m planning on buying a laser printer but concerned about the life cycle of toner in the machine

Is there really no realistic way for a skeleton monster to move around without magic?

How to determine if window is maximised or minimised from bash script

Is Social Media Science Fiction?

I see my dog run



Odd database structure for Firestore security rules - Need Recommendations


What's the difference between Cloud Firestore and the Firebase Realtime Database?Firestore security rules for public and private fieldsFirestore security rules - How to add collections wildcardsFirestore Security RulesFirestore rule on condition from a different collectionCloud Firestore RuleDoes firestore rule simulator account for existing documents actual collections?Firestore write security rule for specific user using auth namesFirestore Rules: validate data does not have fieldFirestore Security Rules: 'request.auth.uid' Is Null With Android Request






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I have a Firestore database for an app where a user will authenticate using email and password in a 3rd-party API which returns their account id, user id, and api token.



If a Firestore user with their email does not exist already, I create one. I then check the Firestore db to see if there is a document for that account id already. If not, I create one, and create a sub-collection for 'users', then add their data as a users document and include the fields isAllowed and isAdmin both as true, and store their firebase user id.



In the admin page of the app, I query their account id in the 3rd party API and return all users in their account. The admin then has the ability to allow other users access to the app and optionally mark them as admins as well. These permissions are stored by adding the user data as documents in the Firestore/account id/users collection with isAllowed and isAdmin set accordingly.



At this point, these additional users do not have firebase accounts, so I am using the user id from the 3rd party as the 'users' document name for everyone. With my knowledge, this makes Firebase security rules hard because I do not have a relationship between the Firebase account data passed into the security rules and the database data.



My desired rules are:



  1. If no account id exists, allow the creation of account and users

  2. If account id exists, allow read-only for account data and only their user IF the user exists in the users collection and isAllowed = true

  3. If #2 is true, allow write access to the entire account if isAdmin = true

Does this make sense? Any thoughts or suggestions?



Thank you.










share|improve this question
























  • Hey Armand, welcome to Stack Overflow. As you may have noticed, nobody answered or commented in the first 12 hours after you posted. You'll find that typically people here are much more likely to respond if you include the actual code, data structure, and security rules in your question, instead of descriptions of them. It also helps if you have a single concrete question about something specific in your code, instead of the broad questions you have now. For more on this, see how to create a minimal, complete, verifiable example

    – Frank van Puffelen
    Mar 9 at 15:55

















0















I have a Firestore database for an app where a user will authenticate using email and password in a 3rd-party API which returns their account id, user id, and api token.



If a Firestore user with their email does not exist already, I create one. I then check the Firestore db to see if there is a document for that account id already. If not, I create one, and create a sub-collection for 'users', then add their data as a users document and include the fields isAllowed and isAdmin both as true, and store their firebase user id.



In the admin page of the app, I query their account id in the 3rd party API and return all users in their account. The admin then has the ability to allow other users access to the app and optionally mark them as admins as well. These permissions are stored by adding the user data as documents in the Firestore/account id/users collection with isAllowed and isAdmin set accordingly.



At this point, these additional users do not have firebase accounts, so I am using the user id from the 3rd party as the 'users' document name for everyone. With my knowledge, this makes Firebase security rules hard because I do not have a relationship between the Firebase account data passed into the security rules and the database data.



My desired rules are:



  1. If no account id exists, allow the creation of account and users

  2. If account id exists, allow read-only for account data and only their user IF the user exists in the users collection and isAllowed = true

  3. If #2 is true, allow write access to the entire account if isAdmin = true

Does this make sense? Any thoughts or suggestions?



Thank you.










share|improve this question
























  • Hey Armand, welcome to Stack Overflow. As you may have noticed, nobody answered or commented in the first 12 hours after you posted. You'll find that typically people here are much more likely to respond if you include the actual code, data structure, and security rules in your question, instead of descriptions of them. It also helps if you have a single concrete question about something specific in your code, instead of the broad questions you have now. For more on this, see how to create a minimal, complete, verifiable example

    – Frank van Puffelen
    Mar 9 at 15:55













0












0








0








I have a Firestore database for an app where a user will authenticate using email and password in a 3rd-party API which returns their account id, user id, and api token.



If a Firestore user with their email does not exist already, I create one. I then check the Firestore db to see if there is a document for that account id already. If not, I create one, and create a sub-collection for 'users', then add their data as a users document and include the fields isAllowed and isAdmin both as true, and store their firebase user id.



In the admin page of the app, I query their account id in the 3rd party API and return all users in their account. The admin then has the ability to allow other users access to the app and optionally mark them as admins as well. These permissions are stored by adding the user data as documents in the Firestore/account id/users collection with isAllowed and isAdmin set accordingly.



At this point, these additional users do not have firebase accounts, so I am using the user id from the 3rd party as the 'users' document name for everyone. With my knowledge, this makes Firebase security rules hard because I do not have a relationship between the Firebase account data passed into the security rules and the database data.



My desired rules are:



  1. If no account id exists, allow the creation of account and users

  2. If account id exists, allow read-only for account data and only their user IF the user exists in the users collection and isAllowed = true

  3. If #2 is true, allow write access to the entire account if isAdmin = true

Does this make sense? Any thoughts or suggestions?



Thank you.










share|improve this question
















I have a Firestore database for an app where a user will authenticate using email and password in a 3rd-party API which returns their account id, user id, and api token.



If a Firestore user with their email does not exist already, I create one. I then check the Firestore db to see if there is a document for that account id already. If not, I create one, and create a sub-collection for 'users', then add their data as a users document and include the fields isAllowed and isAdmin both as true, and store their firebase user id.



In the admin page of the app, I query their account id in the 3rd party API and return all users in their account. The admin then has the ability to allow other users access to the app and optionally mark them as admins as well. These permissions are stored by adding the user data as documents in the Firestore/account id/users collection with isAllowed and isAdmin set accordingly.



At this point, these additional users do not have firebase accounts, so I am using the user id from the 3rd party as the 'users' document name for everyone. With my knowledge, this makes Firebase security rules hard because I do not have a relationship between the Firebase account data passed into the security rules and the database data.



My desired rules are:



  1. If no account id exists, allow the creation of account and users

  2. If account id exists, allow read-only for account data and only their user IF the user exists in the users collection and isAllowed = true

  3. If #2 is true, allow write access to the entire account if isAdmin = true

Does this make sense? Any thoughts or suggestions?



Thank you.







firebase google-cloud-firestore firebase-security-rules






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Mar 9 at 3:51









Doug Stevenson

83.7k10100118




83.7k10100118










asked Mar 9 at 3:49









Armand FarrArmand Farr

1




1












  • Hey Armand, welcome to Stack Overflow. As you may have noticed, nobody answered or commented in the first 12 hours after you posted. You'll find that typically people here are much more likely to respond if you include the actual code, data structure, and security rules in your question, instead of descriptions of them. It also helps if you have a single concrete question about something specific in your code, instead of the broad questions you have now. For more on this, see how to create a minimal, complete, verifiable example

    – Frank van Puffelen
    Mar 9 at 15:55

















  • Hey Armand, welcome to Stack Overflow. As you may have noticed, nobody answered or commented in the first 12 hours after you posted. You'll find that typically people here are much more likely to respond if you include the actual code, data structure, and security rules in your question, instead of descriptions of them. It also helps if you have a single concrete question about something specific in your code, instead of the broad questions you have now. For more on this, see how to create a minimal, complete, verifiable example

    – Frank van Puffelen
    Mar 9 at 15:55
















Hey Armand, welcome to Stack Overflow. As you may have noticed, nobody answered or commented in the first 12 hours after you posted. You'll find that typically people here are much more likely to respond if you include the actual code, data structure, and security rules in your question, instead of descriptions of them. It also helps if you have a single concrete question about something specific in your code, instead of the broad questions you have now. For more on this, see how to create a minimal, complete, verifiable example

– Frank van Puffelen
Mar 9 at 15:55





Hey Armand, welcome to Stack Overflow. As you may have noticed, nobody answered or commented in the first 12 hours after you posted. You'll find that typically people here are much more likely to respond if you include the actual code, data structure, and security rules in your question, instead of descriptions of them. It also helps if you have a single concrete question about something specific in your code, instead of the broad questions you have now. For more on this, see how to create a minimal, complete, verifiable example

– Frank van Puffelen
Mar 9 at 15:55












0






active

oldest

votes












Your Answer






StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");

StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55073802%2fodd-database-structure-for-firestore-security-rules-need-recommendations%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes















draft saved

draft discarded
















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55073802%2fodd-database-structure-for-firestore-security-rules-need-recommendations%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Identity Server 4 is not redirecting to Angular app after login2019 Community Moderator ElectionIdentity Server 4 and dockerIdentityserver implicit flow unauthorized_clientIdentityServer Hybrid Flow - Access Token is null after user successful loginIdentity Server to MVC client : Page Redirect After loginLogin with Steam OpenId(oidc-client-js)Identity Server 4+.NET Core 2.0 + IdentityIdentityServer4 post-login redirect not working in Edge browserCall to IdentityServer4 generates System.NullReferenceException: Object reference not set to an instance of an objectIdentityServer4 without HTTPS not workingHow to get Authorization code from identity server without login form

2005 Ahvaz unrest Contents Background Causes Casualties Aftermath See also References Navigation menue"At Least 10 Are Killed by Bombs in Iran""Iran"Archived"Arab-Iranians in Iran to make April 15 'Day of Fury'"State of Mind, State of Order: Reactions to Ethnic Unrest in the Islamic Republic of Iran.10.1111/j.1754-9469.2008.00028.x"Iran hangs Arab separatists"Iran Overview from ArchivedConstitution of the Islamic Republic of Iran"Tehran puzzled by forged 'riots' letter""Iran and its minorities: Down in the second class""Iran: Handling Of Ahvaz Unrest Could End With Televised Confessions""Bombings Rock Iran Ahead of Election""Five die in Iran ethnic clashes""Iran: Need for restraint as anniversary of unrest in Khuzestan approaches"Archived"Iranian Sunni protesters killed in clashes with security forces"Archived

Can't initialize raids on a new ASUS Prime B360M-A motherboard2019 Community Moderator ElectionSimilar to RAID config yet more like mirroring solution?Can't get motherboard serial numberWhy does the BIOS entry point start with a WBINVD instruction?UEFI performance Asus Maximus V Extreme