3 ms·
The firestore security rules dsl [1] looks like it could become cumbersome as the number of edge cases increases. I've briefly used firebase realtime database j
by jcz 9y ago
The firestore security rules dsl [1] looks like it could become cumbersome as the number of edge cases increases. I've briefly used firebase realtime database json rules [2] in a side project, and while basic acl scenarios can be covered cleanly, rules quickly tangle without a full programming language. It's hard to check syntax, lint, test, and collaboratively edit.
I believe this custom auth layer is best handled by allowing code with restricted api access and time constraints. The technical approach cloudflare used to implement its edge workers by embedding v8/js [3] would be perfect here.
[1] https://firebase.google.com/docs/firestore/security/get-started https://firebase.google.com/docs/firestore/security/get-star...
example:
service cloud.firestore {
match /databases/{database}/documents {
match /{document=**} {
allow read, write: if false;
}
}
}
[2] https://firebase.google.com/docs/database/security/ https://firebase.google.com/docs/database/security/
[3] https://blog.cloudflare.com/introducing-cloudflare-workers/ https://blog.cloudflare.com/introducing-cloudflare-workers/
- habosa 9y agoThe new rules language (which was already used by Cloud Storage) is a full programming language. It's not turing complete, but that's by design. Still, you can declare functions and do other complex things that were never possible with the Firebase Realtime Database JSON rules. We're working on opening up the tools to work with the rules language so you can test and iterate more easily.