I will write and test secure firebase firestore security rules


About this gig
Most Firebase apps ship with rules that look safe and are not. "allow read, write: if request.auth != null" lets any signed-in user read and overwrite every other user's data, and the Firebase console will not warn you.
I write Firestore and Storage security rules that enforce your real access model, and I prove it with automated tests against the Firebase emulator, not by clicking around the app.
What I cover:
- Per-user data: users can only read and change their own documents
- Roles: admin, manager, staff, customer, or whatever your app uses
- Multi-tenant isolation: one company can never see another company's data
- Field validation: types, required fields, immutable fields like createdAt or ownerId
- Storage rules for uploads: file type, size, and owner checks
You get the rules file, the test file you can run yourself with one command, and a short plain-English note explaining every rule.
I have written and tested rules for production apps, including a multi-tenant SaaS used by restaurants in 8 languages.
Please send me your current rules and a short description of who should see what before ordering.
Get to know Kero M
Flutter and React Developer, Firebase, Web Apps and Bug Fixes
- FromItaly
- Member sinceNov 2024
Languages
English, Arabic, Italian
FAQ
Do you need access to my Firebase project?
No. Send me your current rules and your data structure and I work in the local Firebase emulator. Deployment is only part of the Premium package, and you can deploy yourself instead if you prefer.
Will the new rules break my app?
The tests check both sides: that allowed actions still work and that forbidden ones fail. So any breakage shows up in the tests before deployment, not in front of your users.
Do you also do Realtime Database rules?
Yes. Message me before ordering so I can look at your database structure and confirm which package fits.
Can you fix my app code too?
If your app reads data in a way the secure rules no longer allow, I will point out exactly which queries need to change. Changing the app code itself is a separate order.
