I will write and test secure firebase firestore security rules

C
carlos_mina35
C
carlos_mina35
Kero M

About this gig

Most Firebase apps ship with rules that look safe and are not. "allow read, write: if request.auth != null" lets any signed-in user read and overwrite every other user's data, and the Firebase console will not warn you.

I write Firestore and Storage security rules that enforce your real access model, and I prove it with automated tests against the Firebase emulator, not by clicking around the app.

What I cover:

  • Per-user data: users can only read and change their own documents
  • Roles: admin, manager, staff, customer, or whatever your app uses
  • Multi-tenant isolation: one company can never see another company's data
  • Field validation: types, required fields, immutable fields like createdAt or ownerId
  • Storage rules for uploads: file type, size, and owner checks

You get the rules file, the test file you can run yourself with one command, and a short plain-English note explaining every rule.

I have written and tested rules for production apps, including a multi-tenant SaaS used by restaurants in 8 languages.

Please send me your current rules and a short description of who should see what before ordering.

Get to know Kero M

Kero M

Flutter and React Developer, Firebase, Web Apps and Bug Fixes

  • FromItaly
  • Member sinceNov 2024
  • Languages

    English, Arabic, Italian
I build and fix cross-platform apps and web platforms that run in production. Flutter and Dart, React and TypeScript, Next.js, Firebase and Node. Twelve shipped Flutter apps plus React and Next web platforms. Where I am strongest: Firebase Auth, Firestore and security rules with real emulator tests; Stripe subscriptions and billing; Capacitor to turn a web app into Android and iOS; maps and geolocation; PDF generation; and multi-language apps with full right-to-left support. Send me your repo or your bug and I will tell you if I am the right fit.