Repository navigation
Expand file tree
/
Copy pathstorage.rules
More file actions
95 lines (78 loc) · 4.4 KB
/
Copy pathstorage.rules
File metadata and controls
95 lines (78 loc) · 4.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
rules_version = '2';
// ─────────────────────────────────────────────────────────────────────────────
// Wing Zone – Production Firebase Storage Security Rules
// Last updated: 2026-02-20
//
// Admin check uses the custom Auth claim 'admin' (set via Admin SDK).
// Storage rules cannot read Firestore, so custom claims are the only option.
// ─────────────────────────────────────────────────────────────────────────────
service firebase.storage {
match /b/{bucket}/o {
// ── Helper functions ─────────────────────────────────────────────────────
function isAuthenticated() {
return request.auth != null;
}
// Admin check via custom claim only (Firestore not accessible in storage rules)
function isAdmin() {
return isAuthenticated() && request.auth.token.admin == true;
}
function isOwner(userId) {
return isAuthenticated() && request.auth.uid == userId;
}
// Max file size in bytes (5 MB)
function isUnder5MB() {
return request.resource.size <= 5 * 1024 * 1024;
}
// Only allow common image MIME types
function isImage() {
return request.resource.contentType.matches('image/(jpeg|jpg|png|webp|gif)');
}
// ── Profile pictures ─────────────────────────────────────────────────────
// Users can only upload to their own folder.
// Enforces image type and 5 MB size limit.
match /profile-images/{userId}/{fileName} {
allow read: if isAuthenticated();
allow create, update: if isOwner(userId) && isImage() && isUnder5MB();
allow delete: if isOwner(userId) || isAdmin();
}
// ── User general uploads (legacy path) ───────────────────────────────────
match /user-uploads/{userId}/{allPaths=**} {
allow read: if isAuthenticated();
allow create, update: if isOwner(userId) && isImage() && isUnder5MB();
allow delete: if isOwner(userId) || isAdmin();
}
// ── Menu item images ─────────────────────────────────────────────────────
match /menu/{fileName} {
allow read: if true;
allow create, update, delete: if isAdmin() || isAuthenticated();
}
match /menu-images/{fileName} {
allow read: if true;
allow create, update, delete: if isAdmin() || isAuthenticated();
}
// ── Banner images ─────────────────────────────────────────────────────────
match /banners/{fileName} {
allow read: if true;
allow create, update, delete: if isAdmin();
}
// ── Receipts (order PDFs / sticker images) ───────────────────────────────
// Only the authenticated user who owns the receipt path may read.
// Cloud Functions write receipts with admin SDK (bypasses rules).
match /receipts/{userId}/{fileName} {
allow read: if isOwner(userId) || isAdmin();
allow write: if isAdmin();
}
// Legacy flat receipts path (if any)
match /receipts/{receiptId} {
allow read: if isAuthenticated();
allow write: if isAdmin();
}
// ── Notification sounds ──────────────────────────────────────────────────
match /notification-sounds/{soundId} {
allow read: if true;
allow create, update, delete: if isAdmin();
}
// ── Deny everything else ─────────────────────────────────────────────────
// Unmatched paths are denied by default.
}
}