-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathstorage.rules
More file actions
36 lines (32 loc) · 1.67 KB
/
storage.rules
File metadata and controls
36 lines (32 loc) · 1.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
rules_version = '2';
service firebase.storage {
match /b/{bucket}/o {
// ── Profile photos ─────────────────────────────────────────────────────
// Any authenticated user can read (needed to display avatars).
// Only the owner can write/delete their own photo.
match /profile_photos/{filename} {
allow read: if request.auth != null;
allow write, delete: if request.auth != null
&& filename == request.auth.uid + '.jpg';
}
// ── Audio messages ─────────────────────────────────────────────────────
// L'accès Firestore est la vraie barrière (isGroupMember sur les messages).
// Ici on vérifie juste l'auth + le type + la taille.
match /audio/{groupId}/{filename} {
allow read: if request.auth != null;
allow create: if request.auth != null
&& request.resource.size < 50 * 1024 * 1024
&& request.resource.contentType.matches('audio/.*');
allow update, delete: if false;
}
// ── Media messages (photos & vidéos) ───────────────────────────────────
match /media/{groupId}/{filename} {
allow read: if request.auth != null;
allow create: if request.auth != null
&& request.resource.size < 100 * 1024 * 1024
&& (request.resource.contentType.matches('image/.*')
|| request.resource.contentType.matches('video/.*'));
allow update, delete: if false;
}
}
}