-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathstorage.rules
More file actions
31 lines (28 loc) · 1.11 KB
/
Copy pathstorage.rules
File metadata and controls
31 lines (28 loc) · 1.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
rules_version = '2';
service firebase.storage {
match /b/{bucket}/o {
function activeManager(orgId) {
return request.auth != null
&& request.auth.token.firebase.sign_in_provider != 'anonymous'
&& firestore.exists(/databases/(default)/documents/organizations/$(orgId)/members/$(request.auth.uid))
&& firestore.get(/databases/(default)/documents/organizations/$(orgId)/members/$(request.auth.uid)).data.role == 'MANAGER'
&& firestore.get(/databases/(default)/documents/organizations/$(orgId)/members/$(request.auth.uid)).data.active == true;
}
match /organizations/{orgId}/payouts/{payoutId}/proof/payment-proof {
allow read: if activeManager(orgId);
allow write: if activeManager(orgId)
&& request.resource.size <= 10 * 1024 * 1024
&& request.resource.contentType in [
"image/jpeg",
"image/png",
"image/webp",
"image/heic",
"image/heif"
];
}
// Checklist evidence has no browser access until deliberately implemented.
match /{allPaths=**} {
allow read, write: if false;
}
}
}