Skip to content

Tighten Storage rules for user-uploaded media #2500

@rfontanarosa

Description

@rfontanarosa

The current Firebase Storage rule for user-uploaded media (/user-media/surveys/{surveyId}/...)
authorizes writes at the survey level only. Within a survey, any user with write permission can
create, overwrite, or delete files at arbitrary sub-paths, including paths not associated with
their own account.

Metadata

Metadata

Assignees

Labels

type: bugSomething isn't working

Type

Projects

Status

In Progress

Relationships

None yet

Development

No branches or pull requests

Issue actions