Firetool

Home / Docs / Security rules

Docs

Edit Firestore and Storage security rules

See the security rules Firebase has for a Firestore database or a Storage bucket, check them for errors and deploy a change, with production confirmation and the old rules kept in the audit log.

Reading and checking rules work in the Free edition. Deploying needs Pro.

Open the rules

  1. In the sidebar, right-click a project (for its default database) or a database, and choose Security rules…. Or, with one of its collections open, choose Tools → Security rules….
  2. The rules open in their own tab: Firestore shows the rules of that database. Storage shows a bucket's rules; pick the bucket at the top when the project has more than one.
  3. The line above the rules says since when they're live. If nothing has been deployed yet, the box is empty and Firebase uses its defaults.

The emulators read rules from your project's firestore.rules and storage.rules files, so for an emulator you edit those files.

Check for errors

Edit the rules in the box (Tab indents), then choose Check. Firebase compiles them and lists any errors and warnings with their line and column; click one to go to that place. Checking saves nothing and changes nothing.

Deploy

  1. Choose Deploy (it turns on once you've changed something) and confirm.
  2. Firebase checks the rules again. If they have an error, nothing changes and the errors are listed.
  3. New rules apply to every app and user of the database or bucket, usually within a minute.

If someone changed the rules in the Firebase console or with the Firebase CLI after you opened them, Firetool doesn't deploy over their change: choose Reload, then make your edit again.

Production, read-only and Pro

Deploying rules is a change, so it follows the same rules as changing data: a project or database marked read-only refuses it, a Viewer role can only read the rules, a production project asks you to type its project ID, and a reason is asked for when your policy says so. Your Google account needs the Firebase Rules Admin role (or Owner or Editor) in the project.

Put the old rules back

Every deploy is recorded in the audit log as rules.deploy, with the rules it replaced. To go back, open that entry in the audit log and choose Put back these rules…: the earlier rules open in the editor, in place of the live ones. Check them, then choose Deploy.

Questions

Does Firetool change my firestore.rules file?

No. Firetool works with the rules that are live in Firebase. If you keep your rules in a file and deploy them with the Firebase CLI, copy your change into that file too, or the next CLI deploy puts the file's version back.

Can I test a request against the rules?

Not yet. Check finds errors in the rules themselves. To try requests, use the Rules Playground in the Firebase console or the emulators.