# Do we need to change Firebase rules after 30 days?

**URL:** <https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894>\
**Category:** Questions about Thunkable X\
**Created:** [June 24, 2021, 2:37am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894 "2021-06-24T02:37:56Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 2:37am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/1 "2021-06-24T02:37:57Z")

</div>

Do we have to change our firebase project after every 30 days. This is not clearly mentioned in the documentation.

---

<div class="post-metadata">

**Author:** ![tatiang](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/tatiang/32/55482_2.png) [@tatiang](https://community.thunkable.com/u/tatiang)\
**Post date:** [June 24, 2021, 2:58am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/2 "2021-06-24T02:58:00Z")

</div>

Can you provide a link to whatever made you ask this?

---

<div class="post-metadata">

**Author:** ![sketch](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/sketch/32/109058_2.png) [@sketch](https://community.thunkable.com/u/sketch)\
**Post date:** [June 24, 2021, 5:13am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/3 "2021-06-24T05:13:55Z")

</div>

Not that i know.  
I’ve never touched it after creating and connecting

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 6:09am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/4 "2021-06-24T06:09:09Z")

</div>

![image](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/5/a/5aaeb45ecf6c017f52983e11ba7511bdd82ae141.png)  
Do We have to use test mode or locked mode ?

> **[Realtime DB by Firebase](https://docs.thunkable.com/realtime-db)**

---

<div class="post-metadata">

**Author:** ![sketch](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/sketch/32/109058_2.png) [@sketch](https://community.thunkable.com/u/sketch)\
**Post date:** [June 24, 2021, 6:32am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/5 "2021-06-24T06:32:53Z")

</div>

Locked

---

<div class="post-metadata">

**Author:** ![tatiang](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/tatiang/32/55482_2.png) [@tatiang](https://community.thunkable.com/u/tatiang)\
**Post date:** [June 24, 2021, 6:59am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/6 "2021-06-24T06:59:01Z")

</div>

This has nothing to do with Thunkable. Firebase is just letting you know that if you don’t set up secure rules within 30 days, they will lock your database.

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 7:01am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/7 "2021-06-24T07:01:08Z")

</div>

So you mean we have to start in locked mode and then change the rules to true( or can we do that in test mode too?)

---

<div class="post-metadata">

**Author:** ![sketch](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/sketch/32/109058_2.png) [@sketch](https://community.thunkable.com/u/sketch)\
**Post date:** [June 24, 2021, 7:33am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/9 "2021-06-24T07:33:54Z")

</div>

> [@overturner](#):
>
> So you mean we have to start in locked mode and then change the rules to true

Yes

> [@overturner](#):
>
> or can we do that in test mode too?

No

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [June 24, 2021, 11:32am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/10 "2021-06-24T11:32:26Z")

</div>

@overturner  
I have my database in test mode for over a year now. I just changed the database rules and made it not date bound instead of 30 days however, my production database has different rules

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 11:35am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/11 "2021-06-24T11:35:41Z")

</div>

> [@muneer](#):
>
> database rules and made it not date bound instead of 30 days

This sentence is a bit confusing for me. 😰

> [@muneer](#):
>
> my production database has different rules

What do you mean by production db?

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [June 24, 2021, 11:59am UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/12 "2021-06-24T11:59:27Z")

</div>

I have my test DB and my production DB (Firebase calls them projects). When working on a project, it is connected to the test environment with minimum rules but when I move it to production then permission rules are different.

This is in my test DB

```auto
{
  "rules": {
    ".read": "true", // 2021-2-4
    ".write": "true", // 2021-2-4
  }
}

```

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 1:29pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/13 "2021-06-24T13:29:45Z")

</div>

And in Production Db You Have removed the dates And you have started in test mode. Am I Right @muneer ?

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [June 24, 2021, 1:45pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/14 "2021-06-24T13:45:55Z")

</div>

In production, you use `Locked mode`

This is a sample rule

```auto
{
  "rules": {
    "users": {
      "$uid": {
        ".read": "$uid === auth.uid",
        ".write": "$uid === auth.uid"
      }
    }
  }
}

```

Only authenticated users can access the data that is located under their own userID.

The simplest is to use this

```auto
{
 “rules”: {
 “.read”: “auth != null”,
 “.write”: “auth != null”
 }
}

```

Which means only authenticated users can perform CRUD.

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 1:47pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/15 "2021-06-24T13:47:59Z")

</div>

Thanks @muneer for the reply  
The first screen in my app in login , so whoever accesses the data has to login.  
So In the End , I Can Add A Test mode And Change the rules to true am i right?

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 1:48pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/16 "2021-06-24T13:48:24Z")

</div>

or do i have to change it to auth != null

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [June 24, 2021, 1:55pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/17 "2021-06-24T13:55:09Z")

</div>

> [@overturner](#):
>
> auth != null

I would use this. Because if you just set it to TRUE then if there is a bug in the **Login Screen** that allows the user to go to the next screen the database will not allow data retrieval or update.

The way I do is to start with just `True` for both read and write to ease the work. When the first demo is ready I switch to validating user IDs to prevent accidental data changes from unauthenticated users.

> [@muneer](#):
>
> ```auto
> "$uid": {
> ".read": "$uid === auth.uid",
> ".write": "$uid === auth.uid"
> 
> ```

With this option, the application will only change data that is located under the User ID key in the database. Preventing accidental change to other users’ data.

---

<div class="post-metadata">

**Author:** ![overturner](https://avatars.discourse-cdn.com/v4/letter/o/53a042/32.png) [@overturner](https://community.thunkable.com/u/overturner)\
**Post date:** [June 24, 2021, 1:59pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/18 "2021-06-24T13:59:59Z")

</div>

Thank you @muneer for your time. I will implement this

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [June 24, 2021, 2:08pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/19 "2021-06-24T14:08:17Z")

</div>

You are welcome. However, when implementing such rules you need to review your project use case.

If for example you are developing a forum such as this community then you will need an admin or a group leader who is allowed to change or delete other users’ posts then the rules to restrict access to userID only will not help for the project and you will need a rule that will allow the leader to change the posts of other.

Hope that clarifies it.

---

<div class="post-metadata">

**Author:** ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)\
**Post date:** [November 8, 2024, 1:20pm UTC](https://community.thunkable.com/t/do-we-need-to-change-firebase-rules-after-30-days/1360894/20 "2024-11-08T13:20:09Z")

</div>


