# Firebase good practices

**URL:** <https://community.thunkable.com/t/firebase-good-practices/1963727>\
**Category:** Questions about Thunkable X\
**Created:** [July 14, 2022, 3:27pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727 "2022-07-14T15:27:29Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [July 14, 2022, 3:27pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/1 "2022-07-14T15:27:29Z")

</div>

hi

in my application which allows to control who frequents the library I associate the name of the user and the link which points to his photo is this harmful ?

---

<div class="post-metadata">

**Author:** ![zander](https://avatars.discourse-cdn.com/v4/letter/z/ecb155/32.png) [@zander](https://community.thunkable.com/u/zander)\
**Post date:** [July 14, 2022, 4:26pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/2 "2022-07-14T16:26:29Z")

</div>

Is this harmfull in what way?

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [July 15, 2022, 5:41am UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/3 "2022-07-15T05:41:24Z")

</div>

hi

could someone not modify the names or the photos even by game?  
i use these rules

 ![Capture d’écran 2022-07-15 à 07.42.06](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/b/b/bb2827bb0ab9d7f4791b01784ba9dce878bc8740.png)

---

<div class="post-metadata">

**Author:** ![zander](https://avatars.discourse-cdn.com/v4/letter/z/ecb155/32.png) [@zander](https://community.thunkable.com/u/zander)\
**Post date:** [July 15, 2022, 12:27pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/4 "2022-07-15T12:27:49Z")

</div>

Are these rules for real time database, firestore?

---

<div class="post-metadata">

**Author:** ![jared](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/jared/32/138473_2.png) [@jared](https://community.thunkable.com/u/jared)\
**Post date:** [July 15, 2022, 1:06pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/5 "2022-07-15T13:06:38Z")

</div>

Setting up Firebase rules can be a bit confusing at times.

Anything in terms or chapters only requires a user to be authenticated but in the user bucket, the current users is must match the bucket key they are trying to read/write to.

I like to store info under private keys in a users bucket like this

 ![image](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/0/a/0add7c8af70f9c703b6e4c4b7e46d6e77348c1db.jpeg)  
 ![image](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/f/7/f7248106e4790db379a942381db69d36a72a6819.jpeg)

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [July 15, 2022, 2:02pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/6 "2022-07-15T14:02:44Z")

</div>

Hi

This rules are for realtime database

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [July 15, 2022, 2:13pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/7 "2022-07-15T14:13:54Z")

</div>

Hi

I agree with you except that connected is not my user bucket it’s the place where I store the temporary info of people who are temporarily in the reading room

---

<div class="post-metadata">

**Author:** ![zander](https://avatars.discourse-cdn.com/v4/letter/z/ecb155/32.png) [@zander](https://community.thunkable.com/u/zander)\
**Post date:** [July 15, 2022, 2:23pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/8 "2022-07-15T14:23:27Z")

</div>

Are they required to read from it? If yes put something like read: auth != null and remove the write ability. Thus your users wont be able to write to the DB only read from it

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [July 15, 2022, 3:27pm UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/9 "2022-07-15T15:27:31Z")

</div>

hi

yes they are obliged to read and I would follow your recommendation delete the writing as if it were the user bucket

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [July 16, 2022, 6:17am UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/10 "2022-07-16T06:17:57Z")

</div>

hi

I don’t know where I was thinking in fact everyone can read the data and each user must be able to “delete his presence” in the reading room

I hope to find more appropriate rules

thanks for your support

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/0/f/0f59f292712368bce16ff80133ae10de8a6f27e8.png) [@system](https://community.thunkable.com/u/system)\
**Post date:** [October 14, 2022, 6:17am UTC](https://community.thunkable.com/t/firebase-good-practices/1963727/11 "2022-10-14T06:17:59Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
