0Pricing
Firebase Auth & Realtime Database Apps · Lesson

User-Based Access Control

Implement rules to grant or deny read/write access based on authenticated user IDs and roles.

User-Based Access Control is a free Firebase Auth & Realtime Database Apps lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Firebase Auth & Realtime Database Apps learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Control Access by User

Welcome to this lesson! In secure applications, it's crucial to control who can access what data. This is known as User-Based Access Control.

Firebase Realtime Database Security Rules allow you to define precise permissions based on the user who is currently logged in.

Meet the 'auth' Variable

Inside your security rules, Firebase provides a special auth variable. This variable contains information about the currently authenticated user.

  • auth.uid: The unique ID of the logged-in user.
  • auth.token: An object containing custom claims and other token details (e.g., email).

If no user is logged in, auth will be null.

Authenticated Users Only

The simplest form of user-based access is to ensure only authenticated users can read or write any data.

You can achieve this by checking if the auth variable is not null.

{
  "rules": {
    ".read": "auth != null",
    ".write": "auth != null"
  }
}

Users Read Their Own Data

Often, you want users to only read data that belongs to them. Imagine a /users node where each user has a sub-node with their UID.

We can use a wildcard variable ($uid) in the path to match the current user's ID.

{
  "rules": {
    "users": {
      "$uid": {
        ".read": "auth.uid == $uid"
      }
    }
  }
}

Users Write Their Own Data

Similarly, you can restrict write access so users can only modify their own data. This prevents one user from changing another's profile.

The rule is very similar to the read rule, just applied to .write.

{
  "rules": {
    "users": {
      "$uid": {
        ".write": "auth.uid == $uid"
      }
    }
  }
}

Read & Write Your Own Profile

Let's combine the read and write rules. This common pattern allows users full control over their own specific data node, often used for user profiles.

Here, $userId is a placeholder for an actual user's UID.

{
  "rules": {
    "profiles": {
      "$userId": {
        ".read": "auth.uid == $userId",
        ".write": "auth.uid == $userId"
      }
    }
  }
}

Post Ownership Example

Consider a 'posts' section where anyone can read posts, but only the creator can edit or delete their own post.

We assume each post object has an ownerId field. We use data.ownerId to refer to the existing owner ID in the database.

{
  "rules": {
    "posts": {
      "$postId": {
        ".read": "true",
        ".write": "auth.uid == data.ownerId"
      }
    }
  }
}

Validating Data with Auth

Beyond just who can write, you can also validate what data they write. For instance, ensuring that when a user creates an item, they correctly set themselves as the owner.

The newData variable refers to the data being written.

{
  "rules": {
    "items": {
      "$itemId": {
        ".write": "auth != null",
        ".validate": "newData.ownerId == auth.uid"
      }
    }
  }
}

Introducing User Roles

For more complex access, you can define roles like 'admin' or 'moderator'. These roles are often stored as custom claims in the user's authentication token.

You can then check for these roles in your rules using auth.token.

{
  "rules": {
    "adminContent": {
      ".read": "auth.token.isAdmin == true",
      ".write": "auth.token.isAdmin == true"
    }
  }
}

Quick Check on Access

Consider the following Realtime Database Security Rules:

{ "rules": { "messages": { "$messageId": { ".read": "auth.uid == data.senderId", ".write": "auth.uid == data.senderId" } } } }

If user "user123" is authenticated and tries to read a message where data.senderId is "user456", will they succeed?

Recap: User Access Rules

You've learned how to implement powerful user-based access control in Firebase Realtime Database Security Rules!

  • The auth variable provides current user details.
  • You can restrict access to authenticated users (auth != null).
  • Users can be granted read/write access to their own specific data using auth.uid == $uid.
  • You can validate incoming data using newData and auth.uid.
  • Roles can be used to grant access to specific user groups.

Next, explore how to validate the data itself!

Frequently asked questions

Is the “User-Based Access Control” lesson free?

Yes — the full text of “User-Based Access Control” is free to read here on the web, and the Firebase Auth & Realtime Database Apps course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Firebase Auth & Realtime Database Apps course, upgrade to CoddyKit PRO.

What will I learn in “User-Based Access Control”?

Implement rules to grant or deny read/write access based on authenticated user IDs and roles. You practise Firebase Auth & Realtime Database Apps with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Firebase Auth & Realtime Database Apps?

No prior experience is required. Firebase Auth & Realtime Database Apps on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “User-Based Access Control” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Firebase Auth & Realtime Database Apps lesson?

Yes. Every Firebase Auth & Realtime Database Apps lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Understanding Security Rules Syntax
  2. User-Based Access Control
  3. Validating Data with Rules
  4. Testing & Debugging Security Rules
← Back to Firebase Auth & Realtime Database Apps