aumuaythai / aumt-website-frontend

AUMT club membership website
https://aumt.co.nz
2 stars 1 forks source link

Firestore > Admin document rules #35

Closed mouyang2001 closed 2 years ago

mouyang2001 commented 2 years ago

Admin document collections enabled anyone from writing to it, essentially allowing people to create admin documents with their own id and gain access.

mouyang2001 commented 2 years ago

Solved this by updating rules to stop write admin documents. We'll need a backend to secure this feature.