2
votes

Under my "allUsers" node I'm trying to only allow new data entries to have the following structure:

"allUsers" {
   "$user1: {
     "name": "user1Name"
     "uid": "12345"
   }
}

I don't want any other values besides "name" and "uid". I added a "other": { ".validate": false } rule under each $user, but for some reason the following write is denied:

pic

Can anybody help me understand why the write fails even though I only have a name and uid in the data?

2
Maybe it's because you are denying everything in $other by placing ".validate": false - CraftedGaming
Exactly what @CraftedGaming said, you need to pass all path and subpath validations. - Marc M.
I posted a solution, you also should not be checking for hasChildren() in writes rules as they cascade. Let me know if you need me to elaborate, I'm in a helpful mood 😂. - Marc M.

2 Answers

0
votes

Line 15 in your screenshot passed. It checks for newData.child($user) underneath $user. So, it looks like the write was to: /allUsers/meow/meow/ (note repetition of username), which may be the source of the problem.

That might explain why lines 18 and 19 for name and uid have neither a pass nor a fail, and why line 20 fails, since "meow" is not a valid key underneath $user, even though it is a valid username.

0
votes

You need to pass validation at all paths and subpaths. The variable $other is catching everything, including the paths you intend to allow. Instead write you rule as such.

"$path": {
  ".validate": "$path == 'name' || $path == 'uid'"
},