My firebase storage rules are
service {
match /{allPaths=**} {
allow read: if request.auth != null;
I am logged out of google and in a chrome browser (incognito mode) and I enter the url I got from (the download url link). I can still download the file. How do I secure the files to only allow downloads if the user has been authenticated by firebase.authentication?
My files are in the root location.
I have also tried
service {
match /b/{bucket}/o {
match /{allPaths=**} {
allow read: if request.auth != null;
There is a revoke download url url in but it doesn't seem to do anything at all.