I have the following rule in my Firebase Storage. But still, I am able to access the images when I have the link that starts with "https://firebasestorage.googleapis.com/", even when I am not authorized/authenticated. I have a folder called toyCarImages and I want to allow writes from the public and reads from only authorized accounts
rules_version = '2';
service firebase.storage {
match /b/{bucket}/o {
match /{allPaths=**} {
// allow read, write: if request.auth == null;
allow read: if request.auth != null;
allow write: if request.resource.size < 5 * 1024 * 1024
&& request.resource.contentType.matches('image/.*');
}
}
}
How can I fix this issue? I am using getDownloadUrl() method in my application. How secure is it when using getDownloadUrl()?
Thanks in advance