Firebase

Google's app platform: authentication, Firestore, storage, functions and messaging.

adds it to an existing project · no account needed
Currentas published in v1.5.1

The rule

This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.

Security rules are the security

  • The client talks straight to the database, and the app config is public by design. Rules are the only thing protecting the data.
  • Deny by default; grant narrowly by path and request.auth.uid.
  • Rules live in firestore.rules, in git, deployed with the app. Never edit them in the console — environments drift and the difference surfaces in production.
  • The apiKey in the config is not a secret. Restricting it does not secure anything.

Access

  • One initializeApp for the whole app, in src/services/firebase/.
  • Components call a service; they never import the Firebase SDK directly.
  • Always handle the error branch — permission failures are normal and must be surfaced, not swallowed.

Queries

  • Every real query needs its composite index committed alongside the code.
  • Paginate with limit(). An unbounded collection read is both slow and expensive.
  • Detach listeners on unmount. A leaked listener bills for as long as it lives.

Privileged work

  • Anything the client must not do belongs in a Cloud Function using the Admin SDK, which bypasses rules.
  • The Admin service account key is server-side only. Never in the app.

Never

  • Never leave Firestore in test mode.
  • Never share one Firebase project across environments.
  • Never rely on client-side filtering for access control.

6 formats, one per tool

Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.

.cursor/rules/firebase.mdchand-written
---
description: Firebase conventions
globs: ["src/services/firebase/**", "firestore.rules", "functions/**"]
alwaysApply: false
---

# Firebase

## Security rules are the security

- The client talks straight to the database, and the app config is public by
  design. **Rules are the only thing protecting the data.**
- Deny by default; grant narrowly by path and `request.auth.uid`.
- Rules live in `firestore.rules`, in git, deployed with the app. Never edit
  them in the console — environments drift and the difference surfaces in
  production.
- The `apiKey` in the config is not a secret. Restricting it does not secure
  anything.

## Access

- One `initializeApp` for the whole app, in `src/services/firebase/`.
- Components call a service; they never import the Firebase SDK directly.
- Always handle the error branch — permission failures are normal and must be
  surfaced, not swallowed.

## Queries

- Every real query needs its composite index committed alongside the code.
- Paginate with `limit()`. An unbounded collection read is both slow and
  expensive.
- Detach listeners on unmount. A leaked listener bills for as long as it lives.

## Privileged work

- Anything the client must not do belongs in a Cloud Function using the Admin
  SDK, which bypasses rules.
- The Admin service account key is server-side only. Never in the app.

## Never

- Never leave Firestore in test mode.
- Never share one Firebase project across environments.
- Never rely on client-side filtering for access control.

Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.

What else this module writes

The rule is one file of several. Selecting Firebase contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.

Environment
NEXT_PUBLIC_FIREBASE_API_KEYrequiredIdentifies the project. Public by design.
NEXT_PUBLIC_FIREBASE_AUTH_DOMAINrequiredAuth domain from the console.
NEXT_PUBLIC_FIREBASE_PROJECT_IDrequiredProject id.
NEXT_PUBLIC_FIREBASE_APP_IDrequiredApp id from Project settings.
NEXT_PUBLIC_FIREBASE_STORAGE_BUCKEToptionalStorage bucket, if you use Storage.
FIREBASE_SERVICE_ACCOUNToptionalAdmin SDK credentials JSON. Bypasses all rules — server-side only.
Dependencies
firebase^12.17.0firebase-tools^14.0.0dev
Folders
src/services/firebase/functions/src/
Checklists
checklists/firebase-security.md

Advisory history

Every time this rule turned out to be wrong, and what we did about it.

No corrections yet

This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.

Pro tells you the day a correction lands that affects a repo you actually have.

See what Pro adds →

Rules people add alongside this one

Put this rule in a real project

The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.