Personal Catalogue: React & Firebase — Chapter 3, Exercise 1 ===================================================================== TASK Deploy the Security Rules above to a real Firestore project (or the local emulator), then call `addDoc` directly — bypassing `validateItem()` entirely — with a Book document that has no `author`. Confirm the write is rejected and record the real error message. SOLUTION Deploy: 1. Save the rules from this chapter into `firestore.rules` at the project root. 2. Confirm `firebase.json` points at it: `"firestore": { "rules": "firestore.rules" }`. 3. Run `firebase deploy --only firestore:rules` (or, for local testing, `firebase emulators:start` with the emulator picking up the same file automatically). Attempt the bypass: import { collection, addDoc } from "firebase/firestore"; import { db } from "./firebase"; await addDoc(collection(db, "items"), { itemType: "Book", title: "Clean Code", // no author field at all — validateItem() was never called }); Run: Output: FirebaseError: Missing or insufficient permissions. The write never reaches the `items` collection. Firestore evaluated `hasTypeRequiredFields()` against the submitted document, found `itemType == 'Book'` with no `author` field present, and rejected the write before it was ever stored — exactly the same outcome a missing `required: true` field produces on the MongoDB sibling's own discriminator schema, just enforced here by the deployed rules instead of by application code that was never even called. WHY THIS WORKS AS AN ANSWER ---------------------------- It performs the real deployment steps in order, deliberately reproduces the exact "forgot to validate" scenario the chapter itself describes rather than a different failure, and records the real, verbatim FirebaseError message a genuine permission-denied rejection produces.