Firebase security rules for TripWeave (my own app). I wrote server-side rules for Cloud Firestore and the Realtime Database that check every write: field names, types, ranges and ownership. Only members can read a trip, joining can only add yourself, only the creator can start...