You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iOS已上架App的Firebase App Check权限验证问题求助

Firebase App Check令牌验证导致Firestore权限问题排查求助

我维护的一款已上架App Store的iOS应用,在排查Firebase App Check令牌验证问题时陷入瓶颈:

  • 当Firestore规则设置为:
    // Allow access to deviceScans only when a valid App Check token is provided
    match /deviceScans/{deviceId} { 
      allow read, write: if true; 
    }
    
    所有数据库操作正常;
  • 但将规则修改为:
    // Allow access to deviceScans only when a valid App Check token is provided
    match /deviceScans/{deviceId} { 
      allow read, write: if request.appCheckToken != null; 
    }
    
    后,就会触发**「Missing or insufficient permissions」**错误。

已完成的配置步骤

  • 在Firebase控制台注册DeviceCheck和App Attest服务,反复核对Key ID、Team ID并正确上传.p8密钥文件;
  • 在App Check模块中找到Cloud Firestore,开启App Check强制验证;
  • 确认Xcode项目中已添加GoogleService-Info.plist,且文件内的Bundle ID和Project ID与Firebase配置完全一致。

测试情况

Xcode控制台显示App Check令牌能正常获取,测试代码如下:

class AppDelegate: NSObject, UIApplicationDelegate {
    func application(_ application: UIApplication,
                     didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey: Any]? = nil) -> Bool {
        FirebaseApp.configure()

        let providerFactory = DeviceCheckProviderFactory()
        AppCheck.setAppCheckProviderFactory(providerFactory)

        // ✅ Debugging App Check Token
        AppCheck.appCheck().token(forcingRefresh: true) { token, error in
            if let error = error {
                print("❌ Error getting App Check token: \(error.localizedDescription)")
            } else if let token = token {
                print("✅ Got App Check token: \(token.token)")
            }
        }

        // ✅ Authenticate and then call Firestore test
        authenticateUserAndTestFirestore()
        testFirestoreAccess()

        return true
    }
}

控制台输出**「✅ Got App Check token」**,但调用Firestore测试函数时:

func testFirestoreAccess() {
    let db = Firestore.firestore()
    let testDocRef = db.collection("deviceScans").document("test-doc")

    testDocRef.getDocument { document, error in
        if let error = error {
            print("❌ Firestore access error: \(error.localizedDescription)")
        } else if let document = document, document.exists {
            print("✅ Firestore document retrieved: \(document.data() ?? [:])")
        } else {
            print("❌ Document does not exist")
        }
    }
}

会输出**「❌ Firestore access error: Missing or insufficient permissions」**。

目前只能暂时将Firestore规则设为allow read, write: if true;维持应用运行,但付费用户依赖这些数据库操作解锁付费功能,急需解决App Check验证问题,恳请提供排查思路。

内容的提问来源于stack exchange,提问作者Isaac Isaiah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 00:17:23