You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase规则与Flutter:SlideShow集合删除权限配置问题求助

解决Firestore删除权限拒绝问题(仅Admin可删除SlideShow文档)

问题根源

你的Firestore规则存在两个关键错误:

  • 删除操作中request.resource.data.Uid无效:删除文档时,request.resource为空(无新写入数据),无法通过它获取Uid。
  • 错误的Uid来源:你需要用当前已认证用户的UID(从Firebase Auth的auth.uid获取),而非从SlideShow文档取值——你明确说明过SlideShow集合里没有Uid字段。

修正后的Firestore规则

替换原SlideShow规则,通过auth.uid获取当前用户ID,再验证user_registration中的用户角色:

match /SlideShow/{SlideShowId} {
  allow read: if true; 
  allow delete, write, update: if exists(/databases/$(database)/documents/user_registration/$(auth.uid)) 
                            && get(/databases/$(database)/documents/user_registration/$(auth.uid)).data.role == 'admin';
}
  • 先通过exists()确保用户在user_registration中有记录,避免因用户不存在触发规则报错
  • 用auth.uid获取当前登录用户的UID,再校验其role是否为admin

Flutter代码注意事项

确保代码中使用的Uid是当前已认证用户的UID:

// 先获取当前登录用户的UID
final String? currentUserUid = FirebaseAuth.instance.currentUser?.uid;
if (currentUserUid == null) {
  print("用户未登录");
  return;
}

// 用currentUserUid查询用户权限
DocumentSnapshot userDoc = await FirebaseFirestore.instance
    .collection('user_registration')
    .doc(currentUserUid) 
    .get();

注:本地权限校验仅为优化用户体验,Firestore安全规则是服务器端强制校验,必须确保规则配置正确。

内容的提问来源于stack exchange,提问作者M Al

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 21:34:52