You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firestore规则配置:强制排序与查询字段权限管控需求

Firestore 规则配置方案

问题1:禁止非指定字段的查询条件

需强制按createdAt降序查询,同时拦截所有针对非允许字段(如status)的查询条件。

规则代码

如果完全不允许任何查询条件:

allow list: if 
  request.query.orderBy.createdAt == "DESC" &&
  request.query.where == null;

如果仅允许指定字段的查询条件(例如允许userId):

allow list: if 
  request.query.orderBy.createdAt == "DESC" &&
  (request.query.where == null || 
   request.query.where.keys().every(field => field in ['userId']));

说明

  • 第一行确保查询必须以createdAt降序排序;
  • 第二部分要么没有查询条件,要么所有查询条件的字段都在允许列表内,否则拦截请求。

问题2:强制createdAt排序,仅允许price字段查询

需保证查询必须按createdAt降序排序,仅允许针对price字段添加查询条件,其他字段的查询全部拦截。

规则代码

allow list: if 
  request.query.orderBy.createdAt == "DESC" &&
  (request.query.where == null || 
   request.query.where.keys().every(field => field == 'price'));

说明

  • 强制排序规则不变;
  • 限制查询条件只能是price字段,无论是单个还是多个针对price的条件(比如where('price', '>', 100)或组合多个price条件)都允许,其他字段的条件会被拦截。

内容的提问来源于stack exchange,提问作者Ibrahim Ali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 18:39:52