You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firestore规则拒绝已认证Flutter用户数据库访问求助

Firebase Firestore规则拒绝已认证用户访问问题

我遇到了Firebase Firestore规则拒绝已认证用户访问数据库的问题,我对Firestore规则不太熟悉,问题应该出在我的配置上。

当前Firestore规则

service cloud.firestore {
  match /databases/{database}/documents {
    match /{userID} {
      allow read: if request.auth.uid == userID;
      allow write: if request.auth.uid == userID
    }
    match /payment_options{
        allow read: if request.auth != null;
      allow write: if false
    }
    match /logs{
        allow read, write: if false
    }
  }
}

注:Firestore数据快照中红线标记的是从Firebase Authentication获取的UserID。

异常信息

我使用Flutter Firestore和Firebase Auth SDK,确保仅在用户登录后才执行数据库读写操作,但仍持续收到以下异常:

Exception:
[cloud_firestore/permission-denied] The caller does not have permission to execute the specified operation.

应用认证监听代码

以下是监听认证状态变化的应用树代码,未登录时跳转至登录页,登录后跳转至主页(Firestore操作仅在主页执行):

class AppTreeWidgetState extends State<AppTreeWidget > {
  @override
  Widget build(BuildContext context) {
    return StreamBuilder(
        stream: Auth.currentUserStream,
        builder: (context, snapshot){
          if(snapshot.hasData) {
            //TODO: Tell firebase to use the Signed in user to authenticate requests
            //to the Firestore Database
            return const MainPage();
          } else {
            return const LoginScreen();
          }
        }
      );
  }
}

疑问

我原本以为Auth和Firestore SDK会互操作,用户通过Firebase Auth SDK登录后,Firestore调用会自动完成认证——我的想法有误吗?是否需要使用登录用户的信息显式授权Firestore数据库调用?

内容的提问来源于stack exchange,提问作者Mike Scriven

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 11:17:10