Firestore过滤查询触发权限不足错误问题排查
问题原因
Firestore安全规则处理集合查询时,不会逐个校验每个文档的resource.data(这种方式效率极低),而是会验证你的查询是否严格匹配规则要求的过滤条件,确保你只能查询到有权限的文档子集。
你当前的规则仅验证单个文档的authorUid是否等于用户UID,但未验证查询本身是否包含该过滤条件,所以Firestore会直接拒绝整个查询——它无法确认你的查询不会试图访问其他用户的文档。
解决方法
修改Firestore规则,添加对查询条件的验证,确保查询必须包含authorUid == request.auth.uid的过滤条件:
match /data/{firstId}/subCol/{secondId}/subSubCol/{thirdId} { allow create: if true; allow read: if resource.data.authorUid == request.auth.uid && request.query.where("authorUid", "==", request.auth.uid); allow write: if resource.data.authorUid == request.auth.uid; allow delete: if resource.data.authorUid == request.auth.uid; }
更简洁的写法(利用权限与查询条件的一致性):
match /data/{firstId}/subCol/{secondId}/subSubCol/{thirdId} { allow create: if true; allow read: if request.auth != null && request.query.where("authorUid", "==", request.auth.uid); allow write: if resource.data.authorUid == request.auth.uid; allow delete: if resource.data.authorUid == request.auth.uid; }
补充说明
- 单个文档读取(比如
getDoc(docRef))不会触发查询条件验证,因为此时resource是明确的单个文档,所以原规则能正常生效。 - 集合查询必须通过规则验证查询条件合法性,这是Firestore的安全机制,防止恶意用户构造查询遍历整个集合。
内容的提问来源于stack exchange,提问作者Thomas Jefferson
相关产品推荐
相关产品推荐

