You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase安全规则配置问题求助:支出追踪应用权限设置导致部分功能失效

分析与修正你的Firebase数据库规则问题

看起来你的核心问题出在规则逻辑与需求不匹配,以及部分节点的权限设置完全违背了应用功能的基本逻辑,导致功能失效。我先拆解你的核心需求,再逐一修正规则:

你的核心权限需求回顾

  • 公开访问节点(所有用户可读):fullname、username、partner
  • 仅所有者/伙伴可访问节点:expenses、categories、receipts
  • 仅所有者可访问节点:subscriptions、uid、theme
  • 所有认证用户可访问节点:settings、bankingApps、loans、notifications

当前规则的致命问题

  1. 公开节点权限逻辑错误:
    你给partner、fullname、username设置的规则是.read": "auth.uid != $uid",这意味着账户所有者自己都无法读取这些节点——比如用户打开自己的个人主页时,连自己的名字都加载不出来,这肯定会导致功能崩溃。

  2. 伙伴请求节点权限完全错误:
    partnerRequest的规则同样是auth.uid != $uid,这会导致用户自己无法查看或处理别人发来的伙伴请求,完全违背了功能逻辑。

  3. 父节点权限缺失:
    /users/$uid没有设置默认权限,Firebase规则默认是拒绝所有访问。如果你的应用中有读取整个用户节点的操作(比如一次性加载用户基本信息),会直接被拦截。

修正后的规则方案

我调整了所有逻辑冲突的部分,同时优化了规则的可读性:

{
  "rules": {
    "users": {
      "$uid": {
        // 定义复用变量,减少重复代码
        "isOwnerOrPartner": "auth.uid === $uid || root.child('users').child($uid).child('partner').val() === auth.uid",
        // 默认拒绝父节点的读写,避免误操作读取整个用户数据
        ".read": false,
        ".write": false,

        // 仅所有者/伙伴可访问的节点
        "expenses": {
          ".read": "$isOwnerOrPartner",
          ".write": "$isOwnerOrPartner"
        },
        "categories": {
          ".read": "$isOwnerOrPartner",
          ".write": "$isOwnerOrPartner"
        },
        "receipts": {
          ".read": "$isOwnerOrPartner",
          ".write": "$isOwnerOrPartner"
        },

        // 所有认证用户可访问的节点
        "settings": {
          ".read": "auth.uid != null",
          ".write": "auth.uid != null"
        },
        "bankingApps": {
          ".read": "auth.uid != null",
          ".write": "auth.uid != null"
        },
        "loans": {
          ".read": "auth.uid != null",
          ".write": "auth.uid != null"
        },
        "notifications": {
          ".read": "auth.uid != null",
          ".write": "auth.uid != null"
        },

        // 仅所有者可访问的节点
        "subscriptions": {
          ".read": "auth.uid === $uid",
          ".write": "auth.uid === $uid"
        },
        "uid": {
          ".read": "auth.uid === $uid",
          ".write": "auth.uid === $uid"
        },
        "theme": {
          ".read": "auth.uid === $uid",
          ".write": "auth.uid === $uid"
        },

        // 公开访问节点(所有用户可读,仅所有者可写)
        "partner": {
          ".read": true, // 若仅允许认证用户访问,改为"auth.uid != null"
          ".write": "auth.uid === $uid"
        },
        "fullname": {
          ".read": true,
          ".write": "auth.uid === $uid"
        },
        "username": {
          ".read": true,
          ".write": "auth.uid === $uid"
        },

        // 伙伴请求节点修正:允许所有者和请求发起方访问
        "partnerRequest": {
          ".read": "auth.uid === $uid || root.child('users').child($uid).child('partnerRequest').val() === auth.uid",
          ".write": "auth.uid === $uid || root.child('users').child($uid).child('partnerRequest').val() === auth.uid"
        }
      }
    }
  }
}

关键修正说明

  • 给公开节点设置了".read": true,确保所有用户(包括所有者自己)都能读取这些信息;写入权限限制为仅所有者,符合数据归属逻辑。
  • 修复了partnerRequest的权限,让用户能正常处理伙伴请求。
  • 使用isOwnerOrPartner变量复用权限逻辑,减少重复代码,降低出错概率。
  • 默认拒绝父节点的读写,避免应用误操作读取整个用户数据,提升安全性。

测试建议

使用Firebase控制台的规则模拟器,分别模拟以下身份测试每个节点的读写权限:

  1. 账户所有者
  2. 已关联的伙伴用户
  3. 普通认证用户
  4. 未认证用户(如果允许公开访问)

通过模拟器可以精准定位哪个节点的权限仍有问题,快速排查功能失效的具体原因。

内容的提问来源于stack exchange,提问作者Danish Ajaib

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 17:48:10