Firestore父集合规则限制下,如何合法获取子集合?
解决Firestore子集合权限验证问题
问题根源
你的安全规则中,match /mycollection/{documents=**} 会匹配mycollection下的所有文档,但访问子集合mycollection/{id}/subcollection时,规则里的resource.data.author指向的是子集合文档的字段,而非父文档的author。由于子集合文档没有这个字段(或未匹配当前用户UID),导致权限验证失败。
解决方案:修改安全规则关联父文档权限
调整规则,让子集合的访问权限依赖父文档的author字段,通过get()函数读取父文档完成验证:
match /mycollection/{docId} { // 父集合原有规则 allow read, write: if request.auth != null && request.auth.uid == resource.data.author; allow create: if request.auth != null && request.auth.uid == request.resource.data.author; // 子集合权限规则 match /subcollection/{subDocId} { allow read, write: if request.auth != null && get(/databases/$(database)/documents/mycollection/$(docId)).data.author == request.auth.uid; allow create: if request.auth != null && get(/databases/$(database)/documents/mycollection/$(docId)).data.author == request.auth.uid; } }
规则说明
get(/databases/$(database)/documents/mycollection/$(docId)):通过父文档IDdocId获取对应父文档的数据- 验证当前用户UID与父文档的
author字段一致,确保只有父文档的创建者才能访问其子集合
代码无需额外修改
调整规则后,你原来的子集合查询代码可直接正常使用,无需添加额外where条件,权限验证已由规则完成:
const [collection, loading, error] = useCollection( query(collection(db, `mycollection/${id}/subcollection`), orderBy("createdAt", "desc")) )
备选方案(不推荐)
如果子集合文档本身存储了author字段,也可以通过以下方式处理,但安全性低于关联父文档的方案:
- 查询代码增加条件:
const [collection, loading, error] = useCollection( query(collection(db, `mycollection/${id}/subcollection`), where("author", "==", uid), orderBy("createdAt", "desc")) )
- 保留原有规则不变:
match /mycollection/{documents=**} { allow read, write: if request.auth != null && request.auth.uid == resource.data.author; allow create: if request.auth != null && request.auth.uid == request.resource.data.author; }
该方式依赖子文档的author字段未被篡改,存在安全风险。
内容的提问来源于stack exchange,提问作者pewpewlasers
相关产品推荐
相关产品推荐

