You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Firebase不同集合设置差异化安全规则:实现未认证仅读取language集合、认证后读取Users集合

Firebase Security Rules for Authenticated/Unauthenticated Access Control

Got it, let's put together the Firebase security rules that fit your exact requirements. Here's a clear, tested setup along with explanations so you understand how each part works:

Complete Rule Configuration

rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    // Allow unauthenticated users to read the 'language' collection
    match /language/{document} {
      allow read: if true;
      allow write: if false; // Block all writes to this collection for everyone
    }

    // Restrict 'Users' collection access to authenticated users only
    match /Users/{document} {
      allow read: if request.auth != null;
      allow write: if request.auth != null; // Adjust this if you need stricter write controls
    }

    // Default rule: Block access to all other collections (best practice)
    match /{document=**} {
      allow read, write: if false;
    }
  }
}

Breakdown of Each Rule

  • rules_version = '2';: This is required to use the latest version of Firebase's security rules, which includes all modern features and syntax.
  • language Collection:
    • allow read: if true;: Grants read access to all users, including those who haven't authenticated yet.
    • allow write: if false;: Explicitly blocks any write operations (create, update, delete) on this collection. This is optional but highly recommended to prevent unauthenticated users from modifying your language data.
  • Users Collection:
    • allow read: if request.auth != null;: Only lets users who have successfully signed in (i.e., request.auth exists) read documents in this collection.
    • allow write: if request.auth != null;: Currently allows any authenticated user to write to the collection. If you need tighter control (like only letting users modify their own document), you can update this to:
      allow write: if request.auth.uid == document.id;
      
      This ensures users can only edit the document that matches their unique user ID.
  • Default Catch-All Rule: The match /{document=**} rule blocks access to every other collection not explicitly defined above. This is a critical best practice to avoid accidentally exposing sensitive data.

Testing the Rules

Don't forget to validate these rules using Firebase Console's Rule Simulator:

  1. Go to your Firebase project → Firestore Database → Rules tab.
  2. Use the simulator to test two scenarios:
    • An unauthenticated request to read language (should succeed)
    • An unauthenticated request to read Users (should fail)
    • An authenticated request to read Users (should succeed)

This ensures your rules behave exactly as expected before deploying them.

内容的提问来源于stack exchange,提问作者Abhay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 03:47:50