You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase Storage设allow read:if true仍拒读取权限问题求助

问题解决:Firebase Storage listAll 权限被拒但直接访问下载URL正常

核心原因

你的Storage规则仅允许读取/images/{userId}路径下的文件,但listAll是对目录本身的读取操作,当前规则未覆盖目录的list权限,因此触发storage/unauthorized错误。而直接通过下载URL访问图片时,请求的是具体文件路径,规则里的allow read: if true生效,所以能正常加载。

修复后的Storage规则

调整规则,通过递归匹配覆盖目录和所有子文件,或显式允许目录的list操作:

方案1:递归匹配(推荐)

rules_version = '2';
service firebase.storage {
  match /b/{bucket}/o {
    // 递归匹配/images/{userId}下的所有文件和子目录
    match /images/{userId}/{allPaths=**} {
      allow read: if true;
      allow write: if request.auth != null && request.auth.uid == userId;
    }
    match /videos/{userId}/{allPaths=**} {
      allow read: if true;
      allow write: if request.auth != null && request.auth.uid == userId;
    }
  }
}

方案2:显式允许目录list操作

rules_version = '2';
service firebase.storage {
  match /b/{bucket}/o {
    match /images/{userId} {
      // 允许对目录的list操作
      allow list: if true;
      // 允许对目录下文件的读取
      allow read: if true;
      allow write: if request.auth != null && request.auth.uid == userId;
    }
    match /images/{userId}/{file} {
      allow read: if true;
    }
    match /videos/{userId} {
      allow list: if true;
      allow read: if true;
      allow write: if request.auth != null && request.auth.uid == userId;
    }
    match /videos/{userId}/{file} {
      allow read: if true;
    }
  }
}

补充说明

  • Firestore中存储的下载URL指向Storage的具体文件,访问时仅校验文件路径的读取规则,无需目录list权限,因此能正常渲染。
  • listAll属于目录级权限操作,必须在规则中显式允许list动作,或通过递归匹配覆盖目录及所有子资源的权限。

内容的提问来源于stack exchange,提问作者Coolkid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 10:07:35