You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firestore规则安全性咨询:已知他人uid能否绕过规则越权操作?

Firestore规则安全疑问解答

首先贴出你配置的Firestore规则:

rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    
    ///Rules:
    ///Only the owner can modify their stuff under the Users collection     
    match /users/{uid} { 
      allow read, write, delete: if isOwner(uid) && emailVerified();
    }
    
    match /users/{uid}/groups/{groupID} { 
        allow read, write, delete: if isOwner(uid) && emailVerified();
    }
    
    match /users/{uid}/friends/{friendID} { 
        allow read, write, delete: if isOwner(uid) && emailVerified();
    }
    
    match /users/{uid}/notifications/{notifID} { 
        allow read, write, delete: if isOwner(uid) && emailVerified();
    }
    
    /// Functions ///
    function emailVerified() { 
      return request.auth.token.email_verified; ///returns true if email is verified
    }

    function isOwner(uid) {
      return request.auth.uid == uid
    }
  }
}

你的规则逻辑是:仅允许邮箱已验证的用户,读写自己users/{uid}路径下的所有文档及子集合(groups、friends、notifications),核心校验是request.auth.uid与路径中的uid匹配。

针对你提出的安全顾虑:恶意用户无法通过获取到的他人UID,修改对方的Firestore记录,原因如下:

  • isOwner(uid)函数校验的是当前请求发起者的真实UID(来自Firebase Auth签发的认证令牌),和路径中的uid是否一致。用户拿到的他人UID只是一串字符串,无法伪造对应的Auth令牌——Firebase的Auth令牌由服务器签名,客户端无法篡改,恶意用户没法冒充他人的身份发起请求。
  • 假设恶意用户尝试请求修改users/{他人UID}/friends/xxx,此时request.auth.uid是他自己的UID,和路径中的他人UID不匹配,规则会直接拒绝该请求,无论他是否知道对方的UID。

你的规则设计在身份校验层面是安全的,好友UID的泄露不会导致对方数据被非法篡改。

内容的提问来源于stack exchange,提问作者whatwhatwhat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 19:22:48