Firestore Cloud Function HTTP接口403错误:已设权限仍无法让未认证用户访问
问题描述
我希望任何未认证用户都能调用API,根据名字(FN)、姓氏(LN)、出生日期(DOB)返回对应的套餐等级。通过Cloud Function创建了HTTP endpoint,即使在Google Cloud中更新权限允许所有用户作为调用者,仍收到403错误。
函数代码
import * as functions from "firebase-functions"; import * as admin from "firebase-admin"; admin.initializeApp(); export const checkEligibility = functions.https.onRequest(async (req, res) => { const firstName = req.body.firstName; const lastName = req.body.lastName; const dateOfBirth = new Date(req.body.dateOfBirth); console.log(firstName); const eligibleUsersRef = admin.firestore().collection("eligible_people"); const querySnapshot = await eligibleUsersRef .where("firstName", "==", firstName) .where("lastName", "==", lastName) .where("dob", "==", admin.firestore.Timestamp.fromDate(dateOfBirth)) .get(); if (querySnapshot.empty) { // User is not eligible, return an error message res.status(403).send("User is not eligible"); } else { // User is eligible, return the name of the tier const eligibleUser = querySnapshot.docs[0].data(); res.json({tier: eligibleUser.tier}); } });
调用日志
Function execution took 4077 ms, finished with status code: 403
问题排查与解决
你的403错误不是来自Cloud Function的调用权限,而是函数内部逻辑主动返回的——当查询eligible_people集合没有匹配到用户时,代码会返回res.status(403).send("User is not eligible"),这和日志里的403状态完全对应。
可以从以下几个方向排查:
- 核对请求参数:检查
firstName、lastName的拼写、大小写是否和Firestore文档中的字段完全一致,比如文档存的是FirstName而请求传firstName会导致匹配失败。 - 验证日期格式:前端传入的
dateOfBirth字符串需能被new Date()正确解析(推荐用YYYY-MM-DD标准格式),否则转换后的Timestamp会和Firestore中存储的不匹配。 - 检查Firestore数据:直接在Firestore控制台用相同条件查询,确认是否存在匹配文档,同时确保
dob字段是Timestamp类型,而非字符串或其他格式。
如果要区分调用权限错误和业务逻辑错误,可以修改代码返回不同状态码:
if (querySnapshot.empty) { // 用404表示无匹配用户,和权限错误的403区分开 res.status(404).send("User not found in eligible list"); } else { res.json({tier: eligibleUser.tier}); }
内容的提问来源于stack exchange,提问作者PJQuakJag
相关产品推荐
相关产品推荐

