You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Firestore自定义声明配合查询时出现权限错误排查求助

Firebase Firestore权限错误排查:自定义声明验证失败

我在Firebase中有一个notes集合,每个文档都包含一个存储若干用户ID的user_ids数组。我为用户访问令牌设置了格式为nid=true的自定义声明(其中nid为用户应可访问的笔记文档ID),但当我尝试查询相关文档时,却收到了权限错误。

我的查询代码如下:

const notesRef = collection(db, "notes");
const allNotesQuery = query(
  notesRef,
  where("user_ids", "array-contains", user.uid)
);

const noteDocs = await getDocs(allNotesQuery);

我的安全规则最初是这样的:

match /notes/{nid} {
    allow read, write: if request.auth != null && request.auth.token[(nid)] == true
}

我也尝试去掉nid外的括号,修改为以下规则,但仍然无效:

match /notes/{nid} {
    allow read, write: if request.auth != null && request.auth.token[nid] == true
}

请问是否有明显的错误?我检查令牌后确认自定义声明已正确设置,且nid值无误。遗憾的是我无法在开发者控制台中测试自定义声明。


补充说明

针对相关回复的测试情况:以下规则无法生效

allow read, write, list: if  request.auth != null && request.auth.token[nid] in resource.data.user_ids

但以下规则可以正常工作:

allow read, write, list: if  request.auth != null && request.auth.uid in resource.data.user_ids

内容的提问来源于stack exchange,提问作者TommyBs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 16:55:15