You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firestore规则使用用户邮箱报错,及自定义用户UID方案咨询

Addressing Your Firestore Security Rule & UID Questions

Can You Set Firebase Auth UID to an Email?

Short answer: No, you can’t directly set a Firebase Auth user’s UID to an email address. Firebase automatically generates unique, immutable UIDs for every user when they sign up, and there’s no way to override this value.

That said, your current approach—using the user’s email as the document ID in the users collection—is totally valid and a common pattern for linking auth users to their Firestore data. It makes it easy to look up user documents directly using the email from the auth token, which is exactly what you’re trying to do.

Fixing the Security Rule Errors

Let’s break down the two issues you’re facing and how to fix them:

1. "Function not found" for exists in userExists

This error usually happens for one of two reasons: either you’re missing the proper path syntax (including the database variable) in your exists call, or you’re not checking if request.auth.token.email exists before using it (which leads to an invalid path if the email is null).

Here’s a corrected version of the userExists function:

function userExists() {
  // First confirm the user is authenticated and has an email in their token
  return request.auth != null 
    && request.auth.token.email != null 
    && exists(/databases/$(database)/documents/users/$(request.auth.token.email));
}

We add guards to ensure request.auth isn’t null and that the email field exists in the auth token before trying to check for the user document. This prevents invalid path errors and ensures the exists function is called correctly.

2. Path Format Error in userData with get

The path error here is similar: if request.auth.token.email is null, the path you’re passing to get is invalid. We need to add checks to only call get when we have a valid email, and handle the null case gracefully.

Try this corrected userData function:

function userData() {
  // Only fetch the user document if auth and email are valid
  if (request.auth != null && request.auth.token.email != null) {
    return get(/databases/$(database)/documents/users/$(request.auth.token.email)).data;
  }
  // Return null if there's no valid user to avoid errors
  return null;
}

By wrapping the get call in an if condition, we ensure we only attempt to fetch the document when we have a valid email. Accessing .data gives you direct access to the document’s fields (like name_first or name_last) which is typically what you need in security rules.

Key Note About request.auth.token.email

You’re right to suspect that request.auth.token.email is optional. Not all authentication methods provide an email—for example, phone sign-in or anonymous auth won’t include this field. That’s why it’s critical to always check if request.auth and request.auth.token.email exist before using them in path references or function calls.

Here’s a full example of how these functions might fit into your overall security rules:

rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    function userExists() {
      return request.auth != null 
        && request.auth.token.email != null 
        && exists(/databases/$(database)/documents/users/$(request.auth.token.email));
    }

    function userData() {
      if (request.auth != null && request.auth.token.email != null) {
        return get(/databases/$(database)/documents/users/$(request.auth.token.email)).data;
      }
      return null;
    }

    // Example: Only allow authenticated users with a valid profile to read companies
    match /companies/{company} {
      allow read: if userExists();
      allow write: if userExists() && userData().role == 'admin';
    }

    // Example: Users can only modify their own profile
    match /users/{userEmail} {
      allow read, write: if request.auth != null && request.auth.token.email == userEmail;
    }

    // Example: Jobs can be read by anyone, but only edited by admins
    match /jobs/{job} {
      allow read: if true;
      allow write: if userExists() && userData().role == 'admin';
    }
  }
}

内容的提问来源于stack exchange,提问作者GoldenJoe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 20:02:43