为何Firebase提示已配置安全规则的实时数据库存在全局读写权限?
Firebase实时数据库安全规则误判提示分析
配置Firebase实时数据库安全规则后,曾持续收到安全提示邮件,称任意已认证用户均可读写数据库,但已配置了特定访问规则(如下)。近期未再收到该邮件,确认当前规则已安全,疑问为何会出现误判提示。
{ "rules": { "posts": { ".read": "auth.uid !== null", ".write": "auth.uid !== null && newData.hasChildren(['score', 'quote', 'description', 'source', 'sourceType', 'ownerID', 'ownerImageURl', 'ownerUsername', 'timestamp', 'usersVoted'])", ".indexOn":["sourceType", "ownerID"], "$postID": { ".write": "!data.hasChild('ownerID')", "score": { ".write": "newData.isNumber() && (newData.val() === data.val() + 1 || newData.val() === data.val() - 1) && !root.child('posts').child('$postID').child('usersVoted').hasChild(auth.uid)" }, "usersVoted": { ".write": "!data.hasChild(auth.uid)", "$userID": { ".write": false } } } }, "users": { ".write":"auth.uid !== null && !data.hasChild(auth.uid)", "$userID": { ".read": "auth.uid === $userID", ".write": "auth.uid === $userID" } }, "comments": { ".read": "auth.uid !== null", "$postID": { ".write": "auth.uid !== null", "$commentID": { ".write": false } } } } }
邮件提示的触发逻辑
Firebase的安全规则检测工具会扫描规则中是否存在大范围开放的读写权限,你的规则中存在两处符合该判定的逻辑:
users根节点的写入权限:根级.write规则"auth.uid !== null && !data.hasChild(auth.uid)"允许所有已认证用户创建新的用户条目,没有限制只能创建自己的用户节点,属于“任意已认证用户可写”的范围。comments节点的写入权限:$postID下的.write: "auth.uid !== null"允许任何已认证用户在任意帖子节点下写入数据,虽然$commentID下禁止修改,但用户仍可直接在$postID节点下写入任意内容,同样符合提示中的判定条件。
后续提示停止的原因
Firebase的安全扫描是周期性执行的,后续扫描时可能判定你的规则风险可控:
users节点的根级写入仅允许创建新用户,后续用户只能修改自己的节点,没有全局修改权限;comments节点的写入虽然开放,但$commentID下禁止修改,无法篡改已有评论;- 不存在完全开放的全局规则(如
.read/.write: true),因此停止发送安全提示邮件。
内容的提问来源于stack exchange,提问作者Adam Ashkenazy
相关产品推荐
相关产品推荐

