You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Storage安全规则中firestore.get函数无法正常使用问题排查

问题:Cloud Storage安全规则中Firestore读取验证管理员权限失效

执行文件创建操作时触发权限错误:

You don't have a permission to acces the object

当前使用的Cloud Storage安全规则:

rules_version = '2';
service firebase.storage {
  match /b/{bucket}/o {

      match /articles/{allPaths=**} {
        allow read;
        allow create: if firestore.get(/databases/{database}/documents/users/$(request.auth.uid)).data.isAdmin == true;
        allow update;
    }
  }
}

尝试修改规则后仍无效:

allow create: if firestore.get(/databases/{database}/documents/users/$(request.auth.uid)).isAdmin == true;
排查与解决办法
  • 配置Firestore文档读取权限:Cloud Storage规则调用Firestore时,必须确保Firestore安全规则允许Storage服务账号读取users/{uid}文档。添加以下Firestore规则:
rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    match /users/{uid} {
      allow read: if request.auth.uid == uid || request.service == "firebase.storage";
    }
  }
}

该规则允许用户自身读取文档,同时授权Cloud Storage服务账号读取用户数据。

  • 添加文档存在性校验:若users/{request.auth.uid}文档不存在,firestore.get()会直接触发权限错误。可以补充存在性判断:
allow create: if exists(/databases/{database}/documents/users/$(request.auth.uid)) && 
              firestore.get(/databases/{database}/documents/users/$(request.auth.uid)).data.isAdmin == true;
  • 确认字段类型匹配:检查Firestore中isAdmin字段是否为布尔类型(true/false),若为字符串类型("true"/"false")会导致判断逻辑失效。

  • 验证请求认证状态:规则依赖request.auth.uid,需确保请求已通过Firebase认证,未登录用户的request.auth为null,会直接触发权限拒绝。

内容的提问来源于stack exchange,提问作者Dávid Varga

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 13:15:52