Cloud Storage安全规则中firestore.get函数无法正常使用问题排查
问题:Cloud Storage安全规则中Firestore读取验证管理员权限失效
执行文件创建操作时触发权限错误:
You don't have a permission to acces the object
当前使用的Cloud Storage安全规则:
rules_version = '2'; service firebase.storage { match /b/{bucket}/o { match /articles/{allPaths=**} { allow read; allow create: if firestore.get(/databases/{database}/documents/users/$(request.auth.uid)).data.isAdmin == true; allow update; } } }
尝试修改规则后仍无效:
allow create: if firestore.get(/databases/{database}/documents/users/$(request.auth.uid)).isAdmin == true;
排查与解决办法
- 配置Firestore文档读取权限:Cloud Storage规则调用Firestore时,必须确保Firestore安全规则允许Storage服务账号读取
users/{uid}文档。添加以下Firestore规则:
rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /users/{uid} { allow read: if request.auth.uid == uid || request.service == "firebase.storage"; } } }
该规则允许用户自身读取文档,同时授权Cloud Storage服务账号读取用户数据。
- 添加文档存在性校验:若
users/{request.auth.uid}文档不存在,firestore.get()会直接触发权限错误。可以补充存在性判断:
allow create: if exists(/databases/{database}/documents/users/$(request.auth.uid)) && firestore.get(/databases/{database}/documents/users/$(request.auth.uid)).data.isAdmin == true;
确认字段类型匹配:检查Firestore中
isAdmin字段是否为布尔类型(true/false),若为字符串类型("true"/"false")会导致判断逻辑失效。验证请求认证状态:规则依赖
request.auth.uid,需确保请求已通过Firebase认证,未登录用户的request.auth为null,会直接触发权限拒绝。
内容的提问来源于stack exchange,提问作者Dávid Varga
相关产品推荐
相关产品推荐

