Firebase Firestore规则权限异常:无法读取指定集合
Firestore权限拒绝问题排查
核心问题:变量名拼写错误
你的规则中把路径匹配定义的{accountId}错写成了acountId(缺少字母c),导致规则无法正确关联路径中的账户ID参数,这是权限拒绝的直接原因。
修正后的规则:
rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /user_data/{accountId}/nfts { allow read: if request.auth.token.email[0:42].lower() == accountId.lower(); allow write: if false; } } }
优化建议:更可靠的邮箱前缀提取
依赖固定长度切片提取邮箱前缀的方式容错性差,若后续邮箱前缀长度变化会再次触发问题,建议改用split方法提取@之前的部分:
allow read: if request.auth.token.email.split('@')[0].lower() == accountId.lower();
验证步骤
- 修正拼写错误后重新发布Firestore规则
- 执行原读取代码测试权限是否正常
- 若仍有异常,使用Firebase控制台的规则模拟器:输入目标路径、用户邮箱,模拟读取操作,查看规则评估日志定位具体问题
内容的提问来源于stack exchange,提问作者GGizmos
相关产品推荐
相关产品推荐

