Firestore规则权限异常:新增数据提示Permission Denied错误
Firestore 新增文档权限拒绝问题解决
问题原因
你当前的规则中使用了 resource.data.author,但创建文档(add操作)时,resource 对象还不存在——它仅指向已存在的文档。这会导致规则判断时无法获取 resource.data.author,直接触发权限拒绝。
修正后的安全规则
将读写权限拆分,针对创建操作使用 request.resource.data.author(即将写入的文档数据)进行校验:
match /mail/{mailId} { // 读取:仅允许已认证的文档作者访问 allow read: if request.auth != null && request.auth.uid == resource.data.author; // 创建:仅允许已认证用户创建属于自己的文档(提交的author字段需匹配当前用户uid) allow create: if request.auth != null && request.auth.uid == request.resource.data.author; // 更新/删除:仅允许文档作者操作(按需保留) allow update, delete: if request.auth != null && request.auth.uid == resource.data.author; }
额外注意事项
调用 this.db.collection('mail').add(data) 时,确保传入的 data 中包含正确的 author 字段,且值等于当前用户的 this.uid,否则即使规则正确,也会因数据不匹配触发权限错误。
内容的提问来源于stack exchange,提问作者Ali Ghassan
相关产品推荐
相关产品推荐

