You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firestore规则权限异常:新增数据提示Permission Denied错误

Firestore 新增文档权限拒绝问题解决

问题原因

你当前的规则中使用了 resource.data.author,但创建文档(add操作)时,resource 对象还不存在——它仅指向已存在的文档。这会导致规则判断时无法获取 resource.data.author,直接触发权限拒绝。

修正后的安全规则

将读写权限拆分,针对创建操作使用 request.resource.data.author(即将写入的文档数据)进行校验:

match /mail/{mailId} {
  // 读取:仅允许已认证的文档作者访问
  allow read: if request.auth != null && request.auth.uid == resource.data.author;
  // 创建:仅允许已认证用户创建属于自己的文档(提交的author字段需匹配当前用户uid)
  allow create: if request.auth != null && request.auth.uid == request.resource.data.author;
  // 更新/删除:仅允许文档作者操作(按需保留)
  allow update, delete: if request.auth != null && request.auth.uid == resource.data.author;
}

额外注意事项

调用 this.db.collection('mail').add(data) 时,确保传入的 data 中包含正确的 author 字段,且值等于当前用户的 this.uid,否则即使规则正确,也会因数据不匹配触发权限错误。

内容的提问来源于stack exchange,提问作者Ali Ghassan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 14:10:30