如何实现应用内用户仅管理自身内容?餐厅应用API选型咨询
实现用户仅管理自身创建内容的方案
核心逻辑
不管用什么工具,核心都是给每条内容绑定创建者的用户ID,然后在数据查询、修改、删除的环节,强制校验「操作内容的用户ID必须和创建者ID匹配」,从数据存储和权限规则两层锁死访问范围。
用Firebase实现的方案
Firebase的Auth认证+Firestore数据库组合刚好适配这个需求:
- 先通过Firebase Auth完成商家账号的注册登录,每个商家会拿到唯一的
uid。 - 在Firestore里设计数据结构:比如
restaurants集合里的每个餐厅文档,都加一个ownerUid字段存创建者的uid;dishes菜品文档也要关联对应的restaurantId和ownerUid。 - 用Firestore安全规则做权限拦截,示例规则如下:
rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { // 商家只能读写自己创建的餐厅 match /restaurants/{restaurant} { allow read: if request.auth != null && request.auth.uid == resource.data.ownerUid; allow create: if request.auth != null && request.resource.data.ownerUid == request.auth.uid; allow update, delete: if request.auth != null && resource.data.ownerUid == request.auth.uid; } // 菜品权限同理,绑定商家的uid match /dishes/{dish} { allow read, create, update, delete: if request.auth != null && request.resource.data.ownerUid == request.auth.uid; } } } - 前端调用SDK时,自动带上当前用户的
uid过滤数据,比如获取自己的餐厅:const user = firebase.auth().currentUser; const myRestaurants = await firebase.firestore().collection('restaurants') .where('ownerUid', '==', user.uid) .get();
用Sanity实现的方案
Sanity的用户系统+自定义权限规则也能搞定:
- 用Sanity自带的用户管理(或集成第三方认证)给商家创建账号,每个商家有唯一用户ID。
- 在Sanity的Schema里给
restaurant、dish这类文档类型添加owner字段,类型设为指向user文档的引用,或者直接存用户ID字符串。 - 配置Sanity的权限规则(在
sanity.config.ts或专门权限文件中),示例代码:export default defineConfig({ // 其他配置项 permissions: [ { role: 'editor', // 给商家分配editor角色 filter: ({ userId }) => `owner._ref == "user.${userId}"`, // 仅允许操作自己创建的内容 actions: ['read', 'create', 'update', 'delete'] } ] }); - 前端通过Sanity Client查询时,过滤出当前用户的内容:
const currentUserId = '当前登录用户ID'; const myRestaurants = await client.fetch(`*[_type == "restaurant" && owner._ref == "user.${currentUserId}"]`);
选择建议
- 如果你的应用还需要用户认证、实时数据同步、推送通知等配套功能,Firebase的一站式方案更省心,不用额外搭服务。
- 如果你的内容需要灵活的结构化编辑、富文本管理,Sanity作为专业内容管理平台,在内容建模和编辑体验上更有优势。
内容的提问来源于stack exchange,提问作者Sava Catalin
相关产品推荐
相关产品推荐

