You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase Firestore安全规则:文档ID含子串的权限配置问题

Solution for Firebase Security Rule: Check if Document ID Contains User UID

Got it, let's resolve this issue with your Firebase Security Rules for the direct collection. Since .includes() isn't supported in Firebase's rule language, we have two reliable approaches to check if the document ID contains the current user's UID:

If you're constructing your document IDs by joining two UIDs with a consistent separator (like user123_abc456 or uidA-uidB), use the split() method combined with the in operator. This is the most precise method because it avoids false positives from partial UID matches.

Here's the updated rule:

match /direct/{postId} {
  allow read, write: if request.auth.uid in postId.split('_'); // Replace '_' with your actual separator
}

How it works:

  • postId.split('_') breaks the document ID into an array of the two UIDs (e.g., ["user123", "abc456"] for user123_abc456).
  • The in operator checks if the current user's UID exists in that array, ensuring they're one of the two users associated with the document.

2. For Unstructured Document IDs (Fallback)

If your document IDs don't use a fixed separator (not recommended, but sometimes necessary), use the matches() method with a regular expression to check for the UID as a substring:

match /direct/{postId} {
  allow read, write: if postId.matches('.*' + request.auth.uid + '.*');
}

Note:

Be cautious with this approach—if one user's UID is a substring of another (e.g., uid123 and uid1), this rule will incorrectly grant access to the longer UID's document for the shorter UID user. Stick to the separator method whenever possible for security.


内容的提问来源于stack exchange,提问作者user812039

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 18:47:54