You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase Database安全规则配置:好友访问私有帖子报$friendId未知错误

Firebase安全规则权限配置修复方案

错误原因

  • 规则内使用的$friendId通配符未在对应路径层级声明,Firebase无法识别该变量
  • 原有判断逻辑存在拼写错误:Firebase Auth的用户ID字段为auth.uid而非auth.id

修正后规则

{
  "rules": {
    "users": {
      "$uid": {
        ".read": "$uid === auth.uid",
        ".write": "$uid === auth.uid",
        "posts": {
          "public": {
            ".read" : "auth != null"
          },
          "private" : {
            ".read": "auth != null && root.child('users').child($uid).child('friends').hasChild(auth.uid)"
          }
        }
      }
    }
  }
}

规则说明

  • 新增auth != null前置校验,避免未登录用户访问时出现异常
  • 使用hasChild(auth.uid)方法直接校验/users/$uid/friends/路径下是否存在当前访问者的用户ID,完全匹配需求
  • 上层$uid节点的读规则已保障作者本人可访问自己的所有内容,私有帖子的子节点规则额外给符合条件的好友开放了读权限,权限逻辑无冲突

内容的提问来源于stack exchange,提问作者VictoriaStudios

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 03:27:03