You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firestore新集合mailingList开放写入权限被拦截问题咨询

你的安全规则存在集合名拼写错误:你要配置的目标集合是mailingList,但规则中匹配的集合名写为malingList(缺少字母i),导致写入请求没有匹配到对应的放行规则,被安全规则默认拦截。

修正后的完整规则如下:

service cloud.firestore {
  match /databases/{database}/documents {
    
    match /mailingList/{doc} {
        allow write: if true; 
    }
    match /metadata/{doc} {
        allow read: if request.auth.uid != null; 
    }
    match /taken/{doc}{
      allow read: if request.auth.uid != null;
      allow read,write: if
          request.auth.uid == doc;
    }
  }
}

额外注意事项:

  • 当前配置仅给mailingList放行写入权限,如果你需要开放读取权限,可以在对应匹配块中补充allow read的相关规则。
  • 生产环境不建议直接使用allow write: if true的配置,该规则会允许任意用户无限制写入集合,容易被恶意滥用造成资源损耗,建议补充业务校验逻辑限制写入行为。

内容的提问来源于stack exchange,提问作者Eight Rice

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 10:24:07