You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Firestore安全规则配置:仅认证用户可创建对应authorUid的posts文档

问题排查与修正方案

你现有规则存在两处核心遗漏配置:

  • 未校验用户是否已完成身份认证:未登录用户请求时request.auth值为null,直接访问request.auth.uid会触发规则运行异常,直接返回拒绝结果。
  • 未校验待写入文档是否存在authorUid字段:如果提交的文档数据未携带authorUid字段,读取request.resource.data.authorUid也会触发规则异常,导致校验失败。
修正后可用的安全规则
match /posts/{postId} {
  allow read: if true;
  allow create: if signedInUserIsPostAuthor();
}

function signedInUserIsPostAuthor(){
   // 先校验用户已登录、待写入数据包含authorUid字段,再比对值是否一致
   return request.auth != null 
          && "authorUid" in request.resource.data
          && request.auth.uid == request.resource.data.authorUid;
}

内容的提问来源于stack exchange,提问作者sharath

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 17:42:02