You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase报错Missing or insufficient permissions 无法加载feed流问题咨询

问题原因

这个FirebaseError: Missing or insufficient permissions是Firestore安全规则拦截了读请求导致的,昨天能正常访问、今天突然失效,90%以上概率是初始测试模式的安全规则过期了。

修复步骤

  1. 登录Firebase控制台,进入对应项目的「Firestore Database」页面,切换到「规则」标签
  2. 检查当前规则的时间限制,默认测试模式规则会设置一个30天后的过期时间,若该日期早于当前日期,读/写请求就会被拦截:
// 过期的测试规则示例
rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    match /{document=**} {
      allow read, write: if request.time < timestamp.date(2024, 3, 15);
    }
  }
}
  1. 替换为适配业务的正式安全规则,以下规则适配社交媒体场景:
rules_version = '2';
service cloud.firestore {
  match /databases/{database}/documents {
    // 用户资料规则:登录用户可读,仅本人可修改
    match /users/{uid} {
      allow read: if request.auth != null;
      allow write: if request.auth != null && request.auth.uid == uid;
    }
    // 帖子规则:登录用户可读,仅发布者可修改
    match /posts/{uid}/userPosts/{postId} {
      allow read: if request.auth != null;
      allow write: if request.auth != null && request.auth.uid == uid;
    }
    // 关注列表规则:登录用户可读,仅本人可修改
    match /following/{uid} {
      allow read: if request.auth != null;
      allow write: if request.auth != null && request.auth.uid == uid;
    }
  }
}
  1. 点击「发布」按钮,等待1-2分钟规则生效后重新测试即可。

额外注意事项

  • 确认当前应用的登录态有效,代码中访问Firestore前没有判断用户登录状态,若用户登录凭证过期、未登录就访问其他用户主页,也会触发权限错误
  • 代码中onFollow方法存在逻辑bug,直接set会覆盖整个关注列表,后续优化建议用arrayUnion方法追加关注用户,避免丢失之前的关注数据

内容的提问来源于stack exchange,提问作者chin14

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 04:36:03