Firestore v1beta1 REST API读写事务调用序列及权限问题
Let's break down the correct transaction flow and troubleshoot that frustrating 403 error you're hitting.
Correct ReadWrite Transaction Sequence
First, let's confirm the proper step-by-step for a read-write transaction via REST—this aligns with what you tried, but let's formalize it with precise request examples:
Initiate the ReadWrite Transaction
Send a POST to thebeginTransactionendpoint with the read-write option:POST https://firestore.googleapis.com/v1beta1/projects/foo-bar-12345/databases/(default)/documents:beginTransaction Authorization: Bearer YOUR_VALID_ACCESS_TOKEN Content-Type: application/json { "options": { "readWrite": {} } }On success, you'll get a
transactionID string to use for all subsequent requests in this transaction.Read the Target Document (Optional but Recommended)
To ensure you're working with the latest document state, fetch it using the transaction ID:POST https://firestore.googleapis.com/v1beta1/projects/foo-bar-12345/databases/(default)/documents:batchGet Authorization: Bearer YOUR_VALID_ACCESS_TOKEN Content-Type: application/json { "documents": [ "projects/foo-bar-12345/databases/(default)/documents/your-collection/your-doc-id" ], "transaction": "YOUR_TRANSACTION_ID" }Commit the Transaction with Updates
Send your write operation along with the transaction ID to finalize the transaction:POST https://firestore.googleapis.com/v1beta1/projects/foo-bar-12345/databases/(default)/documents:commit Authorization: Bearer YOUR_VALID_ACCESS_TOKEN Content-Type: application/json { "transaction": "YOUR_TRANSACTION_ID", "writes": [ { "update": { "name": "projects/foo-bar-12345/databases/(default)/documents/your-collection/your-doc-id", "fields": { "your-field": { "stringValue": "updated-value" } } } } ] }
Troubleshooting the 403 Permission Error
Since your setup works for single-document operations and read-only transactions, here are the most likely fixes:
1. Switch from API Key to OAuth 2.0 Access Token
API keys work for simple, single-request operations, but read-write transactions require OAuth 2.0 authentication—they maintain state across multiple requests, which API keys don't support.
Generate a valid token using the Google Cloud SDK:
gcloud auth print-access-token
Use this token in the Authorization: Bearer header for all transaction requests—this is almost certainly the fix if you've been using an API key.
2. Verify Test Mode Security Rules Are Active
Double-check your Firestore console to ensure your rules are truly set to test mode and published:
rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /{document=**} { allow read, write: if true; } } }
Sometimes rules fail to publish, or there's an accidental expiration (like a request.time check) that blocks transaction operations.
3. Confirm Project ID Consistency
In your example, you used foo-bR-12345 for the read-only transaction and foo-bar-12345 for the read-write attempt. A mismatched project ID will throw a 403 error—make sure all requests use the exact same project ID.
4. Check IAM Permissions (If Using Service Accounts)
If you're using a service account for authentication, ensure it has the Cloud Datastore User or Firestore Editor role assigned in the Google Cloud IAM console. Even with open security rules, IAM can block transaction operations if the service account lacks the right permissions.
内容的提问来源于stack exchange,提问作者gav

