如何将Firebase Auth用户添加至GCP IAM访问策略?GCP Storage权限咨询
Great questions! Let's break this down into two clear workflows since you're dealing with integrating Firebase Auth with GCP IAM and Cloud Storage folder-level access.
Firebase Auth users can be treated as valid principals in GCP IAM, but you need to reference them correctly. There are two common ways to identify a Firebase Auth user in IAM:
- By verified email: If your user signed up with an email/password or a provider that links to a verified email (like Google), use the format
user:<user-email>(e.g.,user:john.doe@example.com). - By Firebase UID: For users without a verified email (like anonymous users or phone-auth users), use the Firebase user's unique ID in the format
firebase-auth://users/<firebase-user-uid>(e.g.,firebase-auth://users/abc123XYZ789).
How to add them via GCP Console
- Navigate to the IAM & Admin > IAM page in your GCP project.
- Click the Add button at the top of the page.
- In the New members field, paste the user identifier (either the email-based or UID-based string).
- Select the appropriate IAM role(s) for the user (e.g.,
roles/storage.objectViewerfor read-only access to storage, or a custom role if you need granular permissions). - Click Save to apply the policy.
How to add them via gcloud CLI
Run this command, replacing placeholders with your project details and user identifier:
gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \ --member="user:john.doe@example.com" \ --role="roles/storage.objectUser"
For UID-based users, swap the member value to the firebase-auth://users/<UID> format.
First, a quick note: Cloud Storage doesn't have actual "folders"—what looks like a folder is just a prefix in object names (e.g., users/abc123/file.txt has the prefix users/abc123/). That said, you can absolutely use IAM to restrict access to these prefixes, effectively creating folder-level permissions.
There are two reliable approaches here:
Option 1: Use IAM Conditions (Recommended for Scalable, Per-User Access)
This method lets you create a single IAM binding that applies to all Firebase Auth users, restricting each to their own prefix based on their Firebase UID.
- Go to your Cloud Storage bucket's Permissions tab in the GCP Console.
- Click Add, then enter a principal that covers all Firebase Auth users (or target specific users if needed). For all users, you can use
allUsersbut pair it with a strict condition, or use a more specific group if you have one. - Select a role like
roles/storage.objectUser(for read/write) orroles/storage.objectViewer(for read-only). - Click Add condition to define the access restriction:
- Set the condition type to
Resource>Name. - Use the
startsWithoperator, and set the value tousers/${request.auth.claims.firebase_uid}/. - Save the condition, then click Save to apply the policy.
- Set the condition type to
This condition ensures that a user can only access objects whose path starts with users/<their-firebase-uid>/, since the firebase_uid claim is automatically included in their authenticated requests.
Option 2: Direct Prefix-Level IAM Binding (For Individual Users/Prefixes)
If you need to set permissions for a specific user and specific prefix, you can use the gsutil CLI to bind permissions directly to the prefix:
gsutil iam ch user:john.doe@example.com:roles/storage.objectUser gs://YOUR_BUCKET_NAME/users/abc123/
This command grants the user access only to objects under the users/abc123/ prefix in your bucket.
Key Notes
- Always use Firebase Auth's ID tokens when accessing Cloud Storage (either via the Firebase Storage SDK or by passing the token in API requests) — this ensures IAM can validate the user's identity and apply the correct conditions.
- For email-based users, make sure their email is verified in Firebase Auth; otherwise, GCP IAM may not recognize the user as a valid principal.
- Test permissions thoroughly: Use a test user's credentials to attempt accessing objects outside their assigned prefix to confirm restrictions work as expected.
内容的提问来源于stack exchange,提问作者KasparTr

