You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Firebase Auth用户添加至GCP IAM访问策略?GCP Storage权限咨询

Great questions! Let's break this down into two clear workflows since you're dealing with integrating Firebase Auth with GCP IAM and Cloud Storage folder-level access.

1. Adding Firebase Auth Users to GCP IAM Access Policies

Firebase Auth users can be treated as valid principals in GCP IAM, but you need to reference them correctly. There are two common ways to identify a Firebase Auth user in IAM:

  • By verified email: If your user signed up with an email/password or a provider that links to a verified email (like Google), use the format user:<user-email> (e.g., user:john.doe@example.com).
  • By Firebase UID: For users without a verified email (like anonymous users or phone-auth users), use the Firebase user's unique ID in the format firebase-auth://users/<firebase-user-uid> (e.g., firebase-auth://users/abc123XYZ789).

How to add them via GCP Console

  • Navigate to the IAM & Admin > IAM page in your GCP project.
  • Click the Add button at the top of the page.
  • In the New members field, paste the user identifier (either the email-based or UID-based string).
  • Select the appropriate IAM role(s) for the user (e.g., roles/storage.objectViewer for read-only access to storage, or a custom role if you need granular permissions).
  • Click Save to apply the policy.

How to add them via gcloud CLI

Run this command, replacing placeholders with your project details and user identifier:

gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
  --member="user:john.doe@example.com" \
  --role="roles/storage.objectUser"

For UID-based users, swap the member value to the firebase-auth://users/<UID> format.

2. Configuring Folder-Level Cloud Storage Permissions for Firebase Auth Users

First, a quick note: Cloud Storage doesn't have actual "folders"—what looks like a folder is just a prefix in object names (e.g., users/abc123/file.txt has the prefix users/abc123/). That said, you can absolutely use IAM to restrict access to these prefixes, effectively creating folder-level permissions.

There are two reliable approaches here:

This method lets you create a single IAM binding that applies to all Firebase Auth users, restricting each to their own prefix based on their Firebase UID.

  • Go to your Cloud Storage bucket's Permissions tab in the GCP Console.
  • Click Add, then enter a principal that covers all Firebase Auth users (or target specific users if needed). For all users, you can use allUsers but pair it with a strict condition, or use a more specific group if you have one.
  • Select a role like roles/storage.objectUser (for read/write) or roles/storage.objectViewer (for read-only).
  • Click Add condition to define the access restriction:
    • Set the condition type to Resource > Name.
    • Use the startsWith operator, and set the value to users/${request.auth.claims.firebase_uid}/.
    • Save the condition, then click Save to apply the policy.

This condition ensures that a user can only access objects whose path starts with users/<their-firebase-uid>/, since the firebase_uid claim is automatically included in their authenticated requests.

Option 2: Direct Prefix-Level IAM Binding (For Individual Users/Prefixes)

If you need to set permissions for a specific user and specific prefix, you can use the gsutil CLI to bind permissions directly to the prefix:

gsutil iam ch user:john.doe@example.com:roles/storage.objectUser gs://YOUR_BUCKET_NAME/users/abc123/

This command grants the user access only to objects under the users/abc123/ prefix in your bucket.

Key Notes

  • Always use Firebase Auth's ID tokens when accessing Cloud Storage (either via the Firebase Storage SDK or by passing the token in API requests) — this ensures IAM can validate the user's identity and apply the correct conditions.
  • For email-based users, make sure their email is verified in Firebase Auth; otherwise, GCP IAM may not recognize the user as a valid principal.
  • Test permissions thoroughly: Use a test user's credentials to attempt accessing objects outside their assigned prefix to confirm restrictions work as expected.

内容的提问来源于stack exchange,提问作者KasparTr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:53:36