You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Firestore安全规则限制用户读取items文档的itemName?

我帮你把Firestore数据库结构和满足需求的安全规则都整理清楚啦,具体如下:

Firestore数据库结构与安全规则配置

数据库结构

  • Firestore根目录
    • users(集合)
      • UidOne(文档)
        • userName: "UserOne"
    • items(集合)
      • ItemIdOne(文档)
        • itemName: "ItemOne"
      • ItemIdTwo(文档)
        • itemName: "ItemTwo"

安全规则配置

下面的规则精准实现了禁止所有用户读取items集合内文档的itemName字段的需求,同时配置了users集合的基础权限(仅允许用户访问自己的文档),你可以直接复制使用:

service cloud.firestore {
  match /databases/{database}/documents {
    // 仅允许用户访问自己的用户文档
    match /users/{userId} {
      allow read, write: if request.auth.uid == userId;
    }

    // 控制items集合的字段级访问权限
    match /items/{itemId} {
      // 允许已认证用户读取items文档的非itemName字段
      allow read: if request.auth != null;
      // 完全禁止读取itemName字段
      match /itemName {
        allow read: if false;
      }

      // 默认禁止写入items文档,若有写入需求可自行调整规则
      allow write: if false;
    }
  }
}

内容的提问来源于stack exchange,提问作者Always Learner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 08:32:11