【问题标题】:Firebase database write permission rules using newValue and data to access existing dataFirebase 数据库写入权限规则使用 newValue 和 data 访问现有数据
【发布时间】:2017-05-25 16:05:49
【问题描述】:

我在 Firebase 中编写规则时遇到问题

我的数据结构是这样的:

"permisos": {
   "owners" : {
      "$userId" : {
          "$client" : true
       }
   }
 }
 "data" : {
    "promotions" : {
       "$promotion_key" : {
           "property1:" : "some value"
           "client" : "client name"
       }
    }
  }

我正在编写要在“data/promotions/$promotion_key”下写入的规则。我想验证当前用户是否有权使用相应的属性客户端值(插入、更新或删除)写入促销条目。到目前为止,我已经尝试了以下规则:

".write" : "root.child('permisos').child('owners').child(auth.uid).child(newData.child('client').val()).exists() || "root.child('permisos').child('owners').child(auth.uid).child(data.child('client').val()).exists()"

规则的第一部分检查插入,第二部分检查删除尝试。

根据 OR 子句的顺序,我可以插入但在尝试删除时失败(权限被拒绝),反之亦然。似乎它没有评估 || 的两个部分。

我已经尝试了 or 个人的每个子句,它们都可以正常工作。

【问题讨论】:

    标签: firebase firebase-realtime-database firebase-security rules


    【解决方案1】:

    newData 将不存在用于删除,因此您需要提防这种情况以避免规则的第一部分失败:

    (
      newData.exists() &&
      root.child('permisos').child('owners').child(auth.uid).child(newData.child('client').val()).exists()
    ) ||
    root.child('permisos').child('owners').child(auth.uid).child(data.child('client').val()).exists()
    

    【讨论】:

      猜你喜欢
      • 2017-06-08
      • 1970-01-01
      • 2018-07-22
      • 1970-01-01
      • 1970-01-01
      • 2020-09-26
      • 2018-12-22
      • 2019-10-11
      • 1970-01-01
      相关资源
      最近更新 更多