【问题标题】:permission denied on firebase databasefirebase 数据库的权限被拒绝
【发布时间】:2019-11-15 21:58:01
【问题描述】:

我正在尝试使用 android studio 在草稿聊天应用程序中创建注册活动。首先,我检查表单的所有字段是否都已填写,然后我想检查用户所需的用户名是否已经在数据库中,并通过消息拒绝该请求。

这是我设法组装在一起的函数:

private void checkifUsernameExists(final String username, final String email, final String password) {
        Query usernameQuery = FirebaseDatabase.getInstance().getReference().child("users").orderByChild("username").equalTo(username);
        usernameQuery.addListenerForSingleValueEvent(new ValueEventListener() {
            @Override
            public void onDataChange(@NonNull DataSnapshot dataSnapshot) {
                if (dataSnapshot.exists()) {
                    Toast.makeText(registerActivity.this, "Username already exists", Toast.LENGTH_LONG).show();
                } else {
                    message.setTitle("Registering user");
                    message.setMessage("Pleases wait while we create your account");
                    message.setCanceledOnTouchOutside(false);
                    message.show();
                    registerUser(username, email, password);
                }
            }

            @Override
            public void onCancelled(@NonNull DatabaseError databaseError) {

            }
        });
    }

当我点击注册按钮时,它在logcat 内给我一个错误说:

“W/SyncTree:监听 /users 失败:DatabaseError: Permission denied”

好像我无法访问数据库的特定值。

这些是数据库中的规则:

{
   "rules": {
    "users": {
      "$uid": {
        ".read": "$uid === auth.uid",
        ".write": "$uid === auth.uid"
      }
    }
  }
}

我确实试图修改数据库规则,但它给了我一个错误。

【问题讨论】:

  • 你是在使用firebase auth注册用户吗?
  • 是的,我是 mAuth.createUserWithEmailAndPassword(email, password)

标签: java json firebase firebase-realtime-database firebase-security


【解决方案1】:

我将讲述你的代码的全部故事。

您正在检查注册前的现有用户。

但是如何在注册之前获得 firebase auth id?注册后您将获得身份验证ID,然后只有您可以查看此规则。

// Checks auth uid equals database node uid
// In other words, the User can only access their own data

{
  "rules": {
    "posts": {
       "$uid": {
         ".read": "$uid === auth.uid",
         ".write": "$uid === auth.uid"
       }
     }
   }
}

如果你想检查用户,你需要在这里修改你的规则

{
  "rules": {
    "posts": {
       "$uid": {
         ".read": true,
         ".write": "$uid === auth.uid"
       }
     }
   }
}

但我认为当您使用 firebase 身份验证时,这是一个不好的例子。您不必检查 firebase auth 中的现有用户。 firebase auth 将为您检查。如果用户已经注册,则会给你错误

这里是示例代码,可以随意修改

private void signUpInFirebaseAuth(String email, String password) {
        mAuth.createUserWithEmailAndPassword(email, password)
                .addOnCompleteListener(this, new OnCompleteListener<AuthResult>() {
                    @Override
                    public void onComplete(@NonNull Task<AuthResult> task) {
                        if (task.isSuccessful()) {
                            // Sign up success, update UI with the signed-up user's information
                            Log.d(TAG, "createUserWithEmail:success");
                            FirebaseUser user = mAuth.getCurrentUser();
                            if (user != null) {
                                saveUserCredentials(user.getUid(), password, email);
                            }
                            updateUI(user);
                        } else {
                            // If sign up fails, display a message to the user.
                            Log.e(TAG, "createUserWithEmail:failure", task.getException());
                            //Toast.makeText(UserRegistrationActivity.this, "Sign Up Failed!: "+task.getException().getMessage(), Toast.LENGTH_LONG).show();

                            updateUI(null);
                        }
                    }
                });

    }

【讨论】:

  • 如何检查分配的 id 是否不在数据库中?
  • createUserWithEmailAndPassword 是否给出错误?相信我,它不会出错。如果它给出错误,你可以发布它吗? (它通过抛出错误告诉用户已经存在)
  • 问题是,firebase auth 正在维护一个数据库,它将检查自己的数据库以获取即将到来的新注册
猜你喜欢
  • 2020-10-08
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2020-11-25
  • 2017-04-17
  • 2018-12-12
  • 2020-02-15
相关资源
最近更新 更多