【发布时间】:2021-11-01 22:05:41
【问题描述】:
我的 Firestore 中有一个名为“reports”的集合
报告映射中的一个字段是对象数组。这些对象引用云存储中的照片。它们看起来像这样(网址指向云存储):
{
id: uid value
url: some-url
}
我的 firebase 规则是这样为报告文档设置的:
match /databases/{database}/documents {
match /reports/{report} {
allow read: if request.auth != null && request.auth.uid == resource.data.userID;
allow create: if request.auth != null && request.resource.data.userID == request.auth.uid;
allow delete, update: if request.auth != null &&
request.auth.uid == resource.data.userID;
}
}
出于某种原因,如果我想证明我有删除权限,我可以删除整个文档.....但是当我尝试从照片数组中删除一个项目时:
const reportRef = db.collection('reports')
reportRef.doc(activeReport.id).update({
photos: firebase.firestore.FieldValue.arrayRemove(photoToDelete)
})
我最终得到一个错误说明:
未处理的承诺拒绝:FirebaseError:缺少权限或权限不足
为什么?我没有授权正确更新此文档吗?
【问题讨论】:
-
您可以尝试在
allow read, write: if request.auth != null && request.auth.uid == resource.data.userID;中添加write,然后再次检查是否可行?如需进一步参考,请查看Firebase Security Rules。
标签: javascript google-cloud-storage firebase-security