【问题标题】:Why do I get an insufficient permissions error while trying to delete an array element from firestore, yet I can delete the entire document为什么在尝试从 Firestore 中删除数组元素时出现权限不足错误,但我可以删除整个文档
【发布时间】:2021-11-01 22:05:41
【问题描述】:

我的 Firestore 中有一个名为“reports”的集合

报告映射中的一个字段是对象数组。这些对象引用云存储中的照片。它们看起来像这样(网址指向云存储):

{
   id: uid value
   url: some-url
}

我的 firebase 规则是这样为报告文档设置的:

match /databases/{database}/documents {
    match /reports/{report} {
      allow read: if request.auth != null && request.auth.uid == resource.data.userID;
      allow create: if request.auth != null && request.resource.data.userID == request.auth.uid;
      allow delete, update: if request.auth != null &&
      request.auth.uid == resource.data.userID;
    }
}

出于某种原因,如果我想证明我有删除权限,我可以删除整个文档.....但是当我尝试从照片数组中删除一个项目时:

const reportRef = db.collection('reports')
reportRef.doc(activeReport.id).update({
    photos: firebase.firestore.FieldValue.arrayRemove(photoToDelete)
})

我最终得到一个错误说明:

未处理的承诺拒绝:FirebaseError:缺少权限或权限不足

为什么?我没有授权正确更新此文档吗?

【问题讨论】:

  • 您可以尝试在allow read, write: if request.auth != null && request.auth.uid == resource.data.userID; 中添加write,然后再次检查是否可行?如需进一步参考,请查看Firebase Security Rules。

标签: javascript google-cloud-storage firebase-security


【解决方案1】:

进入数据库 -> 规则 ->

用于开发:

将allow read, write: if false; 更改为 true;

注意:这只是用于开发目的的快速解决方案,因为它会关闭所有安全性。因此,不建议用于生产。

用于生产:

如果从 firebase 进行身份验证:Change allow read, write: if false; 到 request.auth != null;

【讨论】:

  • 这是一个糟糕的解决方案...它允许任何经过身份验证的人访问数据,即使这不是他们的数据。
【解决方案2】:

在这种情况下,传入的参数是错误的。我需要传递 activeReport 而不是 activeReport.id。

这是一个误导性的错误消息。我会删除这个问题,但 stackoverflow 不希望我这样做,因为这里已经发布了答案。傻。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2021-08-30
    • 2019-05-12
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2023-02-07
    • 1970-01-01
    • 2021-11-28
    相关资源
    最近更新 更多