【问题标题】:Firebase security rules custom fieldFirebase 安全规则自定义字段
【发布时间】:2015-06-15 09:23:59
【问题描述】:

我的 Firebase 安全规则如下所示:

"users": {
      "$uid": {
        // grants write access to the owner of this user account whose uid must exactly match the key ($uid)
        ".write": "auth !== null && auth.uid === $uid",

        // grants read access to any user who is logged in with an email and password
        ".read": "auth !== null && auth.provider === 'password'"
      }
    },

另外,我有一个自定义的userId,我存储在users/$uid。例如,我的users/$uid 如下所示:

users
   /$uid
       /email: foo@bar.com
       /userId: "foobargayid123456"

我在其他节点使用这个userId,例如节点profile_pictures来设置依赖:

profile_pictures
   /userId
       /thumbnail: "datablabla"

问题

如何在 firebase 中为节点 profile_pictures 设置安全规则,以便只有 id 为 users/$uid/userId 的用户才能 .write 节点 profile_pictures/userId

【问题讨论】:

  • 当用户更改现有帐户的电子邮件地址时,他们的uid 将保持不变。您是否使用此处记录的ref.changeEmail? firebase.com/docs/web/guide/login/…
  • @FrankvanPuffelen 是的,你是对的。我假设它确实发生了变化,因为几个月前我使用图书馆时发生了这种情况。谢谢,我已经更新了我的问题。
  • uid 和 userId 的值是否相同?如果没有,你可能应该改变它。为同一个用户保留两个不同的 id 是没有意义的。

标签: javascript angularjs firebase angularfire firebase-security


【解决方案1】:

我想这就是你要找的。​​p>

{ 
  "rules": {
    "profile_pictures": {
      "$userId": {
        ".write": "
          root.child('users').child(auth.uid).child('userId').val == $userId"
      }
    }
  }
}

【讨论】:

  • 太棒了!也是非常直观的方式。
猜你喜欢
  • 1970-01-01
  • 2022-12-06
  • 1970-01-01
  • 1970-01-01
  • 2022-01-19
  • 2020-10-11
  • 1970-01-01
  • 2016-06-27
  • 1970-01-01
相关资源
最近更新 更多