【问题标题】:Firebase Security Rules NestingFirebase 安全规则嵌套
【发布时间】:2015-06-04 09:48:56
【问题描述】:

我正在创建一个 reddit 类型的应用程序。我有一系列故事,每个故事都有一个标题、描述和一个 voteCount。我想为 voteCount 设置单独的 .write 规则,所以我像这样构建了我的规则 -

"stories": {
  "$story_id": {

    "title": { ".write": "auth !== null" },
    "description" { ".write": "auth !== null" },
    "voteCount": { ".write": "newData.val() === data.val() + 1" },

  }
}

这适用于现有故事。但是,这不再允许我添加新故事,除非我将 .write 规则直接添加到 $story_id 节点。当然,这会阻止我为 voteCount 节点设置特殊的 .write 规则。

关于为什么会发生这种情况的任何想法?

【问题讨论】:

    标签: firebase angularfire firebase-security


    【解决方案1】:

    所以用户拥有更高级别的.write访问权限,但他们只能写入遵循特定规则的数据?

    您需要将其放入 .validation 规则中,而不是 .write 规则中。

    记住这一点的一个简单方法是.write 规则决定谁 可以写入数据,而.validate 规则决定什么 数据可以写入。

    【讨论】:

    • 谢谢。实际上,我还想限制谁也可以写入 voteCount 节点。我只是在这里使用了一个简化版本。 voteCount 安全节点实际上是这样的 - "voteCount": { ".write": "auth !== null && newData.val() === data.val() + 1 && auth.uid !== root.child('stories').child($story_id).child('user').child('id').val()" }
    • 是的,我希望auth 签入.write。解决方案的第一步是将数据验证分离到.validate 规则中。看起来最后一个!==实际上应该是===。
    • 弗兰克已经暗示了这一点,但直接说明:您当前示例失败的原因是没有 .write 规则允许在 $story_id 级别进行写访问。能够访问所有孩子仍然不允许写入父路径。所以 auth != null 属于 $story_id 级别,而其余规则(如前所述,肯定是 .validate)属于子级别。
    猜你喜欢
    • 1970-01-01
    • 2018-06-17
    • 1970-01-01
    • 1970-01-01
    • 2016-06-27
    • 1970-01-01
    • 1970-01-01
    • 2016-08-19
    相关资源
    最近更新 更多