【问题标题】:Firebase Realtime Database Security Failing to Read ClosureFirebase 实时数据库安全无法读取关闭
【发布时间】:2018-05-10 02:27:24
【问题描述】:

我正在 firebase 中编写安全规则,以验证帖子是否存在或群组是否存在。我完全理解安全规则不是过滤器,我没有将它用作过滤器,而是用作验证指标。这是我正在尝试实施的规则...

    "notifications": {
  ".read": "auth !== null",
  ".write": "auth !== null",
  ".indexOn": ["post_ID", "group_ID"],
  "$userID": {
    "$notifID": {
      ".validate": "newData.hasChildren(['has-seen', 'end-time', 'time', 'user_ID', 'username']) && $userID !== newData.child('sender_ID').val() && (root.child('groups').child(newData.child('group_ID').val()).exists() || root.child('follower-feed-storage').child(newData.child('post_ID').val()).exists())",
      ".write": "auth.uid !== $userID && !data.exists()",
    }
  }
},

显然,该规则应该正确评估 hasChildren 和 $userID !== newData.child('user_ID').val() 条件。但是,当它应该计算 && 之后和括号内的最后一个表达式时,它会根据括号内的第一个条件成功或失败,而不执行 or 运算符并计算第二个表达式。显然我在语法上做错了,但我无法弄清楚。提前感谢任何帮助。

【问题讨论】:

    标签: firebase firebase-realtime-database firebase-security


    【解决方案1】:

    您必须将string 传递给.child,因此如果newData.child('group_ID').val() 的计算结果为null 或undefined,那么它将失败。尝试将结果转换为string 或在查找之前测试它是否存在。 (我推荐后者。)

    (newData.child('group_ID').exists() && root.child('groups').child(newData.child('group_ID').val()).exists())
    

    【讨论】:

    • 漂亮,我不清楚这是阅读文档所必需的。现在像魅力一样工作
    猜你喜欢
    • 2022-11-11
    • 2022-01-18
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2020-08-08
    • 2021-12-22
    相关资源
    最近更新 更多