0Pricing
Firebase Auth & Realtime Database Apps · درس

التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار

اجمع بين أدوار Firebase Auth وقواعد Realtime Database لمنح المسؤولين والأعضاء والضيوف مستويات مختلفة من الوصول إلى البيانات المشتركة والشخصية.

التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار درس مجاني في Firebase Auth & Realtime Database Apps على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Firebase Auth & Realtime Database Apps، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Firebase Auth & Realtime Database Apps 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Beyond Owner-Only Access

So far each user reads and writes their own data. Real apps need roles: an admin who moderates content, members who collaborate, and guests with read-only access.

Role-based access control (RBAC) layers permissions on top of authentication.

Where Roles Live

You can store a user's role in two places:

  • A roles node in the database, read inside rules
  • A custom claim on the auth token (set server-side)

Custom claims are faster to check; database roles are easier to change at runtime.

Roles in the Database

A simple model maps each uid to a role string. This data itself must be locked down so users cannot promote themselves.

{
  "roles": {
    "uid_alice": "admin",
    "uid_bob": "member"
  }
}

Checking a Database Role in Rules

Rules can read other parts of the database with root. Here only admins may write to a shared config node.

{
  "rules": {
    "config": {
      ".write": "root.child('roles').child(auth.uid).val() === 'admin'"
    }
  }
}

Custom Claims for Roles

With the Admin SDK you can attach a role to the token itself. This is checked without an extra database read.

await admin.auth().setCustomUserClaims(uid, { role: 'admin' });

Checking Claims in Rules

Custom claims appear under auth.token. The rule becomes simpler and avoids a root lookup.

{
  "rules": {
    "config": {
      ".write": "auth.token.role === 'admin'"
    }
  }
}

Reading the Claim Client-Side

The client can read its own claims to adjust the UI, for example showing an admin panel only to admins.

import { getAuth, getIdTokenResult } from 'firebase/auth';

const res = await getIdTokenResult(getAuth().currentUser);
if (res.claims.role === 'admin') showAdminPanel();

Tiered Read Access

Different roles can have different read scopes. Members read shared docs; guests read only public ones.

{
  "rules": {
    "shared": {
      ".read": "auth.token.role === 'member' || auth.token.role === 'admin'"
    }
  }
}

Protecting the Role Data Itself

Critically, users must not be able to edit their own role. Make the roles node writable only by admins (or only server-side), or self-escalation defeats the whole system.

{
  "rules": {
    "roles": {
      ".write": "auth.token.role === 'admin'"
    }
  }
}

Claim Propagation Delay

After you change a custom claim, the user's existing token still has the old value until it refreshes (about an hour, or on forced refresh). Call getIdToken(true) client-side to pick up new roles immediately.

await getAuth().currentUser.getIdToken(true);

Choosing an Approach

Use custom claims for stable, security-critical roles, and database roles when permissions change often or need to be queried. Many apps combine both.

Quick Check

Test your understanding of role-based access.

Recap

You can now grant tiered access by role.

  • Store roles in the database or as custom claims
  • Check database roles via root, claims via auth.token
  • Give roles different read/write scopes
  • Lock down the role data so users cannot self-promote
  • Refresh tokens to pick up new claims promptly

الأسئلة الشائعة

هل درس «التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار» مجاني؟

نعم — نص درس «التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Firebase Auth & Realtime Database Apps، انتقل إلى CoddyKit PRO. تتضمن دورة Firebase Auth & Realtime Database Apps 4 دروس في المجموع.

ماذا ستتعلم في «التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار»؟

اجمع بين أدوار Firebase Auth وقواعد Realtime Database لمنح المسؤولين والأعضاء والضيوف مستويات مختلفة من الوصول إلى البيانات المشتركة والشخصية. تتمرن على Firebase Auth & Realtime Database Apps مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Firebase Auth & Realtime Database Apps؟

لا تُشترط خبرة سابقة. Firebase Auth & Realtime Database Apps على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Firebase Auth & Realtime Database Apps هذا؟

نعم. كل درس في Firebase Auth & Realtime Database Apps يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. ربط بيانات المستخدم بالمصادقة
  2. ملفات المستخدمين الشخصية في الوقت الفعلي
  3. تحرير البيانات بشكل تعاوني
  4. التحكم بالوصول إلى بيانات المستخدمين حسب الأدوار
← العودة إلى Firebase Auth & Realtime Database Apps