اختبار قواعد الأمان وتصحيح أخطائها
عزّز ثقتك بقواعد Realtime Database عبر محاكاة الطلبات، واستخدام Rules Playground، وكتابة اختبارات آلية باستخدام المحاكي، وقراءة رسائل الرفض.
اختبار قواعد الأمان وتصحيح أخطائها درس مجاني في Firebase Auth & Realtime Database Apps على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Firebase Auth & Realtime Database Apps، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Firebase Auth & Realtime Database Apps 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Why Test Your Rules
Security Rules are the only thing standing between your data and the open internet. A single mistake can expose private data or block legitimate users.
Testing rules is as important as testing code, and Firebase gives you several tools to do it.
The Rules Playground
The Firebase console includes a Rules Playground where you simulate a single read or write without touching real data.
- Pick read or write
- Set a path and auth state
- See instantly whether it is allowed or denied
Simulating Auth State
In the simulator you can run as an unauthenticated user or supply a fake auth.uid and custom claims. This is how you verify that user-based access control behaves correctly.
Reading a Denial
When a request is denied, the simulator highlights the exact rule that evaluated to false. Use this to pinpoint why a legitimate request is being blocked.
The Local Emulator
For repeatable, automated testing, use the Firebase Local Emulator Suite. It runs the Realtime Database and its rules entirely on your machine, with no cloud costs.
firebase emulators:start --only databaseWriting a Rules Test
The @firebase/rules-unit-testing library lets you assert that operations succeed or fail. This is the gold standard for rule confidence.
import { assertSucceeds, assertFails } from '@firebase/rules-unit-testing';
await assertSucceeds(authedDb.ref('users/alice').set({ name: 'Alice' }));
await assertFails(authedDb.ref('users/bob').set({ name: 'hax' }));Test Both Directions
Good rule tests check both outcomes:
- Authorized users can do allowed actions (no false denials)
- Unauthorized users cannot do forbidden actions (no security holes)
Testing only the happy path hides the dangerous gaps.
Testing Validation Rules
Beyond access, test your .validate rules: confirm that malformed data is rejected and well-formed data is accepted.
await assertFails(db.ref('age').set('not-a-number'));
await assertSucceeds(db.ref('age').set(30));Common Rule Bugs
Watch for these frequent mistakes:
- Rules cascade: a true
.readhigher up overrides children - Forgetting that read and write rules are independent
- Assuming
authis non-null without checking
Debugging with newData
Inside write rules, newData represents what the write would produce and data is the current value. Logging your reasoning about these in test cases clears up many confusing denials.
{
"posts": {
"$id": {
".write": "!data.exists() || data.child('owner').val() === auth.uid"
}
}
}CI Integration
Run your emulator-based rule tests in continuous integration so a risky rule change is caught before it reaches production. This turns security into a regression-tested guarantee.
Quick Check
Test your understanding of rules testing.
Recap
You can now validate rules with confidence.
- Use the Rules Playground for quick manual checks
- Use the Local Emulator for repeatable runs
- Write tests with
assertSucceeds/assertFails - Cover both access and validation, both directions
- Run rule tests in CI
الأسئلة الشائعة
هل درس «اختبار قواعد الأمان وتصحيح أخطائها» مجاني؟
نعم — نص درس «اختبار قواعد الأمان وتصحيح أخطائها» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Firebase Auth & Realtime Database Apps، انتقل إلى CoddyKit PRO. تتضمن دورة Firebase Auth & Realtime Database Apps 4 دروس في المجموع.
ماذا ستتعلم في «اختبار قواعد الأمان وتصحيح أخطائها»؟
عزّز ثقتك بقواعد Realtime Database عبر محاكاة الطلبات، واستخدام Rules Playground، وكتابة اختبارات آلية باستخدام المحاكي، وقراءة رسائل الرفض. تتمرن على Firebase Auth & Realtime Database Apps مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ Firebase Auth & Realtime Database Apps؟
لا تُشترط خبرة سابقة. Firebase Auth & Realtime Database Apps على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.
كم من الوقت يستغرق درس «اختبار قواعد الأمان وتصحيح أخطائها»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس Firebase Auth & Realtime Database Apps هذا؟
نعم. كل درس في Firebase Auth & Realtime Database Apps يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- فهم صياغة قواعد الأمان
- التحكم في الوصول المستند إلى المستخدم
- التحقق من صحة البيانات باستخدام القواعد
- اختبار قواعد الأمان وتصحيح أخطائها