0Pricing
Firebase Auth & Realtime Database Apps · Lección

Validación de datos con reglas

Utilice reglas de seguridad para validar los datos entrantes, asegurándose de que cumplan los formatos esperados y evitando escrituras maliciosas.

Validación de datos con reglas es una lección gratuita de Firebase Auth & Realtime Database Apps en CoddyKit. Esta es la lección 3 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Firebase Auth & Realtime Database Apps, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Firebase Auth & Realtime Database Apps incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Why Validate Data?

Welcome to Lesson 3! In this lesson, we'll learn how to use Firebase Realtime Database Security Rules to validate incoming data. This is super important to:

  • Prevent bad or malicious data from entering your database.
  • Maintain the integrity and consistency of your application's data.
  • Ensure data conforms to expected formats and types.

Think of it as a bouncer for your database!

Introducing newData & .validate()

When data is written to your database, Firebase provides a special object called newData. This object represents the data that's about to be written.

We use the .validate() rule to define conditions that newData must meet. If these conditions aren't met, the write operation will be rejected.

Here's a basic example:

{
  "rules": {
    "posts": {
      "$postId": {
        // Allow anyone authenticated to write
        ".write": "auth != null",
        // Validate that new posts must have 'title' and 'content'
        ".validate": "newData.hasChildren(['title', 'content'])"
      }
    }
  }
}

Checking Data Types

One of the most common validations is checking the data type. You can ensure fields are strings, numbers, booleans, or even null.

This helps prevent users from submitting, for example, a number where a name (string) is expected.

{
  "rules": {
    "users": {
      "$userId": {
        "name": { ".validate": "newData.isString()" },
        "age": { ".validate": "newData.isNumber()" },
        "isActive": { ".validate": "newData.isBoolean()" }
      }
    }
  }
}

Making Fields Mandatory

Sometimes, certain fields are absolutely required. You can use newData.hasChildren(['field1', 'field2']) to ensure multiple fields exist, or directly access a child to check its presence.

If a required field is missing, the write will fail.

{
  "rules": {
    "messages": {
      "$messageId": {
        ".validate": "newData.hasChildren(['senderId', 'text'])"
      }
    }
  }
}

Controlling String Lengths

For text fields, you often want to limit the minimum or maximum length. This prevents overly short or excessively long inputs.

You can use the .length property on a string value.

{
  "rules": {
    "products": {
      "$productId": {
        "name": {
          ".validate": "newData.isString() && newData.val().length > 2 && newData.val().length < 50"
        }
      }
    }
  }
}

Setting Number Ranges

For numerical data, you might need to ensure values fall within a specific range. For example, an age must be positive, or a score must be between 0 and 100.

You can use standard comparison operators (>, <, >=, <=).

{
  "rules": {
    "scores": {
      "$scoreId": {
        "value": {
          ".validate": "newData.isNumber() && newData.val() >= 0 && newData.val() <= 100"
        }
      }
    }
  }
}

Advanced Pattern Matching

For more complex string formats, like emails or URLs, you can use regular expressions with the .matches() function.

Regular expressions are powerful patterns for matching text. They can seem intimidating at first, but are very useful!

{
  "rules": {
    "profiles": {
      "$profileId": {
        "email": {
          // Basic email regex pattern validation
          ".validate": "newData.isString() && newData.val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i)"
        }
      }
    }
  }
}

Combining Validation Rules

You'll often need to combine multiple validation checks. You can use logical operators:

  • && (AND): All conditions must be true.
  • || (OR): At least one condition must be true.

This allows for very flexible and robust validation logic.

{
  "rules": {
    "tasks": {
      "$taskId": {
        ".validate": "newData.hasChildren(['title', 'status']) && newData.child('title').isString() && newData.child('title').val().length > 5"
      }
    }
  }
}

User Profile Validation Example

Let's put it all together with a comprehensive example for a user profile:

  • username: must be a string, at least 3 characters.
  • email: must be a string and match an email regex.
  • age: must be a number and at least 13.
{
  "rules": {
    "userProfiles": {
      "$userId": {
        ".validate": "newData.hasChildren(['username', 'email', 'age']) && \
                      newData.child('username').isString() && \
                      newData.child('username').val().length >= 3 && \
                      newData.child('email').isString() && \
                      newData.child('email').val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i) && \
                      newData.child('age').isNumber() && \
                      newData.child('age').val() >= 13"
      }
    }
  }
}

Validate Your Knowledge

Consider a rule for a 'product' node. A product must have a 'name' (string, min 2 chars, max 100 chars) and a 'price' (number, greater than 0).

Recap: Data Integrity Secured

Great job! You've learned how to use Firebase Realtime Database Security Rules to validate data:

  • The newData object represents data being written.
  • The .validate() rule enforces conditions on newData.
  • You can check data types (isString(), isNumber()).
  • Ensure required fields exist with hasChildren().
  • Validate string lengths (.length) and number ranges (>, <).
  • Use .matches() for complex pattern validation with regex.
  • Combine rules with && and || for powerful logic.

By validating data, you ensure your database remains clean and secure!

Preguntas frecuentes

¿La lección «Validación de datos con reglas» es gratis?

Sí — el texto completo de «Validación de datos con reglas» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Firebase Auth & Realtime Database Apps, actualiza a CoddyKit PRO. El curso de Firebase Auth & Realtime Database Apps incluye 4 lecciones en total.

¿Qué aprenderé en «Validación de datos con reglas»?

Utilice reglas de seguridad para validar los datos entrantes, asegurándose de que cumplan los formatos esperados y evitando escrituras maliciosas. Practicas Firebase Auth & Realtime Database Apps con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar Firebase Auth & Realtime Database Apps?

No se requiere experiencia previa. Firebase Auth & Realtime Database Apps en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 3 de 4.

¿Cuánto tiempo toma la lección «Validación de datos con reglas»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de Firebase Auth & Realtime Database Apps?

Sí. Cada lección de Firebase Auth & Realtime Database Apps incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. Comprensión de la sintaxis de las reglas de seguridad
  2. Control de acceso basado en usuarios
  3. Validación de datos con reglas
  4. Pruebas y depuración de reglas de seguridad
← Volver a Firebase Auth & Realtime Database Apps