Validazione dei dati con le regole
Utilizzi le regole di sicurezza per validare i dati in ingresso, verificando che rispettino i formati previsti e impedendo scritture malevole
Validazione dei dati con le regole è una lezione Firebase Auth & Realtime Database Apps gratuita su CoddyKit. Questa è la lezione 3 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Firebase Auth & Realtime Database Apps, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Firebase Auth & Realtime Database Apps include 4 lezioni in totale.
Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.
Why Validate Data?
Welcome to Lesson 3! In this lesson, we'll learn how to use Firebase Realtime Database Security Rules to validate incoming data. This is super important to:
- Prevent bad or malicious data from entering your database.
- Maintain the integrity and consistency of your application's data.
- Ensure data conforms to expected formats and types.
Think of it as a bouncer for your database!
Introducing newData & .validate()
When data is written to your database, Firebase provides a special object called newData. This object represents the data that's about to be written.
We use the .validate() rule to define conditions that newData must meet. If these conditions aren't met, the write operation will be rejected.
Here's a basic example:
{
"rules": {
"posts": {
"$postId": {
// Allow anyone authenticated to write
".write": "auth != null",
// Validate that new posts must have 'title' and 'content'
".validate": "newData.hasChildren(['title', 'content'])"
}
}
}
}Checking Data Types
One of the most common validations is checking the data type. You can ensure fields are strings, numbers, booleans, or even null.
This helps prevent users from submitting, for example, a number where a name (string) is expected.
{
"rules": {
"users": {
"$userId": {
"name": { ".validate": "newData.isString()" },
"age": { ".validate": "newData.isNumber()" },
"isActive": { ".validate": "newData.isBoolean()" }
}
}
}
}Making Fields Mandatory
Sometimes, certain fields are absolutely required. You can use newData.hasChildren(['field1', 'field2']) to ensure multiple fields exist, or directly access a child to check its presence.
If a required field is missing, the write will fail.
{
"rules": {
"messages": {
"$messageId": {
".validate": "newData.hasChildren(['senderId', 'text'])"
}
}
}
}Controlling String Lengths
For text fields, you often want to limit the minimum or maximum length. This prevents overly short or excessively long inputs.
You can use the .length property on a string value.
{
"rules": {
"products": {
"$productId": {
"name": {
".validate": "newData.isString() && newData.val().length > 2 && newData.val().length < 50"
}
}
}
}
}Setting Number Ranges
For numerical data, you might need to ensure values fall within a specific range. For example, an age must be positive, or a score must be between 0 and 100.
You can use standard comparison operators (>, <, >=, <=).
{
"rules": {
"scores": {
"$scoreId": {
"value": {
".validate": "newData.isNumber() && newData.val() >= 0 && newData.val() <= 100"
}
}
}
}
}Advanced Pattern Matching
For more complex string formats, like emails or URLs, you can use regular expressions with the .matches() function.
Regular expressions are powerful patterns for matching text. They can seem intimidating at first, but are very useful!
{
"rules": {
"profiles": {
"$profileId": {
"email": {
// Basic email regex pattern validation
".validate": "newData.isString() && newData.val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i)"
}
}
}
}
}Combining Validation Rules
You'll often need to combine multiple validation checks. You can use logical operators:
&&(AND): All conditions must be true.||(OR): At least one condition must be true.
This allows for very flexible and robust validation logic.
{
"rules": {
"tasks": {
"$taskId": {
".validate": "newData.hasChildren(['title', 'status']) && newData.child('title').isString() && newData.child('title').val().length > 5"
}
}
}
}User Profile Validation Example
Let's put it all together with a comprehensive example for a user profile:
username: must be a string, at least 3 characters.email: must be a string and match an email regex.age: must be a number and at least 13.
{
"rules": {
"userProfiles": {
"$userId": {
".validate": "newData.hasChildren(['username', 'email', 'age']) && \
newData.child('username').isString() && \
newData.child('username').val().length >= 3 && \
newData.child('email').isString() && \
newData.child('email').val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i) && \
newData.child('age').isNumber() && \
newData.child('age').val() >= 13"
}
}
}
}Validate Your Knowledge
Consider a rule for a 'product' node. A product must have a 'name' (string, min 2 chars, max 100 chars) and a 'price' (number, greater than 0).
Recap: Data Integrity Secured
Great job! You've learned how to use Firebase Realtime Database Security Rules to validate data:
- The
newDataobject represents data being written. - The
.validate()rule enforces conditions onnewData. - You can check data types (
isString(),isNumber()). - Ensure required fields exist with
hasChildren(). - Validate string lengths (
.length) and number ranges (>,<). - Use
.matches()for complex pattern validation with regex. - Combine rules with
&&and||for powerful logic.
By validating data, you ensure your database remains clean and secure!
Domande Frequenti
La lezione «Validazione dei dati con le regole» è gratuita?
Sì — il testo completo di «Validazione dei dati con le regole» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Firebase Auth & Realtime Database Apps, passa a CoddyKit PRO. Il corso Firebase Auth & Realtime Database Apps include 4 lezioni in totale.
Cosa imparerò in «Validazione dei dati con le regole»?
Utilizzi le regole di sicurezza per validare i dati in ingresso, verificando che rispettino i formati previsti e impedendo scritture malevole Eserciti Firebase Auth & Realtime Database Apps con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.
Ho bisogno di esperienza per iniziare Firebase Auth & Realtime Database Apps?
Non è richiesta alcuna esperienza precedente. Firebase Auth & Realtime Database Apps su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 3 di 4.
Quanto tempo richiede la lezione «Validazione dei dati con le regole»?
La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.
Posso scrivere ed eseguire codice in questa lezione Firebase Auth & Realtime Database Apps?
Sì. Ogni lezione Firebase Auth & Realtime Database Apps include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.
Tutte le lezioni di questo corso
- Comprendere la sintassi delle regole di sicurezza
- Controllo degli accessi basato sull'utente
- Validazione dei dati con le regole
- Test e debug delle Security Rules