セキュリティルールのテストとデバッグ
リクエストをシミュレートし、Rules Playgroundを使い、エミュレーターで自動テストを作成し、拒否メッセージを読み取ることで、Realtime Databaseのルールに自信を持てるようにします。
「セキュリティルールのテストとデバッグ」はCoddyKit上の無料Firebase Auth & Realtime Database Appsレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはFirebase Auth & Realtime Database Apps学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Why Test Your Rules
Security Rules are the only thing standing between your data and the open internet. A single mistake can expose private data or block legitimate users.
Testing rules is as important as testing code, and Firebase gives you several tools to do it.
The Rules Playground
The Firebase console includes a Rules Playground where you simulate a single read or write without touching real data.
- Pick read or write
- Set a path and auth state
- See instantly whether it is allowed or denied
Simulating Auth State
In the simulator you can run as an unauthenticated user or supply a fake auth.uid and custom claims. This is how you verify that user-based access control behaves correctly.
Reading a Denial
When a request is denied, the simulator highlights the exact rule that evaluated to false. Use this to pinpoint why a legitimate request is being blocked.
The Local Emulator
For repeatable, automated testing, use the Firebase Local Emulator Suite. It runs the Realtime Database and its rules entirely on your machine, with no cloud costs.
firebase emulators:start --only databaseWriting a Rules Test
The @firebase/rules-unit-testing library lets you assert that operations succeed or fail. This is the gold standard for rule confidence.
import { assertSucceeds, assertFails } from '@firebase/rules-unit-testing';
await assertSucceeds(authedDb.ref('users/alice').set({ name: 'Alice' }));
await assertFails(authedDb.ref('users/bob').set({ name: 'hax' }));Test Both Directions
Good rule tests check both outcomes:
- Authorized users can do allowed actions (no false denials)
- Unauthorized users cannot do forbidden actions (no security holes)
Testing only the happy path hides the dangerous gaps.
Testing Validation Rules
Beyond access, test your .validate rules: confirm that malformed data is rejected and well-formed data is accepted.
await assertFails(db.ref('age').set('not-a-number'));
await assertSucceeds(db.ref('age').set(30));Common Rule Bugs
Watch for these frequent mistakes:
- Rules cascade: a true
.readhigher up overrides children - Forgetting that read and write rules are independent
- Assuming
authis non-null without checking
Debugging with newData
Inside write rules, newData represents what the write would produce and data is the current value. Logging your reasoning about these in test cases clears up many confusing denials.
{
"posts": {
"$id": {
".write": "!data.exists() || data.child('owner').val() === auth.uid"
}
}
}CI Integration
Run your emulator-based rule tests in continuous integration so a risky rule change is caught before it reaches production. This turns security into a regression-tested guarantee.
Quick Check
Test your understanding of rules testing.
Recap
You can now validate rules with confidence.
- Use the Rules Playground for quick manual checks
- Use the Local Emulator for repeatable runs
- Write tests with
assertSucceeds/assertFails - Cover both access and validation, both directions
- Run rule tests in CI
よくある質問
「セキュリティルールのテストとデバッグ」レッスンは無料ですか?
はい。「セキュリティルールのテストとデバッグ」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Firebase Auth & Realtime Database Appsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。
「セキュリティルールのテストとデバッグ」で何を学びますか?
リクエストをシミュレートし、Rules Playgroundを使い、エミュレーターで自動テストを作成し、拒否メッセージを読み取ることで、Realtime Databaseのルールに自信を持てるようにします。 ブラウザで直接実行するハンズオンコードでFirebase Auth & Realtime Database Appsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Firebase Auth & Realtime Database Appsを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのFirebase Auth & Realtime Database Appsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。
「セキュリティルールのテストとデバッグ」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このFirebase Auth & Realtime Database Appsレッスンでコードを書いて実行できますか?
はい。すべてのFirebase Auth & Realtime Database Appsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- セキュリティルール構文の理解
- ユーザーベースのアクセス制御
- ルールによるデータ検証
- セキュリティルールのテストとデバッグ