0Pricing
Firebase Auth & Realtime Database Apps · レッスン

セキュリティルールのテストとデバッグ

リクエストをシミュレートし、Rules Playgroundを使い、エミュレーターで自動テストを作成し、拒否メッセージを読み取ることで、Realtime Databaseのルールに自信を持てるようにします。

「セキュリティルールのテストとデバッグ」はCoddyKit上の無料Firebase Auth & Realtime Database Appsレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはFirebase Auth & Realtime Database Apps学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Why Test Your Rules

Security Rules are the only thing standing between your data and the open internet. A single mistake can expose private data or block legitimate users.

Testing rules is as important as testing code, and Firebase gives you several tools to do it.

The Rules Playground

The Firebase console includes a Rules Playground where you simulate a single read or write without touching real data.

  • Pick read or write
  • Set a path and auth state
  • See instantly whether it is allowed or denied

Simulating Auth State

In the simulator you can run as an unauthenticated user or supply a fake auth.uid and custom claims. This is how you verify that user-based access control behaves correctly.

Reading a Denial

When a request is denied, the simulator highlights the exact rule that evaluated to false. Use this to pinpoint why a legitimate request is being blocked.

The Local Emulator

For repeatable, automated testing, use the Firebase Local Emulator Suite. It runs the Realtime Database and its rules entirely on your machine, with no cloud costs.

firebase emulators:start --only database

Writing a Rules Test

The @firebase/rules-unit-testing library lets you assert that operations succeed or fail. This is the gold standard for rule confidence.

import { assertSucceeds, assertFails } from '@firebase/rules-unit-testing';

await assertSucceeds(authedDb.ref('users/alice').set({ name: 'Alice' }));
await assertFails(authedDb.ref('users/bob').set({ name: 'hax' }));

Test Both Directions

Good rule tests check both outcomes:

  • Authorized users can do allowed actions (no false denials)
  • Unauthorized users cannot do forbidden actions (no security holes)

Testing only the happy path hides the dangerous gaps.

Testing Validation Rules

Beyond access, test your .validate rules: confirm that malformed data is rejected and well-formed data is accepted.

await assertFails(db.ref('age').set('not-a-number'));
await assertSucceeds(db.ref('age').set(30));

Common Rule Bugs

Watch for these frequent mistakes:

  • Rules cascade: a true .read higher up overrides children
  • Forgetting that read and write rules are independent
  • Assuming auth is non-null without checking

Debugging with newData

Inside write rules, newData represents what the write would produce and data is the current value. Logging your reasoning about these in test cases clears up many confusing denials.

{
  "posts": {
    "$id": {
      ".write": "!data.exists() || data.child('owner').val() === auth.uid"
    }
  }
}

CI Integration

Run your emulator-based rule tests in continuous integration so a risky rule change is caught before it reaches production. This turns security into a regression-tested guarantee.

Quick Check

Test your understanding of rules testing.

Recap

You can now validate rules with confidence.

  • Use the Rules Playground for quick manual checks
  • Use the Local Emulator for repeatable runs
  • Write tests with assertSucceeds / assertFails
  • Cover both access and validation, both directions
  • Run rule tests in CI

よくある質問

「セキュリティルールのテストとデバッグ」レッスンは無料ですか?

はい。「セキュリティルールのテストとデバッグ」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Firebase Auth & Realtime Database Appsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。

「セキュリティルールのテストとデバッグ」で何を学びますか?

リクエストをシミュレートし、Rules Playgroundを使い、エミュレーターで自動テストを作成し、拒否メッセージを読み取ることで、Realtime Databaseのルールに自信を持てるようにします。 ブラウザで直接実行するハンズオンコードでFirebase Auth & Realtime Database Appsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Firebase Auth & Realtime Database Appsを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのFirebase Auth & Realtime Database Appsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。

「セキュリティルールのテストとデバッグ」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このFirebase Auth & Realtime Database Appsレッスンでコードを書いて実行できますか?

はい。すべてのFirebase Auth & Realtime Database Appsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. セキュリティルール構文の理解
  2. ユーザーベースのアクセス制御
  3. ルールによるデータ検証
  4. セキュリティルールのテストとデバッグ
← Firebase Auth & Realtime Database Appsに戻る