ルールによるデータ検証
セキュリティルールで入力データを検証し、想定される形式に適合していることを確認するとともに、悪意のある書き込みを防ぎます。
「ルールによるデータ検証」はCoddyKit上の無料Firebase Auth & Realtime Database Appsレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはFirebase Auth & Realtime Database Apps学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Why Validate Data?
Welcome to Lesson 3! In this lesson, we'll learn how to use Firebase Realtime Database Security Rules to validate incoming data. This is super important to:
- Prevent bad or malicious data from entering your database.
- Maintain the integrity and consistency of your application's data.
- Ensure data conforms to expected formats and types.
Think of it as a bouncer for your database!
Introducing newData & .validate()
When data is written to your database, Firebase provides a special object called newData. This object represents the data that's about to be written.
We use the .validate() rule to define conditions that newData must meet. If these conditions aren't met, the write operation will be rejected.
Here's a basic example:
{
"rules": {
"posts": {
"$postId": {
// Allow anyone authenticated to write
".write": "auth != null",
// Validate that new posts must have 'title' and 'content'
".validate": "newData.hasChildren(['title', 'content'])"
}
}
}
}Checking Data Types
One of the most common validations is checking the data type. You can ensure fields are strings, numbers, booleans, or even null.
This helps prevent users from submitting, for example, a number where a name (string) is expected.
{
"rules": {
"users": {
"$userId": {
"name": { ".validate": "newData.isString()" },
"age": { ".validate": "newData.isNumber()" },
"isActive": { ".validate": "newData.isBoolean()" }
}
}
}
}Making Fields Mandatory
Sometimes, certain fields are absolutely required. You can use newData.hasChildren(['field1', 'field2']) to ensure multiple fields exist, or directly access a child to check its presence.
If a required field is missing, the write will fail.
{
"rules": {
"messages": {
"$messageId": {
".validate": "newData.hasChildren(['senderId', 'text'])"
}
}
}
}Controlling String Lengths
For text fields, you often want to limit the minimum or maximum length. This prevents overly short or excessively long inputs.
You can use the .length property on a string value.
{
"rules": {
"products": {
"$productId": {
"name": {
".validate": "newData.isString() && newData.val().length > 2 && newData.val().length < 50"
}
}
}
}
}Setting Number Ranges
For numerical data, you might need to ensure values fall within a specific range. For example, an age must be positive, or a score must be between 0 and 100.
You can use standard comparison operators (>, <, >=, <=).
{
"rules": {
"scores": {
"$scoreId": {
"value": {
".validate": "newData.isNumber() && newData.val() >= 0 && newData.val() <= 100"
}
}
}
}
}Advanced Pattern Matching
For more complex string formats, like emails or URLs, you can use regular expressions with the .matches() function.
Regular expressions are powerful patterns for matching text. They can seem intimidating at first, but are very useful!
{
"rules": {
"profiles": {
"$profileId": {
"email": {
// Basic email regex pattern validation
".validate": "newData.isString() && newData.val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i)"
}
}
}
}
}Combining Validation Rules
You'll often need to combine multiple validation checks. You can use logical operators:
&&(AND): All conditions must be true.||(OR): At least one condition must be true.
This allows for very flexible and robust validation logic.
{
"rules": {
"tasks": {
"$taskId": {
".validate": "newData.hasChildren(['title', 'status']) && newData.child('title').isString() && newData.child('title').val().length > 5"
}
}
}
}User Profile Validation Example
Let's put it all together with a comprehensive example for a user profile:
username: must be a string, at least 3 characters.email: must be a string and match an email regex.age: must be a number and at least 13.
{
"rules": {
"userProfiles": {
"$userId": {
".validate": "newData.hasChildren(['username', 'email', 'age']) && \
newData.child('username').isString() && \
newData.child('username').val().length >= 3 && \
newData.child('email').isString() && \
newData.child('email').val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i) && \
newData.child('age').isNumber() && \
newData.child('age').val() >= 13"
}
}
}
}Validate Your Knowledge
Consider a rule for a 'product' node. A product must have a 'name' (string, min 2 chars, max 100 chars) and a 'price' (number, greater than 0).
Recap: Data Integrity Secured
Great job! You've learned how to use Firebase Realtime Database Security Rules to validate data:
- The
newDataobject represents data being written. - The
.validate()rule enforces conditions onnewData. - You can check data types (
isString(),isNumber()). - Ensure required fields exist with
hasChildren(). - Validate string lengths (
.length) and number ranges (>,<). - Use
.matches()for complex pattern validation with regex. - Combine rules with
&&and||for powerful logic.
By validating data, you ensure your database remains clean and secure!
よくある質問
「ルールによるデータ検証」レッスンは無料ですか?
はい。「ルールによるデータ検証」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Firebase Auth & Realtime Database Appsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Firebase Auth & Realtime Database Appsコースには全4レッスンが含まれています。
「ルールによるデータ検証」で何を学びますか?
セキュリティルールで入力データを検証し、想定される形式に適合していることを確認するとともに、悪意のある書き込みを防ぎます。 ブラウザで直接実行するハンズオンコードでFirebase Auth & Realtime Database Appsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Firebase Auth & Realtime Database Appsを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのFirebase Auth & Realtime Database Appsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。
「ルールによるデータ検証」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このFirebase Auth & Realtime Database Appsレッスンでコードを書いて実行できますか?
はい。すべてのFirebase Auth & Realtime Database Appsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。