0Pricing
Firebase Auth & Realtime Database Apps · Lekcja

Kontrola dostępu oparta na użytkownikach

Zaimplementuj reguły przyznające lub odmawiające dostępu do odczytu i zapisu na podstawie identyfikatorów uwierzytelnionych użytkowników oraz ich ról.

Kontrola dostępu oparta na użytkownikach to bezpłatna lekcja Firebase Auth & Realtime Database Apps na CoddyKit. To lekcja 2 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Firebase Auth & Realtime Database Apps, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Firebase Auth & Realtime Database Apps zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

Control Access by User

Welcome to this lesson! In secure applications, it's crucial to control who can access what data. This is known as User-Based Access Control.

Firebase Realtime Database Security Rules allow you to define precise permissions based on the user who is currently logged in.

Meet the 'auth' Variable

Inside your security rules, Firebase provides a special auth variable. This variable contains information about the currently authenticated user.

  • auth.uid: The unique ID of the logged-in user.
  • auth.token: An object containing custom claims and other token details (e.g., email).

If no user is logged in, auth will be null.

Authenticated Users Only

The simplest form of user-based access is to ensure only authenticated users can read or write any data.

You can achieve this by checking if the auth variable is not null.

{
  "rules": {
    ".read": "auth != null",
    ".write": "auth != null"
  }
}

Users Read Their Own Data

Often, you want users to only read data that belongs to them. Imagine a /users node where each user has a sub-node with their UID.

We can use a wildcard variable ($uid) in the path to match the current user's ID.

{
  "rules": {
    "users": {
      "$uid": {
        ".read": "auth.uid == $uid"
      }
    }
  }
}

Users Write Their Own Data

Similarly, you can restrict write access so users can only modify their own data. This prevents one user from changing another's profile.

The rule is very similar to the read rule, just applied to .write.

{
  "rules": {
    "users": {
      "$uid": {
        ".write": "auth.uid == $uid"
      }
    }
  }
}

Read & Write Your Own Profile

Let's combine the read and write rules. This common pattern allows users full control over their own specific data node, often used for user profiles.

Here, $userId is a placeholder for an actual user's UID.

{
  "rules": {
    "profiles": {
      "$userId": {
        ".read": "auth.uid == $userId",
        ".write": "auth.uid == $userId"
      }
    }
  }
}

Post Ownership Example

Consider a 'posts' section where anyone can read posts, but only the creator can edit or delete their own post.

We assume each post object has an ownerId field. We use data.ownerId to refer to the existing owner ID in the database.

{
  "rules": {
    "posts": {
      "$postId": {
        ".read": "true",
        ".write": "auth.uid == data.ownerId"
      }
    }
  }
}

Validating Data with Auth

Beyond just who can write, you can also validate what data they write. For instance, ensuring that when a user creates an item, they correctly set themselves as the owner.

The newData variable refers to the data being written.

{
  "rules": {
    "items": {
      "$itemId": {
        ".write": "auth != null",
        ".validate": "newData.ownerId == auth.uid"
      }
    }
  }
}

Introducing User Roles

For more complex access, you can define roles like 'admin' or 'moderator'. These roles are often stored as custom claims in the user's authentication token.

You can then check for these roles in your rules using auth.token.

{
  "rules": {
    "adminContent": {
      ".read": "auth.token.isAdmin == true",
      ".write": "auth.token.isAdmin == true"
    }
  }
}

Quick Check on Access

Consider the following Realtime Database Security Rules:

{ "rules": { "messages": { "$messageId": { ".read": "auth.uid == data.senderId", ".write": "auth.uid == data.senderId" } } } }

If user "user123" is authenticated and tries to read a message where data.senderId is "user456", will they succeed?

Recap: User Access Rules

You've learned how to implement powerful user-based access control in Firebase Realtime Database Security Rules!

  • The auth variable provides current user details.
  • You can restrict access to authenticated users (auth != null).
  • Users can be granted read/write access to their own specific data using auth.uid == $uid.
  • You can validate incoming data using newData and auth.uid.
  • Roles can be used to grant access to specific user groups.

Next, explore how to validate the data itself!

Często zadawane pytania

Czy lekcja „Kontrola dostępu oparta na użytkownikach” jest bezpłatna?

Tak — pełny tekst „Kontrola dostępu oparta na użytkownikach” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Firebase Auth & Realtime Database Apps, przejdź na CoddyKit PRO. Kurs Firebase Auth & Realtime Database Apps zawiera 4 lekcji w sumie.

Co nauczysz się w „Kontrola dostępu oparta na użytkownikach”?

Zaimplementuj reguły przyznające lub odmawiające dostępu do odczytu i zapisu na podstawie identyfikatorów uwierzytelnionych użytkowników oraz ich ról. Ćwiczysz Firebase Auth & Realtime Database Apps z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć Firebase Auth & Realtime Database Apps?

Nie wymagamy żadnego doświadczenia. Firebase Auth & Realtime Database Apps w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 2 z 4.

Ile czasu zajmuje lekcja „Kontrola dostępu oparta na użytkownikach”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji Firebase Auth & Realtime Database Apps?

Tak. Każda lekcja Firebase Auth & Realtime Database Apps zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. Zrozumienie składni reguł bezpieczeństwa
  2. Kontrola dostępu oparta na użytkownikach
  3. Walidacja danych za pomocą reguł
  4. Testowanie i debugowanie reguł bezpieczeństwa
← Powrót do Firebase Auth & Realtime Database Apps