0Pricing
Firebase Auth & Realtime Database Apps · Урок

Синтаксис правил безопасности

Освойте синтаксис и структуру правил безопасности Firebase Realtime Database для определения разрешений доступа

«Синтаксис правил безопасности» — бесплатный урок Firebase Auth & Realtime Database Apps на CoddyKit. Это урок 1 из 4. Ты можешь прочитать весь урок бесплатно ниже — а потом практиковать его прямо в браузере с встроенным редактором кода и ИИ-репетитором 24/7. Это часть пути обучения Firebase Auth & Realtime Database Apps, и твой прогресс синхронизируется между веб-версией и приложением CoddyKit. Курс Firebase Auth & Realtime Database Apps содержит 4 уроков всего.

Части этого урока еще не переведены и отображаются на английском.

Why Security Rules?

Welcome to Realtime Database Security Rules! These rules are super important for keeping your data safe and controlling who can do what in your Firebase app.

Think of them as bouncers for your database: they check every request to read, write, or update data, and decide if it's allowed or not.

Your Rules File

Firebase Realtime Database Security Rules are defined in a JSON file, usually named rules.json. You'll upload this file to your Firebase project.

The entire set of rules is wrapped under a top-level "rules" key, like this:

{
  "rules": {
    // Your security rules go here!
  }
}

Default Open Rules

When you first create a Realtime Database, Firebase often provides a very open set of rules. This allows anyone to read and write data, which is great for getting started quickly, but terrible for production!

These rules look like this:

{
  "rules": {
    ".read": "true",
    ".write": "true"
  }
}

Targeting Data Paths

Rules are applied based on the path to your data. You nest rules within the "rules" object to target specific parts of your database, just like folders in a file system.

For example, to set rules for /users or /messages:

{
  "rules": {
    "users": {
      // Rules for data under /users
    },
    "messages": {
      // Rules for data under /messages
    }
  }
}

Basic Read Permissions

The ".read" rule determines who can retrieve data from a specific path. If a read request matches a path with ".read": "true", it's allowed. If it's "false", it's denied.

Here's how you might set read permissions:

{
  "rules": {
    "publicPosts": {
      ".read": "true" // Anyone can read blog posts
    },
    "secretDocs": {
      ".read": "false" // No one can read secret documents
    }
  }
}

Basic Write Permissions

Similarly, the ".write" rule controls who can create, update, or delete data at a given path. Setting it to "true" allows writes, and "false" denies them.

Let's look at some write rule examples:

{
  "rules": {
    "guestbook": {
      ".write": "true" // Anyone can sign the guestbook
    },
    "adminSettings": {
      ".write": "false" // No one can change admin settings yet
    }
  }
}

Combining Read & Write

You can define both ".read" and ".write" rules for the same path. Firebase evaluates them independently.

For example, to make a path readable by everyone but writable by no one (yet):

{
  "rules": {
    "announcements": {
      ".read": "true",  // Everyone can see announcements
      ".write": "false" // No one can post new announcements
    }
  }
}

Dynamic Paths with Wildcards

What if you have many items under a path, like individual user profiles (/users/user123, /users/user456)? You don't want to write a rule for each one!

Use a wildcard variable, prefixed with $, to match any child node. This variable can then be used within the rule itself.

{
  "rules": {
    "profileData": {
      "$userId": {
        ".read": "true",  // Anyone can read any user's profile
        ".write": "false" // But no one can edit them yet
      }
    }
  }
}

`auth` & `data`: Rule Helpers

When writing more advanced rules, you'll often need to check who is making the request or what data already exists. Firebase provides special variables for this:

  • auth: Contains information about the currently authenticated user (if any).
  • data: Refers to the data that already exists at the path being accessed.
  • newData: Refers to the data being written (only for write/validate rules).

These let you create smart rules, like "only the owner can edit their profile." We'll dive into these in upcoming lessons!

Syntax Check

Given the Firebase Realtime Database Security Rules below, which statement is true?

{
  "rules": {
    "posts": {
      ".read": "true",
      "comments": {
        ".write": "false"
      }
    },
    "users": {
      "$userId": {
        ".read": "true"
      }
    }
  }
}

Lesson Summary

Great job! In this lesson, we covered the foundational syntax of Firebase Realtime Database Security Rules:

  • Rules live in a rules.json file.
  • Rules are nested to target specific data paths.
  • ".read" and ".write" control read and write access.
  • Wildcards ($variable) make rules dynamic for child nodes.
  • You got a sneak peek at context variables like auth and data.

Next, we'll dive deeper into using these rules for user-based access control!

Часто задаваемые вопросы

Урок «Синтаксис правил безопасности» бесплатный?

Да — полный текст урока «Синтаксис правил безопасности» бесплатно доступен здесь в веб-версии. Чтобы практиковать его интерактивно (встроенный редактор кода и ИИ-репетитор 24/7) и разблокировать остальной курс Firebase Auth & Realtime Database Apps, подпишись на CoddyKit PRO. Курс Firebase Auth & Realtime Database Apps содержит 4 уроков всего.

Чему я научусь в уроке «Синтаксис правил безопасности»?

Освойте синтаксис и структуру правил безопасности Firebase Realtime Database для определения разрешений доступа Ты практикуешь Firebase Auth & Realtime Database Apps с помощью реального кода, который запускаешь прямо в браузере, и ИИ-репетитор 24/7 отвечает на твои вопросы во время урока.

Нужен ли мне опыт, чтобы начать Firebase Auth & Realtime Database Apps?

Предыдущий опыт не требуется. Firebase Auth & Realtime Database Apps на CoddyKit структурирован для всех уровней — от новичков до продвинутых, поэтому ты можешь начать отсюда или с самого начала и учиться в своем темпе. Это урок 1 из 4.

Сколько времени занимает урок «Синтаксис правил безопасности»?

Большинство уроков CoddyKit занимают около 5–10 минут. Каждый из них компактный и интерактивный, поэтому ты постоянно делаешь прогресс и продолжаешь с того же места в веб-версии и приложении.

Можно ли писать и запускать код в этом уроке Firebase Auth & Realtime Database Apps?

Да. Каждый урок Firebase Auth & Realtime Database Apps включает встроенный редактор кода, поэтому ты пишешь и запускаешь реальный код прямо в браузере и получаешь моментальную обратную связь от AI — локальная установка не требуется.

Все уроки этого курса

  1. Синтаксис правил безопасности
  2. Управление доступом на основе пользователей
  3. Проверка данных с помощью правил
  4. Тестирование и отладка правил безопасности
← Назад к Firebase Auth & Realtime Database Apps