0Pricing
Firebase Auth & Realtime Database Apps · บทเรียน

การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ

ใช้กฎความปลอดภัยตรวจสอบข้อมูลขาเข้า เพื่อให้เป็นไปตามรูปแบบที่คาดไว้และป้องกันการเขียนข้อมูลที่เป็นอันตราย

การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ เป็นบทเรียน Firebase Auth & Realtime Database Apps ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Firebase Auth & Realtime Database Apps และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Firebase Auth & Realtime Database Apps มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

Why Validate Data?

Welcome to Lesson 3! In this lesson, we'll learn how to use Firebase Realtime Database Security Rules to validate incoming data. This is super important to:

  • Prevent bad or malicious data from entering your database.
  • Maintain the integrity and consistency of your application's data.
  • Ensure data conforms to expected formats and types.

Think of it as a bouncer for your database!

Introducing newData & .validate()

When data is written to your database, Firebase provides a special object called newData. This object represents the data that's about to be written.

We use the .validate() rule to define conditions that newData must meet. If these conditions aren't met, the write operation will be rejected.

Here's a basic example:

{
  "rules": {
    "posts": {
      "$postId": {
        // Allow anyone authenticated to write
        ".write": "auth != null",
        // Validate that new posts must have 'title' and 'content'
        ".validate": "newData.hasChildren(['title', 'content'])"
      }
    }
  }
}

Checking Data Types

One of the most common validations is checking the data type. You can ensure fields are strings, numbers, booleans, or even null.

This helps prevent users from submitting, for example, a number where a name (string) is expected.

{
  "rules": {
    "users": {
      "$userId": {
        "name": { ".validate": "newData.isString()" },
        "age": { ".validate": "newData.isNumber()" },
        "isActive": { ".validate": "newData.isBoolean()" }
      }
    }
  }
}

Making Fields Mandatory

Sometimes, certain fields are absolutely required. You can use newData.hasChildren(['field1', 'field2']) to ensure multiple fields exist, or directly access a child to check its presence.

If a required field is missing, the write will fail.

{
  "rules": {
    "messages": {
      "$messageId": {
        ".validate": "newData.hasChildren(['senderId', 'text'])"
      }
    }
  }
}

Controlling String Lengths

For text fields, you often want to limit the minimum or maximum length. This prevents overly short or excessively long inputs.

You can use the .length property on a string value.

{
  "rules": {
    "products": {
      "$productId": {
        "name": {
          ".validate": "newData.isString() && newData.val().length > 2 && newData.val().length < 50"
        }
      }
    }
  }
}

Setting Number Ranges

For numerical data, you might need to ensure values fall within a specific range. For example, an age must be positive, or a score must be between 0 and 100.

You can use standard comparison operators (>, <, >=, <=).

{
  "rules": {
    "scores": {
      "$scoreId": {
        "value": {
          ".validate": "newData.isNumber() && newData.val() >= 0 && newData.val() <= 100"
        }
      }
    }
  }
}

Advanced Pattern Matching

For more complex string formats, like emails or URLs, you can use regular expressions with the .matches() function.

Regular expressions are powerful patterns for matching text. They can seem intimidating at first, but are very useful!

{
  "rules": {
    "profiles": {
      "$profileId": {
        "email": {
          // Basic email regex pattern validation
          ".validate": "newData.isString() && newData.val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i)"
        }
      }
    }
  }
}

Combining Validation Rules

You'll often need to combine multiple validation checks. You can use logical operators:

  • && (AND): All conditions must be true.
  • || (OR): At least one condition must be true.

This allows for very flexible and robust validation logic.

{
  "rules": {
    "tasks": {
      "$taskId": {
        ".validate": "newData.hasChildren(['title', 'status']) && newData.child('title').isString() && newData.child('title').val().length > 5"
      }
    }
  }
}

User Profile Validation Example

Let's put it all together with a comprehensive example for a user profile:

  • username: must be a string, at least 3 characters.
  • email: must be a string and match an email regex.
  • age: must be a number and at least 13.
{
  "rules": {
    "userProfiles": {
      "$userId": {
        ".validate": "newData.hasChildren(['username', 'email', 'age']) && \
                      newData.child('username').isString() && \
                      newData.child('username').val().length >= 3 && \
                      newData.child('email').isString() && \
                      newData.child('email').val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i) && \
                      newData.child('age').isNumber() && \
                      newData.child('age').val() >= 13"
      }
    }
  }
}

Validate Your Knowledge

Consider a rule for a 'product' node. A product must have a 'name' (string, min 2 chars, max 100 chars) and a 'price' (number, greater than 0).

Recap: Data Integrity Secured

Great job! You've learned how to use Firebase Realtime Database Security Rules to validate data:

  • The newData object represents data being written.
  • The .validate() rule enforces conditions on newData.
  • You can check data types (isString(), isNumber()).
  • Ensure required fields exist with hasChildren().
  • Validate string lengths (.length) and number ranges (>, <).
  • Use .matches() for complex pattern validation with regex.
  • Combine rules with && and || for powerful logic.

By validating data, you ensure your database remains clean and secure!

คำถามที่พบบ่อย

บทเรียน “การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Firebase Auth & Realtime Database Apps ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Firebase Auth & Realtime Database Apps มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ”

ใช้กฎความปลอดภัยตรวจสอบข้อมูลขาเข้า เพื่อให้เป็นไปตามรูปแบบที่คาดไว้และป้องกันการเขียนข้อมูลที่เป็นอันตราย คุณปฏิบัติ Firebase Auth & Realtime Database Apps ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Firebase Auth & Realtime Database Apps หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Firebase Auth & Realtime Database Apps บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน

บทเรียน “การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Firebase Auth & Realtime Database Apps นี้ได้ไหม

ได้ บทเรียน Firebase Auth & Realtime Database Apps ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. ทำความเข้าใจไวยากรณ์ของกฎความปลอดภัย
  2. การควบคุมการเข้าถึงตามผู้ใช้
  3. การตรวจสอบความถูกต้องของข้อมูลด้วยกฎ
  4. การทดสอบและแก้ไขข้อบกพร่องของกฎความปลอดภัย
← กลับไปที่ Firebase Auth & Realtime Database Apps