Kullanıcı Verileri İçin Role Dayalı Erişim
Yöneticilere, üyelere ve konuklara ortak ve kişisel verilere farklı erişim düzeyleri vermek için Firebase Auth rollerini Realtime Database kurallarıyla birleştirin.
Kullanıcı Verileri İçin Role Dayalı Erişim, CoddyKit'te ücretsiz bir Firebase Auth & Realtime Database Apps dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Firebase Auth & Realtime Database Apps öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Firebase Auth & Realtime Database Apps kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Beyond Owner-Only Access
So far each user reads and writes their own data. Real apps need roles: an admin who moderates content, members who collaborate, and guests with read-only access.
Role-based access control (RBAC) layers permissions on top of authentication.
Where Roles Live
You can store a user's role in two places:
- A
rolesnode in the database, read inside rules - A custom claim on the auth token (set server-side)
Custom claims are faster to check; database roles are easier to change at runtime.
Roles in the Database
A simple model maps each uid to a role string. This data itself must be locked down so users cannot promote themselves.
{
"roles": {
"uid_alice": "admin",
"uid_bob": "member"
}
}Checking a Database Role in Rules
Rules can read other parts of the database with root. Here only admins may write to a shared config node.
{
"rules": {
"config": {
".write": "root.child('roles').child(auth.uid).val() === 'admin'"
}
}
}Custom Claims for Roles
With the Admin SDK you can attach a role to the token itself. This is checked without an extra database read.
await admin.auth().setCustomUserClaims(uid, { role: 'admin' });Checking Claims in Rules
Custom claims appear under auth.token. The rule becomes simpler and avoids a root lookup.
{
"rules": {
"config": {
".write": "auth.token.role === 'admin'"
}
}
}Reading the Claim Client-Side
The client can read its own claims to adjust the UI, for example showing an admin panel only to admins.
import { getAuth, getIdTokenResult } from 'firebase/auth';
const res = await getIdTokenResult(getAuth().currentUser);
if (res.claims.role === 'admin') showAdminPanel();Tiered Read Access
Different roles can have different read scopes. Members read shared docs; guests read only public ones.
{
"rules": {
"shared": {
".read": "auth.token.role === 'member' || auth.token.role === 'admin'"
}
}
}Protecting the Role Data Itself
Critically, users must not be able to edit their own role. Make the roles node writable only by admins (or only server-side), or self-escalation defeats the whole system.
{
"rules": {
"roles": {
".write": "auth.token.role === 'admin'"
}
}
}Claim Propagation Delay
After you change a custom claim, the user's existing token still has the old value until it refreshes (about an hour, or on forced refresh). Call getIdToken(true) client-side to pick up new roles immediately.
await getAuth().currentUser.getIdToken(true);Choosing an Approach
Use custom claims for stable, security-critical roles, and database roles when permissions change often or need to be queried. Many apps combine both.
Quick Check
Test your understanding of role-based access.
Recap
You can now grant tiered access by role.
- Store roles in the database or as custom claims
- Check database roles via
root, claims viaauth.token - Give roles different read/write scopes
- Lock down the role data so users cannot self-promote
- Refresh tokens to pick up new claims promptly
Yapay zeka eğitmeniyle Firebase Auth & Realtime Database Apps öğren — ücretsiz
Tarayıcında gerçek kod yaz ve çalıştır, 7/24 yapay zeka eğitmeninden anında yardım al; web'de ya da uygulamada kaldığın yerden devam et.
- Kurslar
- 11
- Dersler
- 44
Sıkça Sorulan Sorular
“Kullanıcı Verileri İçin Role Dayalı Erişim” dersi ücretsiz mi?
Evet — “Kullanıcı Verileri İçin Role Dayalı Erişim” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Firebase Auth & Realtime Database Apps kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Firebase Auth & Realtime Database Apps kursu toplamda 4 dersten oluşur.
“Kullanıcı Verileri İçin Role Dayalı Erişim” dersinde ne öğreneceğim?
Yöneticilere, üyelere ve konuklara ortak ve kişisel verilere farklı erişim düzeyleri vermek için Firebase Auth rollerini Realtime Database kurallarıyla birleştirin. Firebase Auth & Realtime Database Apps ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Firebase Auth & Realtime Database Apps öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Firebase Auth & Realtime Database Apps, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.
“Kullanıcı Verileri İçin Role Dayalı Erişim” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Firebase Auth & Realtime Database Apps dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Firebase Auth & Realtime Database Apps dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Kullanıcı Verilerini Kimlik Doğrulamayla Birleştirme
- Gerçek Zamanlı Kullanıcı Profilleri
- Ortak Veri Düzenleme
- Kullanıcı Verileri İçin Role Dayalı Erişim