Kurallarla Verileri Doğrulama
Gelen verileri doğrulamak, beklenen biçimlere uygun olmalarını sağlamak ve kötü amaçlı yazma işlemlerini önlemek için güvenlik kurallarını kullanın
Kurallarla Verileri Doğrulama, CoddyKit'te ücretsiz bir Firebase Auth & Realtime Database Apps dersidir. Bu, 4 dersinin 3. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Firebase Auth & Realtime Database Apps öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Firebase Auth & Realtime Database Apps kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Why Validate Data?
Welcome to Lesson 3! In this lesson, we'll learn how to use Firebase Realtime Database Security Rules to validate incoming data. This is super important to:
- Prevent bad or malicious data from entering your database.
- Maintain the integrity and consistency of your application's data.
- Ensure data conforms to expected formats and types.
Think of it as a bouncer for your database!
Introducing newData & .validate()
When data is written to your database, Firebase provides a special object called newData. This object represents the data that's about to be written.
We use the .validate() rule to define conditions that newData must meet. If these conditions aren't met, the write operation will be rejected.
Here's a basic example:
{
"rules": {
"posts": {
"$postId": {
// Allow anyone authenticated to write
".write": "auth != null",
// Validate that new posts must have 'title' and 'content'
".validate": "newData.hasChildren(['title', 'content'])"
}
}
}
}Checking Data Types
One of the most common validations is checking the data type. You can ensure fields are strings, numbers, booleans, or even null.
This helps prevent users from submitting, for example, a number where a name (string) is expected.
{
"rules": {
"users": {
"$userId": {
"name": { ".validate": "newData.isString()" },
"age": { ".validate": "newData.isNumber()" },
"isActive": { ".validate": "newData.isBoolean()" }
}
}
}
}Making Fields Mandatory
Sometimes, certain fields are absolutely required. You can use newData.hasChildren(['field1', 'field2']) to ensure multiple fields exist, or directly access a child to check its presence.
If a required field is missing, the write will fail.
{
"rules": {
"messages": {
"$messageId": {
".validate": "newData.hasChildren(['senderId', 'text'])"
}
}
}
}Controlling String Lengths
For text fields, you often want to limit the minimum or maximum length. This prevents overly short or excessively long inputs.
You can use the .length property on a string value.
{
"rules": {
"products": {
"$productId": {
"name": {
".validate": "newData.isString() && newData.val().length > 2 && newData.val().length < 50"
}
}
}
}
}Setting Number Ranges
For numerical data, you might need to ensure values fall within a specific range. For example, an age must be positive, or a score must be between 0 and 100.
You can use standard comparison operators (>, <, >=, <=).
{
"rules": {
"scores": {
"$scoreId": {
"value": {
".validate": "newData.isNumber() && newData.val() >= 0 && newData.val() <= 100"
}
}
}
}
}Advanced Pattern Matching
For more complex string formats, like emails or URLs, you can use regular expressions with the .matches() function.
Regular expressions are powerful patterns for matching text. They can seem intimidating at first, but are very useful!
{
"rules": {
"profiles": {
"$profileId": {
"email": {
// Basic email regex pattern validation
".validate": "newData.isString() && newData.val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i)"
}
}
}
}
}Combining Validation Rules
You'll often need to combine multiple validation checks. You can use logical operators:
&&(AND): All conditions must be true.||(OR): At least one condition must be true.
This allows for very flexible and robust validation logic.
{
"rules": {
"tasks": {
"$taskId": {
".validate": "newData.hasChildren(['title', 'status']) && newData.child('title').isString() && newData.child('title').val().length > 5"
}
}
}
}User Profile Validation Example
Let's put it all together with a comprehensive example for a user profile:
username: must be a string, at least 3 characters.email: must be a string and match an email regex.age: must be a number and at least 13.
{
"rules": {
"userProfiles": {
"$userId": {
".validate": "newData.hasChildren(['username', 'email', 'age']) && \
newData.child('username').isString() && \
newData.child('username').val().length >= 3 && \
newData.child('email').isString() && \
newData.child('email').val().matches(/^[A-Z0-9._%+-]+@[A-Z0-9.-]+\\.[A-Z]{2,4}$/i) && \
newData.child('age').isNumber() && \
newData.child('age').val() >= 13"
}
}
}
}Validate Your Knowledge
Consider a rule for a 'product' node. A product must have a 'name' (string, min 2 chars, max 100 chars) and a 'price' (number, greater than 0).
Recap: Data Integrity Secured
Great job! You've learned how to use Firebase Realtime Database Security Rules to validate data:
- The
newDataobject represents data being written. - The
.validate()rule enforces conditions onnewData. - You can check data types (
isString(),isNumber()). - Ensure required fields exist with
hasChildren(). - Validate string lengths (
.length) and number ranges (>,<). - Use
.matches()for complex pattern validation with regex. - Combine rules with
&&and||for powerful logic.
By validating data, you ensure your database remains clean and secure!
Sıkça Sorulan Sorular
“Kurallarla Verileri Doğrulama” dersi ücretsiz mi?
Evet — “Kurallarla Verileri Doğrulama” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Firebase Auth & Realtime Database Apps kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Firebase Auth & Realtime Database Apps kursu toplamda 4 dersten oluşur.
“Kurallarla Verileri Doğrulama” dersinde ne öğreneceğim?
Gelen verileri doğrulamak, beklenen biçimlere uygun olmalarını sağlamak ve kötü amaçlı yazma işlemlerini önlemek için güvenlik kurallarını kullanın Firebase Auth & Realtime Database Apps ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Firebase Auth & Realtime Database Apps öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Firebase Auth & Realtime Database Apps, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 3. dersidir.
“Kurallarla Verileri Doğrulama” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Firebase Auth & Realtime Database Apps dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Firebase Auth & Realtime Database Apps dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Güvenlik Kuralları Söz Dizimini Anlama
- Kullanıcı Tabanlı Erişim Denetimi
- Kurallarla Verileri Doğrulama
- Güvenlik Kurallarını Test Etme ve Hata Ayıklama