小编Tho*_*man的帖子

Firestore 安全访问角色系统

我知道有很多关于使用安全规则在 firestore 上创建角色系统的线程,但我仍然无法做到这一点。我希望能够拥有三种不同的角色,以及三种不同的访问级别。

  • 管理员:可以读取和写入组织内的任何内容
  • 经理:可以阅读组织内的任何内容,但不能写,除非是他们自己的文件
  • 员工:可以读取和更新自己的数据

我找到了谷歌关于此主题的文档(https://firebase.google.com/docs/firestore/solutions/role-based-access),但我不希望每个用户和机构都有每个经理或管理员,因为那是太多的重复数据。此外,角色应适用于组织内的任何地方,每个子集合不应有所不同。

我的数据库:

organisations{
    organisation1{
    <data about organisation>
       establishments{
           establishment1{
              <data about establishment>
           }
           establishment2{
               <data about establishment>
           }
       }
       people{
           user1{
               <data about user>
               userId: <UID from authentication>
               accountType: <Administrator, Manager or Employee>
           }
           user2{
               <data about user>
               userId: <UID from authentication>
               accountType: <Administrator, Manager or Employee>
           }
       }
    }
    organisation2{
    <data about organisation>
       establishments{
           establishment1{
              <data about establishment>
           }
           establishment2{
               <data about establishment>
           }
       }
       people{
           user1{
               <data about user>
               userId: …
Run Code Online (Sandbox Code Playgroud)

firebase firebase-security firebase-authentication google-cloud-firestore

2
推荐指数
1
解决办法
517
查看次数