מאגר ידע

Firebase security rules

המאמר עדיין לא תורגם; הוא מוצג באנגלית.

Firebase apps send their config (API key, project id) to every visitor; the security rules decide what that config can read. Vigavo asks Firebase what an anonymous visitor can do:

  • firebase_rules_open (critical): a Firestore collection or the Realtime Database can be read without signing in. Vigavo tries the collection names it finds in your code plus common ones (users, orders, messages, …).
  • firebase_storage_open: files in Cloud Storage can be listed by anyone.

Only collection names, field names and counts are recorded, never the values.

Fixing

Replace open rules (allow read: if true; or test-mode rules) with rules that require request.auth and match the owner of each document. The fix prompt contains a starting point. Deploy the rules, then verify the fix.

Backups of Firebase data are not available yet; see Supported platforms.

נבדק לאחרונה 7 באוק׳ 2026, 0:00:00

עדיין תקועים? שלחו פנייה

משוב
סוג