Skip to main content

Basic Permissions

CloudBase provides a multi-layered data permission management mechanism to ensure data security while meeting the permission control needs of different business scenarios.

Database read/write operations use the _openid field to determine data ownership.

Permission Management System

CloudBase data permission management includes two levels:

Permission TypeControl GranularityApplicable ScenariosConfiguration Complexity
Basic Permission ControlCollection LevelSimple permission requirementsLow
Security Rules PermissionDocument LevelComplex business logicHigh

Basic Permission Control

Configuration Method

On the CloudBase Console/Document Database/Collection Management page, set corresponding permissions for each collection:

Permission Options

Basic permission control provides four preset permission types, choose based on user identity and data characteristics:

Permission TypeApplicable ScenariosUsage Recommendations
Read all data, modify own dataPublic content, such as articles, productsSuitable for content display applications
Read and modify own dataPrivate data, such as user profilesSuitable for personal information management
Read all data, no data modificationConfiguration data, such as system settingsSuitable for read-only configuration and reference data
No permissionsSensitive data, such as financial informationSuitable for sensitive data that requires server-side processing

Security Rules Permission

Security rules permission is the document-level permission control capability provided by CloudBase database, which has higher flexibility and precision compared to basic permission control.

For details, please refer to Database Security Rules Detailed Guide