أنماط التحكم في الوصول
نفّذ آليات متينة للتحكم في الوصول باستخدام أنماط `Ownable` و`Pausable` والتحكم في الوصول المستند إلى الأدوار (RBAC).
أنماط التحكم في الوصول درس مجاني في Blockchain Smart Contracts with Solidity على CoddyKit. هذا هو الدرس 2 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Blockchain Smart Contracts with Solidity، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Blockchain Smart Contracts with Solidity 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
What is Access Control?
In smart contracts, access control defines who can perform specific actions. It's like setting permissions on a file or folder.
Without proper access control, anyone could call sensitive functions, leading to vulnerabilities or unintended behavior.
Why It's Crucial
Imagine a contract that manages funds or critical system settings. You wouldn't want just anyone to be able to:
- Withdraw all funds.
- Change the contract's owner.
- Pause essential operations.
Access control is a fundamental security measure.
The `onlyOwner` Modifier
A common pattern is to restrict certain functions to the contract's owner (the address that deployed it).
This is often achieved using a modifier, a special keyword in Solidity that can alter the behavior of a function.
Custom `onlyOwner` Example
Here's how you might manually implement an onlyOwner modifier and use it:
pragma solidity ^0.8.0;
contract MyBasicOwnable {
address public owner;
constructor() {
owner = msg.sender;
}
modifier onlyOwner() {
require(msg.sender == owner, "Not owner");
_;
}
function setGreeting(string memory _text) public onlyOwner {
// Only the owner can call this
// ... (e.g., update a greeting message)
}
}OpenZeppelin's `Ownable`
While you can write your own, it's best practice to use battle-tested libraries. OpenZeppelin provides a secure and standardized Ownable contract.
By inheriting from Ownable, your contract gets the owner state variable and the onlyOwner modifier automatically.
Using OpenZeppelin `Ownable`
Simply import and inherit Ownable. The contract deployer automatically becomes the owner.
pragma solidity ^0.8.0;
import "@openzeppelin/contracts/access/Ownable.sol";
contract MyOzOwnable is Ownable {
uint256 public value;
function setValue(uint256 _newValue) public onlyOwner {
value = _newValue;
}
function getValue() public view returns (uint256) {
return value;
}
}The `Pausable` Pattern
The Pausable pattern allows a contract to be put into a 'paused' state, preventing certain functions from being called.
This is crucial for emergency situations, like discovering a critical bug or reacting to a hack, giving developers time to mitigate issues.
Using OpenZeppelin `Pausable`
OpenZeppelin's Pausable provides paused state, whenNotPaused and whenPaused modifiers, and _pause()/_unpause() functions.
pragma solidity ^0.8.0;
import "@openzeppelin/contracts/security/Pausable.sol";
import "@openzeppelin/contracts/access/Ownable.sol";
contract MyPausableContract is Pausable, Ownable {
uint256 public counter;
function increment() public whenNotPaused {
counter++;
}
function pauseContract() public onlyOwner {
_pause(); // Only owner can pause
}
function unpauseContract() public onlyOwner {
_unpause(); // Only owner can unpause
}
}Role-Based Access Control (RBAC)
For more complex contracts, a single 'owner' might not be enough. Role-Based Access Control (RBAC) allows defining multiple roles (e.g., 'minter', 'admin', 'pauser').
OpenZeppelin's AccessControl contract helps manage these roles efficiently.
Using OpenZeppelin `AccessControl`
Define roles as bytes32 constants. The deployer automatically gets DEFAULT_ADMIN_ROLE, which can grant/revoke other roles.
pragma solidity ^0.8.0;
import "@openzeppelin/contracts/access/AccessControl.sol";
contract MyRBACContract is AccessControl {
bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
bytes32 public constant PAUSER_ROLE = keccak256("PAUSER_ROLE");
constructor() {
_grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
_grantRole(MINTER_ROLE, msg.sender); // Deployer is also a minter
}
function mint(address to, uint256 amount) public onlyRole(MINTER_ROLE) {
// Logic to mint tokens
}
function systemPause() public onlyRole(PAUSER_ROLE) {
// Logic to pause critical system functions
}
}Access Control Check
Which of the following are benefits of implementing access control patterns like Ownable, Pausable, or AccessControl in smart contracts?
Recap: Access Control Patterns
You've learned about essential access control patterns in Solidity:
Ownable: Restricts functions to a single owner, often the contract deployer.Pausable: Allows for emergency pausing/unpausing of contract functionality.AccessControl(RBAC): Provides flexible, role-based permissions for more complex scenarios.
These patterns are critical for building robust and secure smart contracts, often leveraged from OpenZeppelin's battle-tested libraries.
الأسئلة الشائعة
هل درس «أنماط التحكم في الوصول» مجاني؟
نعم — نص درس «أنماط التحكم في الوصول» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Blockchain Smart Contracts with Solidity، انتقل إلى CoddyKit PRO. تتضمن دورة Blockchain Smart Contracts with Solidity 4 دروس في المجموع.
ماذا ستتعلم في «أنماط التحكم في الوصول»؟
نفّذ آليات متينة للتحكم في الوصول باستخدام أنماط `Ownable` و`Pausable` والتحكم في الوصول المستند إلى الأدوار (RBAC). تتمرن على Blockchain Smart Contracts with Solidity مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ Blockchain Smart Contracts with Solidity؟
لا تُشترط خبرة سابقة. Blockchain Smart Contracts with Solidity على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 2 من أصل 4.
كم من الوقت يستغرق درس «أنماط التحكم في الوصول»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس Blockchain Smart Contracts with Solidity هذا؟
نعم. كل درس في Blockchain Smart Contracts with Solidity يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- الثغرات الشائعة (إعادة الدخول وغيرها)
- أنماط التحكم في الوصول
- البرمجة الآمنة باستخدام SafeMath
- التدقيق والاختبار ومكافآت اكتشاف الأخطاء