0Pricing
Node.js Backend Development Bootcamp · Lektion

Rollenbasierte Zugriffskontrolle (RBAC)

Implementieren Sie eine rollenbasierte Autorisierung, um den Zugriff auf bestimmte Endpunkte anhand von Benutzerrollen und Berechtigungen einzuschränken.

Rollenbasierte Zugriffskontrolle (RBAC) ist eine kostenlose Node.js Backend Development Bootcamp-Lektion auf CoddyKit. Dies ist Lektion 6 von 6. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Node.js Backend Development Bootcamp-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Node.js Backend Development Bootcamp-Kurs umfasst insgesamt 6 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

What is RBAC?

Role-Based Access Control (RBAC) is a method of restricting access to resources based on the roles individual users have within an organization.

  • Instead of assigning permissions directly to users, permissions are assigned to roles.
  • Users are then assigned to roles, inheriting those permissions.
  • This simplifies security management, especially in larger applications.

Defining User Roles

First, we need to define the roles our application will use. These are typically broad categories like 'admin', 'editor', or 'basic_user'.

Using a Python Enum is a clean way to manage these roles:

from enum import Enum

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

# Example usage:
# role = UserRole.ADMIN

User Role Assignment

Every user in your system will have one or more roles associated with them. In a real FastAPI application, this information usually comes from the user's authenticated token (e.g., a JWT payload).

For this lesson, we'll use a simple User model and a mock function to represent the currently authenticated user with their assigned roles.

from typing import List
from pydantic import BaseModel
from enum import Enum

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user (normally from JWT)
async def get_current_user() -> User:
    # In a real app, this would decode a JWT
    # For demonstration, let's return a mock admin user
    return User(username="admin_user", roles=[UserRole.ADMIN])

Custom Role Dependency

FastAPI's dependency injection system is perfect for implementing RBAC. We can create a custom dependency that checks if the authenticated user has the necessary role(s) to access an endpoint.

  • This dependency will be reusable across many endpoints.
  • If the user doesn't have the required role, it raises an HTTPException.

Building the Role Checker

Our role_required dependency will take a list of roles. It will then fetch the current user and verify if any of their assigned roles match the required roles.

from fastapi import Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user
async def get_current_user() -> User:
    return User(username="test_user", roles=[UserRole.BASIC_USER])

def role_required(required_roles: List[UserRole]):
    async def role_checker(current_user: User = Depends(get_current_user)):
        if not any(role in current_user.roles for role in required_roles):
            raise HTTPException(
                status_code=status.HTTP_403_FORBIDDEN,
                detail="Not enough permissions"
            )
        return current_user
    return role_checker

Code: Admin-Only Endpoint

Here's a full FastAPI application demonstrating how to protect an endpoint so only users with the 'admin' role can access it. Run this code and try accessing /admin and /public.

from fastapi import FastAPI, Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
import uvicorn

app = FastAPI()

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user
# Change roles here to test different access levels
async def get_current_user() -> User:
    # Try changing to [UserRole.BASIC_USER] or [UserRole.ADMIN]
    return User(username="admin_user", roles=[UserRole.ADMIN])

def role_required(required_roles: List[UserRole]):
    async def role_checker(current_user: User = Depends(get_current_user)):
        if not any(role in current_user.roles for role in required_roles):
            raise HTTPException(
                status_code=status.HTTP_403_FORBIDDEN,
                detail="Not enough permissions"
            )
        return current_user
    return role_checker

@app.get("/public")
async def read_public_data():
    return {"message": "This is public data!"}

@app.get("/admin")
async def read_admin_data(current_user: User = Depends(role_required([UserRole.ADMIN]))):
    return {"message": f"Welcome, {current_user.username}! This is admin data."}

if __name__ == "__main__":
    uvicorn.run(app, host="0.0.0.0", port=8000)

Testing the Role Check

When you run the previous code:

  • Access http://127.0.0.1:8000/public: This should always work.
  • Access http://127.0.0.1:8000/admin: This will work if get_current_user returns a user with UserRole.ADMIN.

Try changing the mock user's roles in get_current_user to [UserRole.BASIC_USER] and rerun the app. You'll see a 403 Forbidden error when trying to access /admin.

Allowing Multiple Roles

Sometimes, an endpoint should be accessible by more than one role. For example, both 'admin' and 'editor' users might be allowed to update an article.

Our role_required dependency is already designed for this! It accepts a List[UserRole], and the any() check means access is granted if the user has any one of the specified roles.

Code: Multiple Role Access

This example shows an endpoint accessible by either an 'admin' or an 'editor'. Try changing the mock user's roles to [UserRole.EDITOR] and [UserRole.BASIC_USER] to observe the access control.

from fastapi import FastAPI, Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
import uvicorn

app = FastAPI()

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user
# Change roles here to test different access levels
async def get_current_user() -> User:
    # Try [UserRole.ADMIN], [UserRole.EDITOR], or [UserRole.BASIC_USER]
    return User(username="editor_user", roles=[UserRole.EDITOR])

def role_required(required_roles: List[UserRole]):
    async def role_checker(current_user: User = Depends(get_current_user)):
        if not any(role in current_user.roles for role in required_roles):
            raise HTTPException(
                status_code=status.HTTP_403_FORBIDDEN,
                detail="Not enough permissions"
            )
        return current_user
    return role_checker

@app.get("/edit_content")
async def edit_content(current_user: User = Depends(role_required([UserRole.ADMIN, UserRole.EDITOR]))):
    return {"message": f"Hello {current_user.username}! You can edit content."}

@app.get("/view_only")
async def view_only_content(current_user: User = Depends(role_required([UserRole.BASIC_USER]))):
    return {"message": f"Hello {current_user.username}! You can view content."}

if __name__ == "__main__":
    uvicorn.run(app, host="0.0.0.0", port=8000)

RBAC Implementation Check

You need to create an endpoint /dashboard that should only be accessible by users with the ADMIN role. Which of the following is the correct way to apply the role_required dependency?

RBAC Recap

You've learned how to implement Role-Based Access Control in your FastAPI applications:

  • Defined roles using Python Enum for clarity.
  • Understood how user roles are typically associated (e.g., via JWTs).
  • Created a reusable custom dependency (role_required) to check user roles.
  • Applied this dependency to endpoints to restrict access based on single or multiple roles.

RBAC is a powerful way to manage permissions, making your API more secure and maintainable!

Häufig gestellte Fragen

Ist die Lektion „Rollenbasierte Zugriffskontrolle (RBAC)“ kostenlos?

Ja — der vollständige Text von „Rollenbasierte Zugriffskontrolle (RBAC)“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Node.js Backend Development Bootcamp-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Node.js Backend Development Bootcamp-Kurs umfasst insgesamt 6 Lektionen.

Was lerne ich in „Rollenbasierte Zugriffskontrolle (RBAC)“?

Implementieren Sie eine rollenbasierte Autorisierung, um den Zugriff auf bestimmte Endpunkte anhand von Benutzerrollen und Berechtigungen einzuschränken. Du übst Node.js Backend Development Bootcamp mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Node.js Backend Development Bootcamp zu starten?

Keine Vorkenntnisse erforderlich. Node.js Backend Development Bootcamp auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 6 von 6.

Wie lange dauert die Lektion „Rollenbasierte Zugriffskontrolle (RBAC)“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Node.js Backend Development Bootcamp-Lektion Code schreiben und ausführen?

Ja. Jede Node.js Backend Development Bootcamp-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Benutzerregistrierung und Anmeldung
  2. JWT-Token-Erstellung und -Validierung
  3. JWT für zustandslose Authentifizierung
  4. Integration des OAuth2-Passwort-Flows
  5. Rollenbasierte Zugriffskontrolle
  6. Rollenbasierte Zugriffskontrolle (RBAC)
← Zurück zu Node.js Backend Development Bootcamp