0Pricing
Spring Boot 4 Microservices & REST APIs · Leçon

Contrôle d’accès fondé sur les rôles

Configurez une autorisation fondée sur les rôles afin de définir des permissions d’accès précises pour différents rôles utilisateur.

Contrôle d’accès fondé sur les rôles est une leçon Spring Boot 4 Microservices & REST APIs gratuite sur CoddyKit. Ceci est la leçon 3 sur 3. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Spring Boot 4 Microservices & REST APIs, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Spring Boot 4 Microservices & REST APIs comprend 3 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Intro to Role-Based Access

Role-Based Access Control (RBAC) is a method of restricting system access based on the roles of individual users.

Instead of assigning permissions directly to users, you assign permissions to roles, and then assign roles to users.

  • Simplifies security management.
  • Improves security policy enforcement.
  • Easier to audit and maintain.

Benefits of RBAC

RBAC offers several advantages for securing your applications:

  • Scalability: Easily manage access for many users and resources as your application grows.
  • Flexibility: Roles can be changed or updated without modifying individual user permissions.
  • Compliance: Helps meet regulatory requirements by clearly defining who can do what.

Representing User Roles

In Spring Security, roles are typically represented as simple strings, often prefixed with ROLE_ (e.g., ROLE_ADMIN, ROLE_USER).

It's good practice to define these as constants or enums to avoid typos.

public enum UserRole {
  ADMIN,
  USER
}

Spring Security automatically adds the ROLE_ prefix when you use expressions like hasRole('ADMIN').

public enum UserRole {
  ADMIN,
  USER
}

Basic Security Setup

To enable method-level security and configure users with roles, we set up a SecurityFilterChain bean.

This example defines an in-memory user 'admin' with ROLE_ADMIN and 'user' with ROLE_USER.

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true) // Enable @PreAuthorize
public class RbacApplication {

    public static void main(String[] args) {
        SpringApplication.run(RbacApplication.class, args);
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(authorize -> authorize
                .anyRequest().authenticated()
            )
            .httpBasic(org.springframework.security.config.Customizer.withDefaults());
        return http.build();
    }

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails admin = User.withDefaultPasswordEncoder()
            .username("admin")
            .password("password")
            .roles("ADMIN")
            .build();
        UserDetails user = User.withDefaultPasswordEncoder()
            .username("user")
            .password("password")
            .roles("USER")
            .build();
        return new InMemoryUserDetailsManager(admin, user);
    }
}

@RestController
class PlaceholderController {
    @GetMapping("/")
    public String home() {
        return "Welcome to RBAC Demo!";
    }
}

Applying Role Constraints

Spring Security's @PreAuthorize annotation allows you to define access rules directly on controller methods.

It uses Spring Expression Language (SpEL) to evaluate conditions before a method is executed.

@PreAuthorize("hasRole('ADMIN')")

This ensures only users with the ADMIN role can call the method.

@PreAuthorize("hasRole('ADMIN')")

Exclusive Admin Access

Let's create an endpoint that only users with the ADMIN role can access. If a USER tries to access it, they will get a 403 Forbidden error.

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true)
public class RbacApplication {

    public static void main(String[] args) {
        SpringApplication.run(RbacApplication.class, args);
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(authorize -> authorize
                .anyRequest().authenticated()
            )
            .httpBasic(org.springframework.security.config.Customizer.withDefaults());
        return http.build();
    }

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails admin = User.withDefaultPasswordEncoder()
            .username("admin")
            .password("password")
            .roles("ADMIN")
            .build();
        UserDetails user = User.withDefaultPasswordEncoder()
            .username("user")
            .password("password")
            .roles("USER")
            .build();
        return new InMemoryUserDetailsManager(admin, user);
    }
}

@RestController
class AdminController {

    @GetMapping("/admin/dashboard")
    @PreAuthorize("hasRole('ADMIN')")
    public String getAdminDashboard() {
        return "Welcome, Admin! This is your dashboard.";
    }

    @GetMapping("/")
    public String home() {
        return "Welcome to RBAC Demo!";
    }
}

Granting Multiple Roles

Sometimes, an endpoint should be accessible by more than one role. You can use hasAnyRole() for this.

For example, a dashboard might be visible to both ADMIN and regular USER roles.

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true)
public class RbacApplication {

    public static void main(String[] args) {
        SpringApplication.run(RbacApplication.class, args);
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(authorize -> authorize
                .anyRequest().authenticated()
            )
            .httpBasic(org.springframework.security.config.Customizer.withDefaults());
        return http.build();
    }

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails admin = User.withDefaultPasswordEncoder()
            .username("admin")
            .password("password")
            .roles("ADMIN")
            .build();
        UserDetails user = User.withDefaultPasswordEncoder()
            .username("user")
            .password("password")
            .roles("USER")
            .build();
        return new InMemoryUserDetailsManager(admin, user);
    }
}

@RestController
class MultiRoleController {

    @GetMapping("/dashboard")
    @PreAuthorize("hasAnyRole('ADMIN', 'USER')")
    public String getUserDashboard() {
        return "Hello! Welcome to your dashboard.";
    }

    @GetMapping("/admin/settings")
    @PreAuthorize("hasRole('ADMIN')")
    public String getAdminSettings() {
        return "Admin settings page.";
    }

    @GetMapping("/")
    public String home() {
        return "Welcome to RBAC Demo!";
    }
}

Custom Access Decisions

While hasRole() and hasAnyRole() cover many cases, Spring Security allows more complex access rules.

You can use SpEL to check multiple conditions, like hasRole('ADMIN') and hasIpAddress('192.168.1.0/24').

For very complex or dynamic logic, you can implement custom PermissionEvaluator beans.

Testing Your RBAC

You can test your RBAC configuration by running your Spring Boot application and using a tool like Postman or curl:

  • Log in as 'admin' (user: admin, pass: password) and try to access all endpoints.
  • Log in as 'user' (user: user, pass: password) and verify access to user endpoints, but not admin-only ones.
  • Try without authentication to see if it's rejected.

RBAC Access Check

Consider the following Spring Security configuration and controller method:

@Configuration
@EnableMethodSecurity(prePostEnabled = true)
// ... other config ...

@Bean
public UserDetailsService userDetailsService() {
    UserDetails userA = User.withDefaultPasswordEncoder()
        .username("alice").password("pw").roles("USER").build();
    UserDetails userB = User.withDefaultPasswordEncoder()
        .username("bob").password("pw").roles("MANAGER").build();
    return new InMemoryUserDetailsManager(userA, userB);
}

@RestController
class MyController {
    @GetMapping("/report")
    @PreAuthorize("hasAnyRole('USER', 'ADMIN')")
    public String getReport() {
        return "Confidential Report";
    }
}

Which user(s) can successfully access the /report endpoint?

@Configuration
@EnableMethodSecurity(prePostEnabled = true)
// ... other config ...

@Bean
public UserDetailsService userDetailsService() {
    UserDetails userA = User.withDefaultPasswordEncoder()
        .username("alice").password("pw").roles("USER").build();
    UserDetails userB = User.withDefaultPasswordEncoder()
        .username("bob").password("pw").roles("MANAGER").build();
    return new InMemoryUserDetailsManager(userA, userB);
}

@RestController
class MyController {
    @GetMapping("/report")
    @PreAuthorize("hasAnyRole('USER', 'ADMIN')")
    public String getReport() {
        return "Confidential Report";
    }
}

RBAC Lesson Summary

In this lesson, we explored Role-Based Access Control (RBAC) in Spring Boot Microservices.

  • We learned how to define and assign roles to users.
  • We configured Spring Security to recognize these roles using SecurityFilterChain.
  • We used @PreAuthorize with hasRole() and hasAnyRole() to secure API endpoints based on user roles.

RBAC is a powerful way to manage access control efficiently and securely in your applications.

Questions Fréquemment Posées

La leçon « Contrôle d’accès fondé sur les rôles » est-elle gratuite ?

Oui — le texte complet de « Contrôle d’accès fondé sur les rôles » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Spring Boot 4 Microservices & REST APIs, passe à CoddyKit PRO. Le cours Spring Boot 4 Microservices & REST APIs comprend 3 leçons au total.

Qu'est-ce que j'apprendrai dans « Contrôle d’accès fondé sur les rôles » ?

Configurez une autorisation fondée sur les rôles afin de définir des permissions d’accès précises pour différents rôles utilisateur. Tu pratiques Spring Boot 4 Microservices & REST APIs avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer Spring Boot 4 Microservices & REST APIs ?

Aucune expérience préalable n'est requise. Spring Boot 4 Microservices & REST APIs sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 3 sur 3.

Combien de temps prend la leçon « Contrôle d’accès fondé sur les rôles » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon Spring Boot 4 Microservices & REST APIs ?

Oui. Chaque leçon Spring Boot 4 Microservices & REST APIs inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Principes fondamentaux d’OAuth2 et des JWT
  2. Sécuriser les points de terminaison REST
  3. Contrôle d’accès fondé sur les rôles
← Retour à Spring Boot 4 Microservices & REST APIs