ロールベースアクセス制御(RBAC)
ユーザーのロールと権限に基づいて特定のエンドポイントへのアクセスを制限する、ロールベースの認可を実装します。
「ロールベースアクセス制御(RBAC)」はCoddyKit上の無料Node.js Backend Development Bootcampレッスンです。 これはレッスン6/6です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはNode.js Backend Development Bootcamp学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Node.js Backend Development Bootcampコースには全6レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
What is RBAC?
Role-Based Access Control (RBAC) is a method of restricting access to resources based on the roles individual users have within an organization.
- Instead of assigning permissions directly to users, permissions are assigned to roles.
- Users are then assigned to roles, inheriting those permissions.
- This simplifies security management, especially in larger applications.
Defining User Roles
First, we need to define the roles our application will use. These are typically broad categories like 'admin', 'editor', or 'basic_user'.
Using a Python Enum is a clean way to manage these roles:
from enum import Enum
class UserRole(str, Enum):
ADMIN = "admin"
EDITOR = "editor"
BASIC_USER = "basic_user"
# Example usage:
# role = UserRole.ADMINUser Role Assignment
Every user in your system will have one or more roles associated with them. In a real FastAPI application, this information usually comes from the user's authenticated token (e.g., a JWT payload).
For this lesson, we'll use a simple User model and a mock function to represent the currently authenticated user with their assigned roles.
from typing import List
from pydantic import BaseModel
from enum import Enum
class UserRole(str, Enum):
ADMIN = "admin"
EDITOR = "editor"
BASIC_USER = "basic_user"
class User(BaseModel):
username: str
roles: List[UserRole]
# Mock function to get current user (normally from JWT)
async def get_current_user() -> User:
# In a real app, this would decode a JWT
# For demonstration, let's return a mock admin user
return User(username="admin_user", roles=[UserRole.ADMIN])Custom Role Dependency
FastAPI's dependency injection system is perfect for implementing RBAC. We can create a custom dependency that checks if the authenticated user has the necessary role(s) to access an endpoint.
- This dependency will be reusable across many endpoints.
- If the user doesn't have the required role, it raises an
HTTPException.
Building the Role Checker
Our role_required dependency will take a list of roles. It will then fetch the current user and verify if any of their assigned roles match the required roles.
from fastapi import Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
class UserRole(str, Enum):
ADMIN = "admin"
EDITOR = "editor"
BASIC_USER = "basic_user"
class User(BaseModel):
username: str
roles: List[UserRole]
# Mock function to get current user
async def get_current_user() -> User:
return User(username="test_user", roles=[UserRole.BASIC_USER])
def role_required(required_roles: List[UserRole]):
async def role_checker(current_user: User = Depends(get_current_user)):
if not any(role in current_user.roles for role in required_roles):
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail="Not enough permissions"
)
return current_user
return role_checkerCode: Admin-Only Endpoint
Here's a full FastAPI application demonstrating how to protect an endpoint so only users with the 'admin' role can access it. Run this code and try accessing /admin and /public.
from fastapi import FastAPI, Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
import uvicorn
app = FastAPI()
class UserRole(str, Enum):
ADMIN = "admin"
EDITOR = "editor"
BASIC_USER = "basic_user"
class User(BaseModel):
username: str
roles: List[UserRole]
# Mock function to get current user
# Change roles here to test different access levels
async def get_current_user() -> User:
# Try changing to [UserRole.BASIC_USER] or [UserRole.ADMIN]
return User(username="admin_user", roles=[UserRole.ADMIN])
def role_required(required_roles: List[UserRole]):
async def role_checker(current_user: User = Depends(get_current_user)):
if not any(role in current_user.roles for role in required_roles):
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail="Not enough permissions"
)
return current_user
return role_checker
@app.get("/public")
async def read_public_data():
return {"message": "This is public data!"}
@app.get("/admin")
async def read_admin_data(current_user: User = Depends(role_required([UserRole.ADMIN]))):
return {"message": f"Welcome, {current_user.username}! This is admin data."}
if __name__ == "__main__":
uvicorn.run(app, host="0.0.0.0", port=8000)Testing the Role Check
When you run the previous code:
- Access
http://127.0.0.1:8000/public: This should always work. - Access
http://127.0.0.1:8000/admin: This will work ifget_current_userreturns a user withUserRole.ADMIN.
Try changing the mock user's roles in get_current_user to [UserRole.BASIC_USER] and rerun the app. You'll see a 403 Forbidden error when trying to access /admin.
Allowing Multiple Roles
Sometimes, an endpoint should be accessible by more than one role. For example, both 'admin' and 'editor' users might be allowed to update an article.
Our role_required dependency is already designed for this! It accepts a List[UserRole], and the any() check means access is granted if the user has any one of the specified roles.
Code: Multiple Role Access
This example shows an endpoint accessible by either an 'admin' or an 'editor'. Try changing the mock user's roles to [UserRole.EDITOR] and [UserRole.BASIC_USER] to observe the access control.
from fastapi import FastAPI, Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
import uvicorn
app = FastAPI()
class UserRole(str, Enum):
ADMIN = "admin"
EDITOR = "editor"
BASIC_USER = "basic_user"
class User(BaseModel):
username: str
roles: List[UserRole]
# Mock function to get current user
# Change roles here to test different access levels
async def get_current_user() -> User:
# Try [UserRole.ADMIN], [UserRole.EDITOR], or [UserRole.BASIC_USER]
return User(username="editor_user", roles=[UserRole.EDITOR])
def role_required(required_roles: List[UserRole]):
async def role_checker(current_user: User = Depends(get_current_user)):
if not any(role in current_user.roles for role in required_roles):
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail="Not enough permissions"
)
return current_user
return role_checker
@app.get("/edit_content")
async def edit_content(current_user: User = Depends(role_required([UserRole.ADMIN, UserRole.EDITOR]))):
return {"message": f"Hello {current_user.username}! You can edit content."}
@app.get("/view_only")
async def view_only_content(current_user: User = Depends(role_required([UserRole.BASIC_USER]))):
return {"message": f"Hello {current_user.username}! You can view content."}
if __name__ == "__main__":
uvicorn.run(app, host="0.0.0.0", port=8000)RBAC Implementation Check
You need to create an endpoint /dashboard that should only be accessible by users with the ADMIN role. Which of the following is the correct way to apply the role_required dependency?
RBAC Recap
You've learned how to implement Role-Based Access Control in your FastAPI applications:
- Defined roles using Python
Enumfor clarity. - Understood how user roles are typically associated (e.g., via JWTs).
- Created a reusable custom dependency (
role_required) to check user roles. - Applied this dependency to endpoints to restrict access based on single or multiple roles.
RBAC is a powerful way to manage permissions, making your API more secure and maintainable!
よくある質問
「ロールベースアクセス制御(RBAC)」レッスンは無料ですか?
はい。「ロールベースアクセス制御(RBAC)」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Node.js Backend Development Bootcampコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Node.js Backend Development Bootcampコースには全6レッスンが含まれています。
「ロールベースアクセス制御(RBAC)」で何を学びますか?
ユーザーのロールと権限に基づいて特定のエンドポイントへのアクセスを制限する、ロールベースの認可を実装します。 ブラウザで直接実行するハンズオンコードでNode.js Backend Development Bootcampを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Node.js Backend Development Bootcampを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのNode.js Backend Development Bootcampは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン6/6です。
「ロールベースアクセス制御(RBAC)」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このNode.js Backend Development Bootcampレッスンでコードを書いて実行できますか?
はい。すべてのNode.js Backend Development Bootcampレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- ユーザー登録とログイン
- JWTトークンの生成と検証
- ステートレス認証のためのJWT
- OAuth2パスワードフローの統合
- ロールベースアクセス制御
- ロールベースアクセス制御(RBAC)