ロールベースアクセス制御(RBAC)
ユーザーのロールと権限に基づいて特定のリソースへのアクセスを制限する、ロールベース認可を実装します。
「ロールベースアクセス制御(RBAC)」はCoddyKit上の無料Spring Security 6 & JWT Authenticationレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSpring Security 6 & JWT Authentication学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Spring Security 6 & JWT Authenticationコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Understanding RBAC Basics
Welcome! Today we'll dive into Role-Based Access Control (RBAC). It's a fundamental security concept for managing who can do what in an application.
Imagine a school: students can view grades, teachers can post grades, and administrators can manage all users. Each group has a 'role' with specific 'permissions'.
- Role: A collection of permissions.
- Permission: The ability to perform a specific action (e.g., read, write, delete).
Roles in Spring Security
Spring Security uses roles to enforce authorization. When you define a user, you also assign them one or more roles.
Internally, Spring Security treats roles as Granted Authorities. By convention, roles are often prefixed with ROLE_ (e.g., ROLE_ADMIN, ROLE_USER). This helps distinguish them from other types of authorities.
Assigning Roles to Users
Before we can use RBAC, users need roles! When a user logs in, Spring Security's authentication process retrieves their assigned roles.
These roles are typically loaded from a database via a UserDetailsService, or for simpler cases, defined directly in memory. We'll use in-memory users for our examples to keep things clear.
Securing URLs with `hasRole()`
The core of RBAC in Spring Security for web applications is configuring HttpSecurity. We use methods like hasRole() to specify which roles can access certain URL patterns.
For example, to protect an 'admin' page, you might write: .requestMatchers("/admin/**").hasRole("ADMIN"). Spring Security automatically adds the ROLE_ prefix when you use hasRole().
RBAC Web Security Config
Let's see a simple Spring Security configuration. This setup defines two in-memory users (user and admin) and secures two endpoints: /user and /admin.
Try running this code and accessing the URLs!
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@SpringBootApplication
@RestController
public class Main {
public static void main(String[] args) {
SpringApplication.run(Main.class, args);
}
@GetMapping("/user")
public String userEndpoint() {
return "Hello, User!";
}
@GetMapping("/admin")
public String adminEndpoint() {
return "Hello, Admin!";
}
@Configuration
@EnableWebSecurity
static class WebSecurityConfig {
@Bean
public UserDetailsService userDetailsService() {
UserDetails user = User.withDefaultPasswordEncoder()
.username("user")
.password("password")
.roles("USER")
.build();
UserDetails admin = User.withDefaultPasswordEncoder()
.username("admin")
.password("password")
.roles("ADMIN", "USER")
.build();
return new InMemoryUserDetailsManager(user, admin);
}
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(authorize -> authorize
.requestMatchers("/user/**").hasRole("USER")
.requestMatchers("/admin/**").hasRole("ADMIN")
.anyRequest().authenticated()
)
.formLogin(org.springframework.security.config.Customizer.withDefaults());
return http.build();
}
}
}Testing Our RBAC Setup
After running the previous example, open your browser and try to access these URLs:
http://localhost:8080/user: Log in withuser/passwordoradmin/password. Both should work!http://localhost:8080/admin: Log in withadmin/password. This should work.http://localhost:8080/admin: Log in withuser/password. You should see an 'Access Denied' error (403 Forbidden).
This demonstrates how roles restrict access!
Multiple Roles: `hasAnyRole()`
What if an endpoint can be accessed by more than one role? Spring Security provides hasAnyRole() for this.
Instead of listing multiple hasRole() calls, you can do: .requestMatchers("/dashboard/**").hasAnyRole("USER", "ADMIN"). This grants access if the authenticated user has EITHER the USER role OR the ADMIN role.
`hasRole()` vs `hasAuthority()`
You might also see hasAuthority() being used. What's the difference?
hasRole("ADMIN"): This implicitly adds theROLE_prefix, so it checks forROLE_ADMIN.hasAuthority("ROLE_ADMIN"): This requires the exact authority string, including theROLE_prefix if it's part of the authority name.
Generally, hasRole() is preferred for clarity when dealing with roles defined with the ROLE_ prefix.
Securing Specific HTTP Methods
RBAC can also be applied to specific HTTP methods for a given path. This is useful for REST APIs where different actions (GET, POST, PUT, DELETE) require different permissions.
You can chain requestMatchers() with HttpMethod:
.requestMatchers(HttpMethod.POST, "/products/**").hasRole("ADMIN")
.requestMatchers(HttpMethod.GET, "/products/**").hasAnyRole("USER", "ADMIN")Here, only ADMIN can create products, but both USER and ADMIN can view them.
Best Practices for RBAC
To make RBAC effective and manageable:
- Keep Roles Simple: Don't create too many roles. Roles should represent distinct job functions.
- Least Privilege: Grant only the necessary roles/permissions to users.
- Centralized Management: Manage roles and their assignments from a single, secure place.
- Audit Regularly: Periodically review role assignments and permissions to ensure they are still appropriate.
RBAC Knowledge Check
You've learned about implementing Role-Based Access Control in Spring Security. Let's quickly test your understanding!
Recap: Role-Based Access Control
Great job! In this lesson, you learned about:
- What RBAC is and its importance for authorization.
- How Spring Security uses roles (as
GrantedAuthority). - Configuring URL-based RBAC with
HttpSecurity. - Using
hasRole()andhasAnyRole()to protect endpoints. - Distinguishing between
hasRole()andhasAuthority(). - Applying RBAC to specific HTTP methods.
- Key best practices for effective RBAC implementation.
You now have a solid foundation for controlling access based on user roles!
よくある質問
「ロールベースアクセス制御(RBAC)」レッスンは無料ですか?
はい。「ロールベースアクセス制御(RBAC)」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Spring Security 6 & JWT Authenticationコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Spring Security 6 & JWT Authenticationコースには全4レッスンが含まれています。
「ロールベースアクセス制御(RBAC)」で何を学びますか?
ユーザーのロールと権限に基づいて特定のリソースへのアクセスを制限する、ロールベース認可を実装します。 ブラウザで直接実行するハンズオンコードでSpring Security 6 & JWT Authenticationを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Spring Security 6 & JWT Authenticationを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのSpring Security 6 & JWT Authenticationは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。
「ロールベースアクセス制御(RBAC)」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このSpring Security 6 & JWT Authenticationレッスンでコードを書いて実行できますか?
はい。すべてのSpring Security 6 & JWT Authenticationレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- ロールベースアクセス制御(RBAC)
- アノテーションによるメソッドレベルセキュリティ
- HttpSecurity設定の詳細
- カスタムアクセスルールでエンドポイントを保護する