역할 기반 접근 제어(RBAC)
사용자 역할과 권한에 따라 특정 리소스에 대한 접근을 제한하도록 역할 기반 인증을 구현합니다.
역할 기반 접근 제어(RBAC)은(는) CoddyKit의 무료 Spring Security 6 & JWT Authentication 강의입니다. 이것은 4개 중 1번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Spring Security 6 & JWT Authentication 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Spring Security 6 & JWT Authentication 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Understanding RBAC Basics
Welcome! Today we'll dive into Role-Based Access Control (RBAC). It's a fundamental security concept for managing who can do what in an application.
Imagine a school: students can view grades, teachers can post grades, and administrators can manage all users. Each group has a 'role' with specific 'permissions'.
- Role: A collection of permissions.
- Permission: The ability to perform a specific action (e.g., read, write, delete).
Roles in Spring Security
Spring Security uses roles to enforce authorization. When you define a user, you also assign them one or more roles.
Internally, Spring Security treats roles as Granted Authorities. By convention, roles are often prefixed with ROLE_ (e.g., ROLE_ADMIN, ROLE_USER). This helps distinguish them from other types of authorities.
Assigning Roles to Users
Before we can use RBAC, users need roles! When a user logs in, Spring Security's authentication process retrieves their assigned roles.
These roles are typically loaded from a database via a UserDetailsService, or for simpler cases, defined directly in memory. We'll use in-memory users for our examples to keep things clear.
Securing URLs with `hasRole()`
The core of RBAC in Spring Security for web applications is configuring HttpSecurity. We use methods like hasRole() to specify which roles can access certain URL patterns.
For example, to protect an 'admin' page, you might write: .requestMatchers("/admin/**").hasRole("ADMIN"). Spring Security automatically adds the ROLE_ prefix when you use hasRole().
RBAC Web Security Config
Let's see a simple Spring Security configuration. This setup defines two in-memory users (user and admin) and secures two endpoints: /user and /admin.
Try running this code and accessing the URLs!
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@SpringBootApplication
@RestController
public class Main {
public static void main(String[] args) {
SpringApplication.run(Main.class, args);
}
@GetMapping("/user")
public String userEndpoint() {
return "Hello, User!";
}
@GetMapping("/admin")
public String adminEndpoint() {
return "Hello, Admin!";
}
@Configuration
@EnableWebSecurity
static class WebSecurityConfig {
@Bean
public UserDetailsService userDetailsService() {
UserDetails user = User.withDefaultPasswordEncoder()
.username("user")
.password("password")
.roles("USER")
.build();
UserDetails admin = User.withDefaultPasswordEncoder()
.username("admin")
.password("password")
.roles("ADMIN", "USER")
.build();
return new InMemoryUserDetailsManager(user, admin);
}
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(authorize -> authorize
.requestMatchers("/user/**").hasRole("USER")
.requestMatchers("/admin/**").hasRole("ADMIN")
.anyRequest().authenticated()
)
.formLogin(org.springframework.security.config.Customizer.withDefaults());
return http.build();
}
}
}Testing Our RBAC Setup
After running the previous example, open your browser and try to access these URLs:
http://localhost:8080/user: Log in withuser/passwordoradmin/password. Both should work!http://localhost:8080/admin: Log in withadmin/password. This should work.http://localhost:8080/admin: Log in withuser/password. You should see an 'Access Denied' error (403 Forbidden).
This demonstrates how roles restrict access!
Multiple Roles: `hasAnyRole()`
What if an endpoint can be accessed by more than one role? Spring Security provides hasAnyRole() for this.
Instead of listing multiple hasRole() calls, you can do: .requestMatchers("/dashboard/**").hasAnyRole("USER", "ADMIN"). This grants access if the authenticated user has EITHER the USER role OR the ADMIN role.
`hasRole()` vs `hasAuthority()`
You might also see hasAuthority() being used. What's the difference?
hasRole("ADMIN"): This implicitly adds theROLE_prefix, so it checks forROLE_ADMIN.hasAuthority("ROLE_ADMIN"): This requires the exact authority string, including theROLE_prefix if it's part of the authority name.
Generally, hasRole() is preferred for clarity when dealing with roles defined with the ROLE_ prefix.
Securing Specific HTTP Methods
RBAC can also be applied to specific HTTP methods for a given path. This is useful for REST APIs where different actions (GET, POST, PUT, DELETE) require different permissions.
You can chain requestMatchers() with HttpMethod:
.requestMatchers(HttpMethod.POST, "/products/**").hasRole("ADMIN")
.requestMatchers(HttpMethod.GET, "/products/**").hasAnyRole("USER", "ADMIN")Here, only ADMIN can create products, but both USER and ADMIN can view them.
Best Practices for RBAC
To make RBAC effective and manageable:
- Keep Roles Simple: Don't create too many roles. Roles should represent distinct job functions.
- Least Privilege: Grant only the necessary roles/permissions to users.
- Centralized Management: Manage roles and their assignments from a single, secure place.
- Audit Regularly: Periodically review role assignments and permissions to ensure they are still appropriate.
RBAC Knowledge Check
You've learned about implementing Role-Based Access Control in Spring Security. Let's quickly test your understanding!
Recap: Role-Based Access Control
Great job! In this lesson, you learned about:
- What RBAC is and its importance for authorization.
- How Spring Security uses roles (as
GrantedAuthority). - Configuring URL-based RBAC with
HttpSecurity. - Using
hasRole()andhasAnyRole()to protect endpoints. - Distinguishing between
hasRole()andhasAuthority(). - Applying RBAC to specific HTTP methods.
- Key best practices for effective RBAC implementation.
You now have a solid foundation for controlling access based on user roles!
자주 묻는 질문
“역할 기반 접근 제어(RBAC)” 강의는 무료인가요?
네 — “역할 기반 접근 제어(RBAC)” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Spring Security 6 & JWT Authentication 강의 전체를 잠금 해제할 수 있습니다. Spring Security 6 & JWT Authentication 강의에는 총 4개의 강의가 포함되어 있습니다.
“역할 기반 접근 제어(RBAC)”에서 뭘 배우나요?
사용자 역할과 권한에 따라 특정 리소스에 대한 접근을 제한하도록 역할 기반 인증을 구현합니다. 브라우저에서 직접 실행하는 실습 코드로 Spring Security 6 & JWT Authentication을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
Spring Security 6 & JWT Authentication을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 Spring Security 6 & JWT Authentication은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 1번째 강의입니다.
“역할 기반 접근 제어(RBAC)” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 Spring Security 6 & JWT Authentication 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 Spring Security 6 & JWT Authentication 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- 역할 기반 접근 제어(RBAC)
- 주석을 사용한 메서드 수준 보안
- HttpSecurity 구성 심층 학습
- 사용자 지정 접근 규칙으로 엔드포인트 보호하기