Kontrola dostępu oparta na rolach (RBAC)
Modeluj role i uprawnienia użytkowników, przechowuj je w sesji i egzekwuj sprawdzanie ról w komponentach serwerowych, obsłudze tras oraz middleware aplikacji Next.js 15.
Kontrola dostępu oparta na rolach (RBAC) to bezpłatna lekcja Next.js 15 Fullstack Web Apps na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Next.js 15 Fullstack Web Apps, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Next.js 15 Fullstack Web Apps zawiera 4 lekcji w sumie.
Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.
Authorization Beyond Login
Authentication answers who are you; authorization answers what may you do. Role-Based Access Control (RBAC) assigns each user one or more roles and grants permissions to roles instead of individuals.
- Roles:
admin,editor,viewer - Permissions are derived from the role.
Storing the Role in the JWT
With NextAuth, attach the role to the token in the jwt callback so it travels with every request without a database hit.
callbacks: {
async jwt({ token, user }) {
if (user) token.role = user.role;
return token;
},
async session({ session, token }) {
session.user.role = token.role;
return session;
},
}A Permissions Map
Centralize what each role can do. A simple map keeps checks consistent and easy to audit.
export const permissions = {
admin: ['read', 'write', 'delete'],
editor: ['read', 'write'],
viewer: ['read'],
};
export function can(role, action) {
return permissions[role]?.includes(action) ?? false;
}Testing the Helper
The can helper is pure logic, so it runs anywhere. Here is a self-contained check.
const permissions = {
admin: ['read', 'write', 'delete'],
editor: ['read', 'write'],
viewer: ['read'],
};
function can(role, action) {
return permissions[role]?.includes(action) ?? false;
}
console.log(can('editor', 'write'));
console.log(can('viewer', 'delete'));Guarding a Server Component
Read the session on the server and redirect users who lack the required role before any sensitive UI renders.
import { auth } from '@/auth';
import { redirect } from 'next/navigation';
export default async function AdminPage() {
const session = await auth();
if (session?.user.role !== 'admin') redirect('/');
return <h1>Admin Dashboard</h1>;
}Guarding a Route Handler
API route handlers must enforce roles too. Never trust the client. Return 403 when the role is insufficient.
import { auth } from '@/auth';
import { can } from '@/lib/rbac';
export async function DELETE(req) {
const session = await auth();
if (!can(session?.user.role, 'delete')) {
return new Response('Forbidden', { status: 403 });
}
return Response.json({ ok: true });
}Role Checks in Middleware
Middleware can block whole route groups early. Match an admin prefix and verify the token's role.
import { NextResponse } from 'next/server';
export function middleware(req) {
const role = req.cookies.get('role')?.value;
if (req.nextUrl.pathname.startsWith('/admin') && role !== 'admin') {
return NextResponse.redirect(new URL('/login', req.url));
}
return NextResponse.next();
}
export const config = { matcher: ['/admin/:path*'] };Defense in Depth
Apply checks at multiple layers. Middleware gives a fast first gate, but always re-verify in the server component or route handler that actually touches data.
- Middleware: coarse routing gate.
- Server component / handler: authoritative check.
Hiding UI Conditionally
Hide controls users cannot use, but remember UI hiding is convenience, not security. The server must still reject unauthorized actions.
export default async function Toolbar() {
const session = await auth();
return (
<div>
{can(session?.user.role, 'delete') && <DeleteButton />}
</div>
);
}Multiple Roles and Scopes
Real apps often give a user several roles or fine-grained scopes. Store an array and check membership. This scales toward permission-based (ABAC) systems later.
function hasRole(userRoles, required) {
return userRoles.some((r) => r === required);
}
console.log(hasRole(['editor', 'viewer'], 'editor'));Common Pitfalls
Avoid these RBAC mistakes:
- Trusting a role sent from the client body.
- Checking roles only in the UI.
- Forgetting to re-issue the JWT after a role change.
- Hardcoding role strings instead of a central map.
Quick Check
Where is the authoritative place to enforce that only admins can delete a record?
Recap
You implemented RBAC end to end:
- Stored the role in the JWT and session via NextAuth callbacks.
- Centralized permissions with a
can()helper. - Guarded server components, route handlers, and middleware.
- Applied defense in depth and avoided client-trust pitfalls.
Często zadawane pytania
Czy lekcja „Kontrola dostępu oparta na rolach (RBAC)” jest bezpłatna?
Tak — pełny tekst „Kontrola dostępu oparta na rolach (RBAC)” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Next.js 15 Fullstack Web Apps, przejdź na CoddyKit PRO. Kurs Next.js 15 Fullstack Web Apps zawiera 4 lekcji w sumie.
Co nauczysz się w „Kontrola dostępu oparta na rolach (RBAC)”?
Modeluj role i uprawnienia użytkowników, przechowuj je w sesji i egzekwuj sprawdzanie ról w komponentach serwerowych, obsłudze tras oraz middleware aplikacji Next.js 15. Ćwiczysz Next.js 15 Fullstack Web Apps z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.
Czy potrzebuję doświadczenia, aby zacząć Next.js 15 Fullstack Web Apps?
Nie wymagamy żadnego doświadczenia. Next.js 15 Fullstack Web Apps w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.
Ile czasu zajmuje lekcja „Kontrola dostępu oparta na rolach (RBAC)”?
Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.
Czy mogę pisać i uruchamiać kod w tej lekcji Next.js 15 Fullstack Web Apps?
Tak. Każda lekcja Next.js 15 Fullstack Web Apps zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.
Wszystkie lekcje w tym kursie
- Integracja NextAuth.js
- Zarządzanie sesjami i JWT
- Middleware i kontrola dostępu
- Kontrola dostępu oparta na rolach (RBAC)