0Pricing
Web3 & DApp Development Fundamentals · Lekcja

Kontrola dostępu

Ownable i role

Kontrola dostępu to bezpłatna lekcja Web3 & DApp Development Fundamentals na CoddyKit. To lekcja 2 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Web3 & DApp Development Fundamentals, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Web3 & DApp Development Fundamentals zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

Why Access Control

Many contract functions should only be callable by certain accounts — minting tokens, pausing the system, withdrawing funds. Access control enforces who can do what.

OpenZeppelin offers two main patterns: Ownable and AccessControl.

The Ownable Pattern

Ownable gives a contract a single privileged owner. Import and inherit it:

import "@openzeppelin/contracts/access/Ownable.sol"; contract Vault is Ownable { constructor() Ownable(msg.sender) {} }

The deployer becomes the initial owner.

import "@openzeppelin/contracts/access/Ownable.sol";

contract Vault is Ownable {
    constructor() Ownable(msg.sender) {}
}

The onlyOwner Modifier

Restrict a function to the owner with the onlyOwner modifier:

function withdraw() public onlyOwner { payable(owner()).transfer(address(this).balance); }

If anyone else calls it, the transaction reverts automatically.

function withdraw() public onlyOwner {
    payable(owner()).transfer(address(this).balance);
}

Transferring Ownership

Ownable lets you hand control to another address:

// Give ownership to a new account vault.transferOwnership(newOwner); // Or give it up forever vault.renounceOwnership();

Renouncing makes onlyOwner functions permanently uncallable — use with care.

// Give ownership to a new account
vault.transferOwnership(newOwner);

// Or give it up forever
vault.renounceOwnership();

Limits of a Single Owner

One owner is simple but limiting:

  • No way to grant different permissions to different people.
  • A single key is a single point of failure.

For richer setups, use role-based access control.

The AccessControl Pattern

AccessControl supports many named roles. Inherit it and define your roles:

import "@openzeppelin/contracts/access/AccessControl.sol"; contract Token is AccessControl { bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE"); }

Roles are identified by a hashed name.

import "@openzeppelin/contracts/access/AccessControl.sol";

contract Token is AccessControl {
    bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
}

Granting Roles

The deployer typically gets the admin role and then grants others:

constructor() { _grantRole(DEFAULT_ADMIN_ROLE, msg.sender); _grantRole(MINTER_ROLE, msg.sender); }

The DEFAULT_ADMIN_ROLE can grant and revoke all other roles.

constructor() {
    _grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
    _grantRole(MINTER_ROLE, msg.sender);
}

The onlyRole Modifier

Restrict functions to holders of a role:

function mint(address to, uint256 amount) public onlyRole(MINTER_ROLE) { _mint(to, amount); }

Only accounts granted MINTER_ROLE can mint; everyone else reverts.

function mint(address to, uint256 amount)
    public onlyRole(MINTER_ROLE) {
    _mint(to, amount);
}

Managing Roles at Runtime

Admins can grant and revoke roles after deployment:

token.grantRole(MINTER_ROLE, alice); token.revokeRole(MINTER_ROLE, alice); // Check membership bool canMint = await token.hasRole(MINTER_ROLE, alice);

An account can even renounce its own role.

token.grantRole(MINTER_ROLE, alice);
token.revokeRole(MINTER_ROLE, alice);

// Check membership
bool canMint = await token.hasRole(MINTER_ROLE, alice);

Choosing a Pattern

Which to use?

  • Ownable — simple admin tasks, one trusted operator.
  • AccessControl — multiple roles, separation of duties, DAOs.

For production, consider giving the owner/admin role to a multisig rather than a single key.

Each Role Has an Admin

In AccessControl, every role has an admin role that controls who can grant or revoke it. By default that is DEFAULT_ADMIN_ROLE, but you can change it:

// Make MANAGER_ROLE the admin of MINTER_ROLE _setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);

This lets you build hierarchies of permissions.

// Make MANAGER_ROLE the admin of MINTER_ROLE
_setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);

Quick Check

Test your understanding of access control.

Recap

You learned OpenZeppelin's access control patterns.

  • Ownable gives one owner; restrict with onlyOwner and transfer or renounce ownership.
  • AccessControl supports many roles identified by hashed names.
  • Grant the admin role at deploy; protect functions with onlyRole.
  • Admins grant/revoke roles at runtime; accounts can renounce roles.
  • Use Ownable for simple cases, AccessControl (ideally behind a multisig) for complex ones.

Często zadawane pytania

Czy lekcja „Kontrola dostępu” jest bezpłatna?

Tak — pełny tekst „Kontrola dostępu” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Web3 & DApp Development Fundamentals, przejdź na CoddyKit PRO. Kurs Web3 & DApp Development Fundamentals zawiera 4 lekcji w sumie.

Co nauczysz się w „Kontrola dostępu”?

Ownable i role Ćwiczysz Web3 & DApp Development Fundamentals z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć Web3 & DApp Development Fundamentals?

Nie wymagamy żadnego doświadczenia. Web3 & DApp Development Fundamentals w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 2 z 4.

Ile czasu zajmuje lekcja „Kontrola dostępu”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji Web3 & DApp Development Fundamentals?

Tak. Każda lekcja Web3 & DApp Development Fundamentals zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. Dlaczego OpenZeppelin
  2. Kontrola dostępu
  3. Rozszerzenia tokenów
  4. Kontrakty z możliwością aktualizacji
← Powrót do Web3 & DApp Development Fundamentals