Blockchain Smart Contracts with Solidity · บทเรียน

รูปแบบการควบคุมการเข้าถึง

นำกลไกควบคุมการเข้าถึงที่แข็งแกร่งมาใช้ด้วยรูปแบบ `Ownable`, `Pausable` และการควบคุมการเข้าถึงตามบทบาท (RBAC)

บทเรียน 2 จาก 412 ขั้นตอน

รูปแบบการควบคุมการเข้าถึง เป็นบทเรียน Blockchain Smart Contracts with Solidity ฟรีบน CoddyKit นี่คือบทเรียนที่ 2 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Blockchain Smart Contracts with Solidity และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Blockchain Smart Contracts with Solidity มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

What is Access Control?

In smart contracts, access control defines who can perform specific actions. It's like setting permissions on a file or folder.

Without proper access control, anyone could call sensitive functions, leading to vulnerabilities or unintended behavior.

Why It's Crucial

Imagine a contract that manages funds or critical system settings. You wouldn't want just anyone to be able to:

  • Withdraw all funds.
  • Change the contract's owner.
  • Pause essential operations.

Access control is a fundamental security measure.

The `onlyOwner` Modifier

A common pattern is to restrict certain functions to the contract's owner (the address that deployed it).

This is often achieved using a modifier, a special keyword in Solidity that can alter the behavior of a function.

Custom `onlyOwner` Example

Here's how you might manually implement an onlyOwner modifier and use it:

pragma solidity ^0.8.0;

contract MyBasicOwnable {
  address public owner;

  constructor() {
    owner = msg.sender;
  }

  modifier onlyOwner() {
    require(msg.sender == owner, "Not owner");
    _;
  }

  function setGreeting(string memory _text) public onlyOwner {
    // Only the owner can call this
    // ... (e.g., update a greeting message)
  }
}

OpenZeppelin's `Ownable`

While you can write your own, it's best practice to use battle-tested libraries. OpenZeppelin provides a secure and standardized Ownable contract.

By inheriting from Ownable, your contract gets the owner state variable and the onlyOwner modifier automatically.

Using OpenZeppelin `Ownable`

Simply import and inherit Ownable. The contract deployer automatically becomes the owner.

pragma solidity ^0.8.0;

import "@openzeppelin/contracts/access/Ownable.sol";

contract MyOzOwnable is Ownable {
  uint256 public value;

  function setValue(uint256 _newValue) public onlyOwner {
    value = _newValue;
  }

  function getValue() public view returns (uint256) {
    return value;
  }
}

The `Pausable` Pattern

The Pausable pattern allows a contract to be put into a 'paused' state, preventing certain functions from being called.

This is crucial for emergency situations, like discovering a critical bug or reacting to a hack, giving developers time to mitigate issues.

Using OpenZeppelin `Pausable`

OpenZeppelin's Pausable provides paused state, whenNotPaused and whenPaused modifiers, and _pause()/_unpause() functions.

pragma solidity ^0.8.0;

import "@openzeppelin/contracts/security/Pausable.sol";
import "@openzeppelin/contracts/access/Ownable.sol";

contract MyPausableContract is Pausable, Ownable {
  uint256 public counter;

  function increment() public whenNotPaused {
    counter++;
  }

  function pauseContract() public onlyOwner {
    _pause(); // Only owner can pause
  }

  function unpauseContract() public onlyOwner {
    _unpause(); // Only owner can unpause
  }
}

Role-Based Access Control (RBAC)

For more complex contracts, a single 'owner' might not be enough. Role-Based Access Control (RBAC) allows defining multiple roles (e.g., 'minter', 'admin', 'pauser').

OpenZeppelin's AccessControl contract helps manage these roles efficiently.

Using OpenZeppelin `AccessControl`

Define roles as bytes32 constants. The deployer automatically gets DEFAULT_ADMIN_ROLE, which can grant/revoke other roles.

pragma solidity ^0.8.0;

import "@openzeppelin/contracts/access/AccessControl.sol";

contract MyRBACContract is AccessControl {
  bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
  bytes32 public constant PAUSER_ROLE = keccak256("PAUSER_ROLE");

  constructor() {
    _grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
    _grantRole(MINTER_ROLE, msg.sender); // Deployer is also a minter
  }

  function mint(address to, uint256 amount) public onlyRole(MINTER_ROLE) {
    // Logic to mint tokens
  }

  function systemPause() public onlyRole(PAUSER_ROLE) {
    // Logic to pause critical system functions
  }
}

Access Control Check

Which of the following are benefits of implementing access control patterns like Ownable, Pausable, or AccessControl in smart contracts?

Recap: Access Control Patterns

You've learned about essential access control patterns in Solidity:

  • Ownable: Restricts functions to a single owner, often the contract deployer.
  • Pausable: Allows for emergency pausing/unpausing of contract functionality.
  • AccessControl (RBAC): Provides flexible, role-based permissions for more complex scenarios.

These patterns are critical for building robust and secure smart contracts, often leveraged from OpenZeppelin's battle-tested libraries.

เริ่มต้นได้ฟรี

เรียนรู้ Blockchain Smart Contracts with Solidity ด้วย AI tutor — ฟรี

เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป

คอร์ส
12
บทเรียน
48

คำถามที่พบบ่อย

บทเรียน “รูปแบบการควบคุมการเข้าถึง” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “รูปแบบการควบคุมการเข้าถึง” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Blockchain Smart Contracts with Solidity ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Blockchain Smart Contracts with Solidity มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “รูปแบบการควบคุมการเข้าถึง”

นำกลไกควบคุมการเข้าถึงที่แข็งแกร่งมาใช้ด้วยรูปแบบ `Ownable`, `Pausable` และการควบคุมการเข้าถึงตามบทบาท (RBAC) คุณปฏิบัติ Blockchain Smart Contracts with Solidity ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Blockchain Smart Contracts with Solidity หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Blockchain Smart Contracts with Solidity บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 2 จากทั้งหมด 4 บทเรียน

บทเรียน “รูปแบบการควบคุมการเข้าถึง” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Blockchain Smart Contracts with Solidity นี้ได้ไหม

ได้ บทเรียน Blockchain Smart Contracts with Solidity ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. ช่องโหว่ทั่วไป (การเรียกซ้ำและอื่น ๆ)
  2. รูปแบบการควบคุมการเข้าถึง
  3. การเขียนโค้ดอย่างปลอดภัยด้วย SafeMath
  4. การตรวจสอบความปลอดภัย การทดสอบ และเงินรางวัลค้นหาข้อบกพร่อง
← กลับไปที่ Blockchain Smart Contracts with Solidity