Erişim Denetimi
Ownable ve roller
Erişim Denetimi, CoddyKit'te ücretsiz bir Web3 & DApp Development Fundamentals dersidir. Bu, 4 dersinin 2. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Web3 & DApp Development Fundamentals öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Web3 & DApp Development Fundamentals kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Why Access Control
Many contract functions should only be callable by certain accounts — minting tokens, pausing the system, withdrawing funds. Access control enforces who can do what.
OpenZeppelin offers two main patterns: Ownable and AccessControl.
The Ownable Pattern
Ownable gives a contract a single privileged owner. Import and inherit it:
import "@openzeppelin/contracts/access/Ownable.sol";
contract Vault is Ownable {
constructor() Ownable(msg.sender) {}
}The deployer becomes the initial owner.
import "@openzeppelin/contracts/access/Ownable.sol";
contract Vault is Ownable {
constructor() Ownable(msg.sender) {}
}The onlyOwner Modifier
Restrict a function to the owner with the onlyOwner modifier:
function withdraw() public onlyOwner {
payable(owner()).transfer(address(this).balance);
}If anyone else calls it, the transaction reverts automatically.
function withdraw() public onlyOwner {
payable(owner()).transfer(address(this).balance);
}Transferring Ownership
Ownable lets you hand control to another address:
// Give ownership to a new account
vault.transferOwnership(newOwner);
// Or give it up forever
vault.renounceOwnership();Renouncing makes onlyOwner functions permanently uncallable — use with care.
// Give ownership to a new account
vault.transferOwnership(newOwner);
// Or give it up forever
vault.renounceOwnership();Limits of a Single Owner
One owner is simple but limiting:
- No way to grant different permissions to different people.
- A single key is a single point of failure.
For richer setups, use role-based access control.
The AccessControl Pattern
AccessControl supports many named roles. Inherit it and define your roles:
import "@openzeppelin/contracts/access/AccessControl.sol";
contract Token is AccessControl {
bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
}Roles are identified by a hashed name.
import "@openzeppelin/contracts/access/AccessControl.sol";
contract Token is AccessControl {
bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
}Granting Roles
The deployer typically gets the admin role and then grants others:
constructor() {
_grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
_grantRole(MINTER_ROLE, msg.sender);
}The DEFAULT_ADMIN_ROLE can grant and revoke all other roles.
constructor() {
_grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
_grantRole(MINTER_ROLE, msg.sender);
}The onlyRole Modifier
Restrict functions to holders of a role:
function mint(address to, uint256 amount)
public onlyRole(MINTER_ROLE) {
_mint(to, amount);
}Only accounts granted MINTER_ROLE can mint; everyone else reverts.
function mint(address to, uint256 amount)
public onlyRole(MINTER_ROLE) {
_mint(to, amount);
}Managing Roles at Runtime
Admins can grant and revoke roles after deployment:
token.grantRole(MINTER_ROLE, alice);
token.revokeRole(MINTER_ROLE, alice);
// Check membership
bool canMint = await token.hasRole(MINTER_ROLE, alice);An account can even renounce its own role.
token.grantRole(MINTER_ROLE, alice);
token.revokeRole(MINTER_ROLE, alice);
// Check membership
bool canMint = await token.hasRole(MINTER_ROLE, alice);Choosing a Pattern
Which to use?
- Ownable — simple admin tasks, one trusted operator.
- AccessControl — multiple roles, separation of duties, DAOs.
For production, consider giving the owner/admin role to a multisig rather than a single key.
Each Role Has an Admin
In AccessControl, every role has an admin role that controls who can grant or revoke it. By default that is DEFAULT_ADMIN_ROLE, but you can change it:
// Make MANAGER_ROLE the admin of MINTER_ROLE
_setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);This lets you build hierarchies of permissions.
// Make MANAGER_ROLE the admin of MINTER_ROLE
_setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);Quick Check
Test your understanding of access control.
Recap
You learned OpenZeppelin's access control patterns.
- Ownable gives one
owner; restrict withonlyOwnerand transfer or renounce ownership. - AccessControl supports many roles identified by hashed names.
- Grant the admin role at deploy; protect functions with
onlyRole. - Admins grant/revoke roles at runtime; accounts can renounce roles.
- Use Ownable for simple cases, AccessControl (ideally behind a multisig) for complex ones.
Sıkça Sorulan Sorular
“Erişim Denetimi” dersi ücretsiz mi?
Evet — “Erişim Denetimi” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Web3 & DApp Development Fundamentals kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Web3 & DApp Development Fundamentals kursu toplamda 4 dersten oluşur.
“Erişim Denetimi” dersinde ne öğreneceğim?
Ownable ve roller Web3 & DApp Development Fundamentals ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Web3 & DApp Development Fundamentals öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Web3 & DApp Development Fundamentals, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 2. dersidir.
“Erişim Denetimi” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Web3 & DApp Development Fundamentals dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Web3 & DApp Development Fundamentals dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.