Node.js Backend Development Bootcamp · 课时

基于角色的访问控制(RBAC)

实现基于角色的授权,根据用户角色和权限限制对特定端点的访问。

第 6 / 6 课11 个步骤

基于角色的访问控制(RBAC) 是 CoddyKit 上的免费 Node.js Backend Development Bootcamp 课时。 这是第 6 节课,共 6 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Node.js Backend Development Bootcamp 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Node.js Backend Development Bootcamp 课程共包含 6 节课。

本课时的部分内容尚未翻译,以英文显示。

What is RBAC?

Role-Based Access Control (RBAC) is a method of restricting access to resources based on the roles individual users have within an organization.

  • Instead of assigning permissions directly to users, permissions are assigned to roles.
  • Users are then assigned to roles, inheriting those permissions.
  • This simplifies security management, especially in larger applications.

Defining User Roles

First, we need to define the roles our application will use. These are typically broad categories like 'admin', 'editor', or 'basic_user'.

Using a Python Enum is a clean way to manage these roles:

from enum import Enum

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

# Example usage:
# role = UserRole.ADMIN

User Role Assignment

Every user in your system will have one or more roles associated with them. In a real FastAPI application, this information usually comes from the user's authenticated token (e.g., a JWT payload).

For this lesson, we'll use a simple User model and a mock function to represent the currently authenticated user with their assigned roles.

from typing import List
from pydantic import BaseModel
from enum import Enum

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user (normally from JWT)
async def get_current_user() -> User:
    # In a real app, this would decode a JWT
    # For demonstration, let's return a mock admin user
    return User(username="admin_user", roles=[UserRole.ADMIN])

Custom Role Dependency

FastAPI's dependency injection system is perfect for implementing RBAC. We can create a custom dependency that checks if the authenticated user has the necessary role(s) to access an endpoint.

  • This dependency will be reusable across many endpoints.
  • If the user doesn't have the required role, it raises an HTTPException.

Building the Role Checker

Our role_required dependency will take a list of roles. It will then fetch the current user and verify if any of their assigned roles match the required roles.

from fastapi import Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user
async def get_current_user() -> User:
    return User(username="test_user", roles=[UserRole.BASIC_USER])

def role_required(required_roles: List[UserRole]):
    async def role_checker(current_user: User = Depends(get_current_user)):
        if not any(role in current_user.roles for role in required_roles):
            raise HTTPException(
                status_code=status.HTTP_403_FORBIDDEN,
                detail="Not enough permissions"
            )
        return current_user
    return role_checker

Code: Admin-Only Endpoint

Here's a full FastAPI application demonstrating how to protect an endpoint so only users with the 'admin' role can access it. Run this code and try accessing /admin and /public.

from fastapi import FastAPI, Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
import uvicorn

app = FastAPI()

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user
# Change roles here to test different access levels
async def get_current_user() -> User:
    # Try changing to [UserRole.BASIC_USER] or [UserRole.ADMIN]
    return User(username="admin_user", roles=[UserRole.ADMIN])

def role_required(required_roles: List[UserRole]):
    async def role_checker(current_user: User = Depends(get_current_user)):
        if not any(role in current_user.roles for role in required_roles):
            raise HTTPException(
                status_code=status.HTTP_403_FORBIDDEN,
                detail="Not enough permissions"
            )
        return current_user
    return role_checker

@app.get("/public")
async def read_public_data():
    return {"message": "This is public data!"}

@app.get("/admin")
async def read_admin_data(current_user: User = Depends(role_required([UserRole.ADMIN]))):
    return {"message": f"Welcome, {current_user.username}! This is admin data."}

if __name__ == "__main__":
    uvicorn.run(app, host="0.0.0.0", port=8000)

Testing the Role Check

When you run the previous code:

  • Access http://127.0.0.1:8000/public: This should always work.
  • Access http://127.0.0.1:8000/admin: This will work if get_current_user returns a user with UserRole.ADMIN.

Try changing the mock user's roles in get_current_user to [UserRole.BASIC_USER] and rerun the app. You'll see a 403 Forbidden error when trying to access /admin.

Allowing Multiple Roles

Sometimes, an endpoint should be accessible by more than one role. For example, both 'admin' and 'editor' users might be allowed to update an article.

Our role_required dependency is already designed for this! It accepts a List[UserRole], and the any() check means access is granted if the user has any one of the specified roles.

Code: Multiple Role Access

This example shows an endpoint accessible by either an 'admin' or an 'editor'. Try changing the mock user's roles to [UserRole.EDITOR] and [UserRole.BASIC_USER] to observe the access control.

from fastapi import FastAPI, Depends, HTTPException, status
from typing import List
from pydantic import BaseModel
from enum import Enum
import uvicorn

app = FastAPI()

class UserRole(str, Enum):
    ADMIN = "admin"
    EDITOR = "editor"
    BASIC_USER = "basic_user"

class User(BaseModel):
    username: str
    roles: List[UserRole]

# Mock function to get current user
# Change roles here to test different access levels
async def get_current_user() -> User:
    # Try [UserRole.ADMIN], [UserRole.EDITOR], or [UserRole.BASIC_USER]
    return User(username="editor_user", roles=[UserRole.EDITOR])

def role_required(required_roles: List[UserRole]):
    async def role_checker(current_user: User = Depends(get_current_user)):
        if not any(role in current_user.roles for role in required_roles):
            raise HTTPException(
                status_code=status.HTTP_403_FORBIDDEN,
                detail="Not enough permissions"
            )
        return current_user
    return role_checker

@app.get("/edit_content")
async def edit_content(current_user: User = Depends(role_required([UserRole.ADMIN, UserRole.EDITOR]))):
    return {"message": f"Hello {current_user.username}! You can edit content."}

@app.get("/view_only")
async def view_only_content(current_user: User = Depends(role_required([UserRole.BASIC_USER]))):
    return {"message": f"Hello {current_user.username}! You can view content."}

if __name__ == "__main__":
    uvicorn.run(app, host="0.0.0.0", port=8000)

RBAC Implementation Check

You need to create an endpoint /dashboard that should only be accessible by users with the ADMIN role. Which of the following is the correct way to apply the role_required dependency?

RBAC Recap

You've learned how to implement Role-Based Access Control in your FastAPI applications:

  • Defined roles using Python Enum for clarity.
  • Understood how user roles are typically associated (e.g., via JWTs).
  • Created a reusable custom dependency (role_required) to check user roles.
  • Applied this dependency to endpoints to restrict access based on single or multiple roles.

RBAC is a powerful way to manage permissions, making your API more secure and maintainable!

免费开始

用 AI 导师学习 JavaScript — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
22
课程
92

常见问题解答

「基于角色的访问控制(RBAC)」课时是免费的吗?

是的 — 「基于角色的访问控制(RBAC)」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Node.js Backend Development Bootcamp 课程的其余内容,请升级到 CoddyKit PRO。 Node.js Backend Development Bootcamp 课程共包含 6 节课。

「基于角色的访问控制(RBAC)」这节课中我会学到什么?

实现基于角色的授权,根据用户角色和权限限制对特定端点的访问。 你通过在浏览器中直接运行的动手代码来练习 Node.js Backend Development Bootcamp,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Node.js Backend Development Bootcamp 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Node.js Backend Development Bootcamp 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 6 节课,共 6 节。

「基于角色的访问控制(RBAC)」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Node.js Backend Development Bootcamp 课中编写并运行代码吗?

能。每节 Node.js Backend Development Bootcamp 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 用户注册与登录
  2. JWT 令牌生成与验证
  3. 使用 JWT 实现无状态身份验证
  4. 集成 OAuth2 密码流程
  5. 基于角色的访问控制
  6. 基于角色的访问控制(RBAC)
← 返回 Node.js Backend Development Bootcamp