0Pricing
Spring Security 6 & JWT Authentication · 课时

基于角色的访问控制(RBAC)

实现基于角色的授权,根据用户角色和权限限制对特定资源的访问。

基于角色的访问控制(RBAC) 是 CoddyKit 上的免费 Spring Security 6 & JWT Authentication 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Security 6 & JWT Authentication 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Understanding RBAC Basics

Welcome! Today we'll dive into Role-Based Access Control (RBAC). It's a fundamental security concept for managing who can do what in an application.

Imagine a school: students can view grades, teachers can post grades, and administrators can manage all users. Each group has a 'role' with specific 'permissions'.

  • Role: A collection of permissions.
  • Permission: The ability to perform a specific action (e.g., read, write, delete).

Roles in Spring Security

Spring Security uses roles to enforce authorization. When you define a user, you also assign them one or more roles.

Internally, Spring Security treats roles as Granted Authorities. By convention, roles are often prefixed with ROLE_ (e.g., ROLE_ADMIN, ROLE_USER). This helps distinguish them from other types of authorities.

Assigning Roles to Users

Before we can use RBAC, users need roles! When a user logs in, Spring Security's authentication process retrieves their assigned roles.

These roles are typically loaded from a database via a UserDetailsService, or for simpler cases, defined directly in memory. We'll use in-memory users for our examples to keep things clear.

Securing URLs with `hasRole()`

The core of RBAC in Spring Security for web applications is configuring HttpSecurity. We use methods like hasRole() to specify which roles can access certain URL patterns.

For example, to protect an 'admin' page, you might write: .requestMatchers("/admin/**").hasRole("ADMIN"). Spring Security automatically adds the ROLE_ prefix when you use hasRole().

RBAC Web Security Config

Let's see a simple Spring Security configuration. This setup defines two in-memory users (user and admin) and secures two endpoints: /user and /admin.

Try running this code and accessing the URLs!

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@RestController
public class Main {

  public static void main(String[] args) {
    SpringApplication.run(Main.class, args);
  }

  @GetMapping("/user")
  public String userEndpoint() {
    return "Hello, User!";
  }

  @GetMapping("/admin")
  public String adminEndpoint() {
    return "Hello, Admin!";
  }

  @Configuration
  @EnableWebSecurity
  static class WebSecurityConfig {

    @Bean
    public UserDetailsService userDetailsService() {
      UserDetails user = User.withDefaultPasswordEncoder()
          .username("user")
          .password("password")
          .roles("USER")
          .build();
      UserDetails admin = User.withDefaultPasswordEncoder()
          .username("admin")
          .password("password")
          .roles("ADMIN", "USER")
          .build();
      return new InMemoryUserDetailsManager(user, admin);
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
      http
          .authorizeHttpRequests(authorize -> authorize
              .requestMatchers("/user/**").hasRole("USER")
              .requestMatchers("/admin/**").hasRole("ADMIN")
              .anyRequest().authenticated()
          )
          .formLogin(org.springframework.security.config.Customizer.withDefaults());
      return http.build();
    }
  }
}

Testing Our RBAC Setup

After running the previous example, open your browser and try to access these URLs:

  • http://localhost:8080/user: Log in with user/password or admin/password. Both should work!
  • http://localhost:8080/admin: Log in with admin/password. This should work.
  • http://localhost:8080/admin: Log in with user/password. You should see an 'Access Denied' error (403 Forbidden).

This demonstrates how roles restrict access!

Multiple Roles: `hasAnyRole()`

What if an endpoint can be accessed by more than one role? Spring Security provides hasAnyRole() for this.

Instead of listing multiple hasRole() calls, you can do: .requestMatchers("/dashboard/**").hasAnyRole("USER", "ADMIN"). This grants access if the authenticated user has EITHER the USER role OR the ADMIN role.

`hasRole()` vs `hasAuthority()`

You might also see hasAuthority() being used. What's the difference?

  • hasRole("ADMIN"): This implicitly adds the ROLE_ prefix, so it checks for ROLE_ADMIN.
  • hasAuthority("ROLE_ADMIN"): This requires the exact authority string, including the ROLE_ prefix if it's part of the authority name.

Generally, hasRole() is preferred for clarity when dealing with roles defined with the ROLE_ prefix.

Securing Specific HTTP Methods

RBAC can also be applied to specific HTTP methods for a given path. This is useful for REST APIs where different actions (GET, POST, PUT, DELETE) require different permissions.

You can chain requestMatchers() with HttpMethod:

.requestMatchers(HttpMethod.POST, "/products/**").hasRole("ADMIN")
.requestMatchers(HttpMethod.GET, "/products/**").hasAnyRole("USER", "ADMIN")

Here, only ADMIN can create products, but both USER and ADMIN can view them.

Best Practices for RBAC

To make RBAC effective and manageable:

  • Keep Roles Simple: Don't create too many roles. Roles should represent distinct job functions.
  • Least Privilege: Grant only the necessary roles/permissions to users.
  • Centralized Management: Manage roles and their assignments from a single, secure place.
  • Audit Regularly: Periodically review role assignments and permissions to ensure they are still appropriate.

RBAC Knowledge Check

You've learned about implementing Role-Based Access Control in Spring Security. Let's quickly test your understanding!

Recap: Role-Based Access Control

Great job! In this lesson, you learned about:

  • What RBAC is and its importance for authorization.
  • How Spring Security uses roles (as GrantedAuthority).
  • Configuring URL-based RBAC with HttpSecurity.
  • Using hasRole() and hasAnyRole() to protect endpoints.
  • Distinguishing between hasRole() and hasAuthority().
  • Applying RBAC to specific HTTP methods.
  • Key best practices for effective RBAC implementation.

You now have a solid foundation for controlling access based on user roles!

常见问题解答

「基于角色的访问控制(RBAC)」课时是免费的吗?

是的 — 「基于角色的访问控制(RBAC)」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Security 6 & JWT Authentication 课程的其余内容,请升级到 CoddyKit PRO。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

「基于角色的访问控制(RBAC)」这节课中我会学到什么?

实现基于角色的授权,根据用户角色和权限限制对特定资源的访问。 你通过在浏览器中直接运行的动手代码来练习 Spring Security 6 & JWT Authentication,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Spring Security 6 & JWT Authentication 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Spring Security 6 & JWT Authentication 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。

「基于角色的访问控制(RBAC)」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Spring Security 6 & JWT Authentication 课中编写并运行代码吗?

能。每节 Spring Security 6 & JWT Authentication 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 基于角色的访问控制(RBAC)
  2. 使用注解实现方法级安全
  3. 深入了解 HttpSecurity 配置
  4. 使用自定义访问规则保护端点
← 返回 Spring Security 6 & JWT Authentication