rbacv0.01This module provides Role-Based Access Control (RBAC) capabilities, enabling permission checks and authorization logic across the application.
Core responsibilities include:
Effective Permission Resolution
Permission Checks
Centralized Authorization Logic
Design
Requirements
Tests
Authorization Flows
/core/auth (for authenticated user context)/profile (optional: user metadata)rbac::shared::service)db_generic SeaORM connectorRoute handlers include:
RBAC data stored in normalized tables
Supports:
The RBAC service layer is responsible for resolving joins and inheritance rules.
| Method | Path | Description |
|---|---|---|
| GET | /api/rbac/effective-permissions |
Get all effective permissions for a user |
| GET | /api/rbac/has-permission |
Check if user has a specific permission |
GET /api/rbac/effective-permissions| Name | Type | Description |
|---|---|---|
| user_id | UUID | Target user identifier |
GET /api/rbac/has-permission| Name | Type | Description |
|---|---|---|
| user_id | UUID | Target user identifier |
| permission | String | Permission key to be evaluated |
{
"user_id": "uuid",
"permissions": ["user.read", "user.write", "admin.panel"]
}
{
"user_id": "uuid",
"permission": "admin.panel",
"allowed": true
}
users| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
roles| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| name | String | Unique role name |
permissions| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| key | String | Permission identifier string |
user_roles| Field | Type | Description |
|---|---|---|
| user_id | UUID | FK → users |
| role_id | UUID | FK → roles |
role_permissions| Field | Type | Description |
|---|---|---|
| role_id | UUID | FK → roles |
| permission_id | UUID | FK → permissions |
| Function | Description |
|---|---|
effective_permissions(user_id) |
Resolves all permissions for a user |
has_permission(user_id, permission) |
Checks if a permission is granted |