Skip to content
Aabha AI Academy

Module 6 of 9 · Lesson 18 of 26

Preserve permission decisions with Casbin

Work through preserve permission decisions with Casbin using a runnable reference, a focused regression check and a local extension.

Read in any order. All lessons stay open, including after an unanswered or incorrect check.

In this lesson you will preserve permission decisions with Casbin. Work with the Equipment Rental API in the downloadable lab. The reference is a complete solution with separate lesson checks, so you can inspect the answer, make a deliberate local change and verify its behavior.
Moving a permission rule into Casbin should preserve its decisions. The model represents subject, object and action; policy rows permit named role/action pairs. The matcher also checks ownership for the customer. Unknown roles and unsupported actions have no matching allow, so the policy denies them.

policy.py constructs a small in-memory enforcer from an explicit matrix. It does not create a database policy administrator or grant a real person a role. test_lesson18 compares every combination of four roles, two owner relationships and three actions with the original may function. This equivalence check guards against broadening permission during refactoring. A readable policy still depends on trustworthy inputs: build Principal from the current user record and Resource from the loaded rental. Never accept a client's claimed role or owner as the object. If policy storage becomes persistent, changes need review, versioning and tests of both allowed and denied paths. Refactoring the enforcement mechanism is not a reason to silently alter the policy.
Worked source: equipment/policy.py, enforcer.

Run lesson18 and count the 24 comparisons. Read the policies added to enforcer and the matcher condition. Notice that admin read/check-in and operator check-in are explicit rather than inferred from a vague role hierarchy. The original Python rule provides a reference for this conversion.
pythonCopyable
def enforcer():
    model = casbin.Model()
    model.load_model_from_text(MODEL)
    result = casbin.Enforcer(model)
    for role, action in (
        ("customer", "read"),
        ("operator", "check_in"),
        ("admin", "read"),
        ("admin", "check_in"),
    ):
        result.add_policy(role, action)
    return result
TerminalPython 3.13 virtual environment; Docker running; extracted lab directory
python run_checks.py -k lesson18

Expected result The selected lesson test passes against a new temporary PostgreSQL database; the container is removed afterward.

Keep for reference

Equipment Rental lab and lesson checks

ZIP containing Python source, real Alembic migrations, 26 lesson checks, a dependency lock and text instructions. Extract it before following the local exercise.

Download Equipment Rental lab and lesson checks

Practise locally

Propose a support role that can read every rental but cannot check one in. Add it to both rule representations in your own lab copy, then extend the full equivalence matrix and add explicit deny assertions for check-in and delete. Record the intended new allow separately so a reviewer can see the behavior change.

The lesson check verifies the reference behavior. Add your own assertions for your change. Local practice is not uploaded or scored by this learning release.

Pause and reflect

What failure does this lesson prevent, and which assertion in lesson18 would expose it?

Use a concrete input, expected result and limitation from your local work. Saving a reflection does not certify the project.

Optional knowledge check

What is the best check when replacing may with Casbin?

Add a catch-all allow rule so the refactor cannot break existing access.

Try another answer. A catch-all broadens authority; preserve the intended matrix with deny tests.

Compare allow and deny decisions across the complete role, ownership and action matrix.

Correct. Equivalence tests reveal both lost permissions and unintended new permissions.

Check only that an administrator can perform one action.

Try another answer. One allowed example cannot detect broadened customer or unknown-role permissions.

This practice does not assess your project or award a certificate.

Your reading progress

Progress is saved in this browser when storage is available.

Sign in to save across devices · Create an optional account