Module 6 of 9 · Lesson 18 of 26
Preserve permission decisions with Casbin
Work through preserve permission decisions with Casbin using a runnable reference, a focused regression check and a local extension.
Read in any order. All lessons stay open, including after an unanswered or incorrect check.
policy.py constructs a small in-memory enforcer from an explicit matrix. It does not create a database policy administrator or grant a real person a role. test_lesson18 compares every combination of four roles, two owner relationships and three actions with the original may function. This equivalence check guards against broadening permission during refactoring. A readable policy still depends on trustworthy inputs: build Principal from the current user record and Resource from the loaded rental. Never accept a client's claimed role or owner as the object. If policy storage becomes persistent, changes need review, versioning and tests of both allowed and denied paths. Refactoring the enforcement mechanism is not a reason to silently alter the policy.
Run lesson18 and count the 24 comparisons. Read the policies added to enforcer and the matcher condition. Notice that admin read/check-in and operator check-in are explicit rather than inferred from a vague role hierarchy. The original Python rule provides a reference for this conversion.
def enforcer():
model = casbin.Model()
model.load_model_from_text(MODEL)
result = casbin.Enforcer(model)
for role, action in (
("customer", "read"),
("operator", "check_in"),
("admin", "read"),
("admin", "check_in"),
):
result.add_policy(role, action)
return result
python run_checks.py -k lesson18
Expected result The selected lesson test passes against a new temporary PostgreSQL database; the container is removed afterward.
Keep for reference
Equipment Rental lab and lesson checks
ZIP containing Python source, real Alembic migrations, 26 lesson checks, a dependency lock and text instructions. Extract it before following the local exercise.
Practise locally
Propose a support role that can read every rental but cannot check one in. Add it to both rule representations in your own lab copy, then extend the full equivalence matrix and add explicit deny assertions for check-in and delete. Record the intended new allow separately so a reviewer can see the behavior change.
The lesson check verifies the reference behavior. Add your own assertions for your change. Local practice is not uploaded or scored by this learning release.
Pause and reflect
What failure does this lesson prevent, and which assertion in lesson18 would expose it?
Use a concrete input, expected result and limitation from your local work. Saving a reflection does not certify the project.
Optional knowledge check
What is the best check when replacing may with Casbin?
Add a catch-all allow rule so the refactor cannot break existing access.
Try another answer. A catch-all broadens authority; preserve the intended matrix with deny tests.
Compare allow and deny decisions across the complete role, ownership and action matrix.
Correct. Equivalence tests reveal both lost permissions and unintended new permissions.
Check only that an administrator can perform one action.
Try another answer. One allowed example cannot detect broadened customer or unknown-role permissions.
This practice does not assess your project or award a certificate.
Your reading progress
Progress is saved in this browser when storage is available.