How to make discoverable API permissions

Viewed 39

On my backend, I have an RPC API with AuthN/Authz setup. Every endpoint can be independently controlled for permissions

For authorization, I have 3 roles, let's call them levels 1-3.

  • Level1: Can view its own user
  • Level2: All of the above, and also query the database
  • Level3: All of the above, and can also delete the entire database

If a Level1 user tries to call /database/delete they'll get a 403.

The issue here is UX. If I'm building a frontend, I only want to show users the actions that are available to them. I don't want Level1 users to have a button that says "Delete Database" even if they can't actually do that.

I can implement this manually on the frontend, using something like this

var permissions = []
if (user.group === "Level1"){
  permissions = ["get-user"]
}

But then that code has to be maintained manually, is quite likely to drift and break. I'm thinking of doing something like this

permissions = await fetch(api.example.com/permissions)

Which would then return the list of permissions that are available to the calling user. My only hesitation is that I've never seen this pattern implemented anywhere else, and that tends to indicate it's a bad idea. Is there a best practice for this scenario?

0 Answers
Related