On my backend, I have an RPC API with AuthN/Authz setup. Every endpoint can be independently controlled for permissions
For authorization, I have 3 roles, let's call them levels 1-3.
- Level1: Can view its own user
- Level2: All of the above, and also query the database
- Level3: All of the above, and can also delete the entire database
If a Level1 user tries to call /database/delete they'll get a 403.
The issue here is UX. If I'm building a frontend, I only want to show users the actions that are available to them. I don't want Level1 users to have a button that says "Delete Database" even if they can't actually do that.
I can implement this manually on the frontend, using something like this
var permissions = []
if (user.group === "Level1"){
permissions = ["get-user"]
}
But then that code has to be maintained manually, is quite likely to drift and break. I'm thinking of doing something like this
permissions = await fetch(api.example.com/permissions)
Which would then return the list of permissions that are available to the calling user. My only hesitation is that I've never seen this pattern implemented anywhere else, and that tends to indicate it's a bad idea. Is there a best practice for this scenario?