Role-Based Authorization

Introduction: Why Role-Based Authorization?

Welcome back! In the last lesson, you learned how to protect your API routes so that only authenticated users with a valid JWT can access them. That’s a great start, but in most real-world applications, not all users should have the same permissions. For example, you might want only administrators to be able to delete books or update user information, while regular users can only view data.

In the previous unit we only had JwtAuthGuard: any authenticated user could perform mutations (create/update/delete). That’s intentionally incomplete. In this unit we’ll require roles for sensitive actions. To make this concrete now, we’ll use an admin role (you already have a seeded admin user). In the SPA playground provided with the course you can try both a normal user and an admin; later, in the frontend path, you’ll build your own React UI.

This is where role-based authorization comes in. With role-based authorization, you can control what actions different types of users can perform in your API. In this lesson, you’ll learn how to implement this in your NestJS project so you can restrict certain endpoints to users with specific roles, like admin or user.

Quick Recap: Our API Structure

Before we dive in, let’s quickly remind ourselves of the current setup. You already have:

  • Registration (bcrypt hashes stored).
  • JWT Login (token with sub, role, iat, exp).
  • JwtAuthGuard (only checks if the token is valid → user is logged in).

Here’s a simplified code block to show where we are, focusing on how user roles fit in:

// Example: Protecting a route with JwtAuthGuard
@Patch(':id')
@UseGuards(JwtAuthGuard)
update(
    @Param('id', ParseUUIDPipe) id: string,
    @Body() updateBookDto: UpdateBookDto,
) {
    const book = this.booksService.update(id, updateBookDto);
    return { success: true, data: book };
  }

What’s wrong

  • Any logged-in user can call write endpoints (e.g., create a book). That violates least-privilege.

What we’ll add

  • @Roles() decorator to declare required roles on a route.
  • RolesGuard to enforce those requirements after JwtAuthGuard authenticates the user.
  • BooksController write routes become admin-only (read routes remain public or authenticated as you decide).

Creating a Roles Decorator

Sign up

Join the 1M+ learners on CodeSignal

Be a part of our community of 1M+ users who develop and demonstrate their skills on CodeSignal