abhish1227 / abhish1227/HospitalDB_Spring

Feature Request: Add Role-Based Authentication

Offen
#1 3 Kommentare 0 Reaktionen 1 zugewiesene Person Zugewiesen an @abhish1227 Auf GitHub ansehen
enhancement good first issue help wanted
Vorherrschende Sprache
Java
Sterne
1
Forks
1
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### **Description**
Implement role-based access control (RBAC) to restrict access to specific endpoints based on user roles (e.g., ADMIN, DOCTOR, PATIENT). This will enhance security and allow fine-grained permission management across the system.

### **Motivation**
Currently, all authenticated users have equal access to protected endpoints. Introducing roles will:
- Prevent unauthorized access to sensitive operations
- Enable scalable permission management
- Align with real-world hospital workflows (e.g., only doctors can update medical records)

### Proposed Changes:
- Add a role field to the User entity (e.g., Enum or String)
- Assign roles during registration or via admin panel
- Update SecurityFilterChain to restrict endpoints using .hasRole("ROLE_NAME")

Example:
```
.requestMatchers("/doctors/admin/**").hasRole("DOCTOR")
.requestMatchers("/patients/admin/**").hasRole("ADMIN")
```
### Acceptance Criteria:
- Users can only access endpoints permitted by their role
- Unauthorized access returns 403 Forbidden
- Role assignment is clearly documented and testable

### Additional Notes:
- Consider using Spring Security’s GrantedAuthority and UserDetailsService for extensibility
- Update README with role-based access documentation once implemented

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.