RBAC.sol 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108
  1. pragma solidity ^0.4.21;
  2. import "./Roles.sol";
  3. /**
  4. * @title RBAC (Role-Based Access Control)
  5. * @author Matt Condon (@Shrugs)
  6. * @dev Stores and provides setters and getters for roles and addresses.
  7. * @dev Supports unlimited numbers of roles and addresses.
  8. * @dev See //contracts/mocks/RBACMock.sol for an example of usage.
  9. * This RBAC method uses strings to key roles. It may be beneficial
  10. * for you to write your own implementation of this interface using Enums or similar.
  11. * It's also recommended that you define constants in the contract, like ROLE_ADMIN below,
  12. * to avoid typos.
  13. */
  14. contract RBAC {
  15. using Roles for Roles.Role;
  16. mapping (string => Roles.Role) private roles;
  17. event RoleAdded(address addr, string roleName);
  18. event RoleRemoved(address addr, string roleName);
  19. /**
  20. * @dev reverts if addr does not have role
  21. * @param addr address
  22. * @param roleName the name of the role
  23. * // reverts
  24. */
  25. function checkRole(address addr, string roleName)
  26. view
  27. public
  28. {
  29. roles[roleName].check(addr);
  30. }
  31. /**
  32. * @dev determine if addr has role
  33. * @param addr address
  34. * @param roleName the name of the role
  35. * @return bool
  36. */
  37. function hasRole(address addr, string roleName)
  38. view
  39. public
  40. returns (bool)
  41. {
  42. return roles[roleName].has(addr);
  43. }
  44. /**
  45. * @dev add a role to an address
  46. * @param addr address
  47. * @param roleName the name of the role
  48. */
  49. function addRole(address addr, string roleName)
  50. internal
  51. {
  52. roles[roleName].add(addr);
  53. emit RoleAdded(addr, roleName);
  54. }
  55. /**
  56. * @dev remove a role from an address
  57. * @param addr address
  58. * @param roleName the name of the role
  59. */
  60. function removeRole(address addr, string roleName)
  61. internal
  62. {
  63. roles[roleName].remove(addr);
  64. emit RoleRemoved(addr, roleName);
  65. }
  66. /**
  67. * @dev modifier to scope access to a single role (uses msg.sender as addr)
  68. * @param roleName the name of the role
  69. * // reverts
  70. */
  71. modifier onlyRole(string roleName)
  72. {
  73. checkRole(msg.sender, roleName);
  74. _;
  75. }
  76. /**
  77. * @dev modifier to scope access to a set of roles (uses msg.sender as addr)
  78. * @param roleNames the names of the roles to scope access to
  79. * // reverts
  80. *
  81. * @TODO - when solidity supports dynamic arrays as arguments to modifiers, provide this
  82. * see: https://github.com/ethereum/solidity/issues/2467
  83. */
  84. // modifier onlyRoles(string[] roleNames) {
  85. // bool hasAnyRole = false;
  86. // for (uint8 i = 0; i < roleNames.length; i++) {
  87. // if (hasRole(msg.sender, roleNames[i])) {
  88. // hasAnyRole = true;
  89. // break;
  90. // }
  91. // }
  92. // require(hasAnyRole);
  93. // _;
  94. // }
  95. }