AccessControl.sol 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223
  1. // SPDX-License-Identifier: MIT
  2. // OpenZeppelin Contracts v4.4.0-rc.1 (access/AccessControl.sol)
  3. pragma solidity ^0.8.0;
  4. import "./IAccessControl.sol";
  5. import "../utils/Context.sol";
  6. import "../utils/Strings.sol";
  7. import "../utils/introspection/ERC165.sol";
  8. /**
  9. * @dev Contract module that allows children to implement role-based access
  10. * control mechanisms. This is a lightweight version that doesn't allow enumerating role
  11. * members except through off-chain means by accessing the contract event logs. Some
  12. * applications may benefit from on-chain enumerability, for those cases see
  13. * {AccessControlEnumerable}.
  14. *
  15. * Roles are referred to by their `bytes32` identifier. These should be exposed
  16. * in the external API and be unique. The best way to achieve this is by
  17. * using `public constant` hash digests:
  18. *
  19. * ```
  20. * bytes32 public constant MY_ROLE = keccak256("MY_ROLE");
  21. * ```
  22. *
  23. * Roles can be used to represent a set of permissions. To restrict access to a
  24. * function call, use {hasRole}:
  25. *
  26. * ```
  27. * function foo() public {
  28. * require(hasRole(MY_ROLE, msg.sender));
  29. * ...
  30. * }
  31. * ```
  32. *
  33. * Roles can be granted and revoked dynamically via the {grantRole} and
  34. * {revokeRole} functions. Each role has an associated admin role, and only
  35. * accounts that have a role's admin role can call {grantRole} and {revokeRole}.
  36. *
  37. * By default, the admin role for all roles is `DEFAULT_ADMIN_ROLE`, which means
  38. * that only accounts with this role will be able to grant or revoke other
  39. * roles. More complex role relationships can be created by using
  40. * {_setRoleAdmin}.
  41. *
  42. * WARNING: The `DEFAULT_ADMIN_ROLE` is also its own admin: it has permission to
  43. * grant and revoke this role. Extra precautions should be taken to secure
  44. * accounts that have been granted it.
  45. */
  46. abstract contract AccessControl is Context, IAccessControl, ERC165 {
  47. struct RoleData {
  48. mapping(address => bool) members;
  49. bytes32 adminRole;
  50. }
  51. mapping(bytes32 => RoleData) private _roles;
  52. bytes32 public constant DEFAULT_ADMIN_ROLE = 0x00;
  53. /**
  54. * @dev Modifier that checks that an account has a specific role. Reverts
  55. * with a standardized message including the required role.
  56. *
  57. * The format of the revert reason is given by the following regular expression:
  58. *
  59. * /^AccessControl: account (0x[0-9a-f]{40}) is missing role (0x[0-9a-f]{64})$/
  60. *
  61. * _Available since v4.1._
  62. */
  63. modifier onlyRole(bytes32 role) {
  64. _checkRole(role, _msgSender());
  65. _;
  66. }
  67. /**
  68. * @dev See {IERC165-supportsInterface}.
  69. */
  70. function supportsInterface(bytes4 interfaceId) public view virtual override returns (bool) {
  71. return interfaceId == type(IAccessControl).interfaceId || super.supportsInterface(interfaceId);
  72. }
  73. /**
  74. * @dev Returns `true` if `account` has been granted `role`.
  75. */
  76. function hasRole(bytes32 role, address account) public view override returns (bool) {
  77. return _roles[role].members[account];
  78. }
  79. /**
  80. * @dev Revert with a standard message if `account` is missing `role`.
  81. *
  82. * The format of the revert reason is given by the following regular expression:
  83. *
  84. * /^AccessControl: account (0x[0-9a-f]{40}) is missing role (0x[0-9a-f]{64})$/
  85. */
  86. function _checkRole(bytes32 role, address account) internal view {
  87. if (!hasRole(role, account)) {
  88. revert(
  89. string(
  90. abi.encodePacked(
  91. "AccessControl: account ",
  92. Strings.toHexString(uint160(account), 20),
  93. " is missing role ",
  94. Strings.toHexString(uint256(role), 32)
  95. )
  96. )
  97. );
  98. }
  99. }
  100. /**
  101. * @dev Returns the admin role that controls `role`. See {grantRole} and
  102. * {revokeRole}.
  103. *
  104. * To change a role's admin, use {_setRoleAdmin}.
  105. */
  106. function getRoleAdmin(bytes32 role) public view override returns (bytes32) {
  107. return _roles[role].adminRole;
  108. }
  109. /**
  110. * @dev Grants `role` to `account`.
  111. *
  112. * If `account` had not been already granted `role`, emits a {RoleGranted}
  113. * event.
  114. *
  115. * Requirements:
  116. *
  117. * - the caller must have ``role``'s admin role.
  118. */
  119. function grantRole(bytes32 role, address account) public virtual override onlyRole(getRoleAdmin(role)) {
  120. _grantRole(role, account);
  121. }
  122. /**
  123. * @dev Revokes `role` from `account`.
  124. *
  125. * If `account` had been granted `role`, emits a {RoleRevoked} event.
  126. *
  127. * Requirements:
  128. *
  129. * - the caller must have ``role``'s admin role.
  130. */
  131. function revokeRole(bytes32 role, address account) public virtual override onlyRole(getRoleAdmin(role)) {
  132. _revokeRole(role, account);
  133. }
  134. /**
  135. * @dev Revokes `role` from the calling account.
  136. *
  137. * Roles are often managed via {grantRole} and {revokeRole}: this function's
  138. * purpose is to provide a mechanism for accounts to lose their privileges
  139. * if they are compromised (such as when a trusted device is misplaced).
  140. *
  141. * If the calling account had been revoked `role`, emits a {RoleRevoked}
  142. * event.
  143. *
  144. * Requirements:
  145. *
  146. * - the caller must be `account`.
  147. */
  148. function renounceRole(bytes32 role, address account) public virtual override {
  149. require(account == _msgSender(), "AccessControl: can only renounce roles for self");
  150. _revokeRole(role, account);
  151. }
  152. /**
  153. * @dev Grants `role` to `account`.
  154. *
  155. * If `account` had not been already granted `role`, emits a {RoleGranted}
  156. * event. Note that unlike {grantRole}, this function doesn't perform any
  157. * checks on the calling account.
  158. *
  159. * [WARNING]
  160. * ====
  161. * This function should only be called from the constructor when setting
  162. * up the initial roles for the system.
  163. *
  164. * Using this function in any other way is effectively circumventing the admin
  165. * system imposed by {AccessControl}.
  166. * ====
  167. *
  168. * NOTE: This function is deprecated in favor of {_grantRole}.
  169. */
  170. function _setupRole(bytes32 role, address account) internal virtual {
  171. _grantRole(role, account);
  172. }
  173. /**
  174. * @dev Sets `adminRole` as ``role``'s admin role.
  175. *
  176. * Emits a {RoleAdminChanged} event.
  177. */
  178. function _setRoleAdmin(bytes32 role, bytes32 adminRole) internal virtual {
  179. bytes32 previousAdminRole = getRoleAdmin(role);
  180. _roles[role].adminRole = adminRole;
  181. emit RoleAdminChanged(role, previousAdminRole, adminRole);
  182. }
  183. /**
  184. * @dev Grants `role` to `account`.
  185. *
  186. * Internal function without access restriction.
  187. */
  188. function _grantRole(bytes32 role, address account) internal virtual {
  189. if (!hasRole(role, account)) {
  190. _roles[role].members[account] = true;
  191. emit RoleGranted(role, account, _msgSender());
  192. }
  193. }
  194. /**
  195. * @dev Revokes `role` from `account`.
  196. *
  197. * Internal function without access restriction.
  198. */
  199. function _revokeRole(bytes32 role, address account) internal virtual {
  200. if (hasRole(role, account)) {
  201. _roles[role].members[account] = false;
  202. emit RoleRevoked(role, account, _msgSender());
  203. }
  204. }
  205. }