search
HomeWeb Front-endJS TutorialRole-Based Authentication in MERN Stack: A Complete Guide

Role-Based Authentication in MERN Stack: A Complete Guide

Authentication is a crucial aspect of web applications, ensuring that only authorized users can access certain resources. Role-Based Authentication (RBAC) takes this a step further by assigning different permissions to users based on their roles.

In this post, we'll cover:
✅ What is Role-Based Authentication?
✅ Why Use Role-Based Authentication?
✅ How to Implement RBAC in a MERN Stack Application

What is Role-Based Authentication?
Role-Based Access Control (RBAC) is a security approach where users are assigned roles, and each role has specific permissions.

For example, in an e-commerce application:

Admin can add, edit, or delete products.
Seller can manage their own products.
Customer can only view and purchase products.
This ensures that users can only perform actions relevant to their roles.

Why Use Role-Based Authentication?
✔ Enhanced Security – Prevents unauthorized access to sensitive operations.
✔ Scalability – Easily add new roles and permissions as the system grows.
✔ Better User Management – Assign permissions without modifying code.

How to Implement RBAC in a MERN Stack Application?
1️⃣ Setting Up the User Model (MongoDB Mongoose)
In your models/user.model.js:

javascript
Copy code
const mongoose = require("mongoose");

const UserSchema = new mongoose.Schema({
username: { type: String, required: true, unique: true },
email: { type: String, required: true, unique: true },
password: { type: String, required: true },
role: {
type: String,
enum: ["admin", "seller", "customer"],
default: "customer"
}
});

module.exports = mongoose.model("User", UserSchema);
? Here, each user has a role field, which determines their permissions.

2️⃣ Generating JWT Tokens for Authentication
In your controllers/auth.controller.js:

javascript
Copy code
const jwt = require("jsonwebtoken");
const User = require("../models/user.model");

const login = async (req, res) => {
const { email, password } = req.body;
const user = await User.findOne({ email });

if (!user || user.password !== password) {
return res.status(401).json({ message: "Invalid credentials" });
}

const token = jwt.sign({ userId: user._id, role: user.role }, "SECRET_KEY", { expiresIn: "1h" });

res.json({ token, role: user.role });
};

module.exports = { login };
? This function generates a JWT token containing the user's role.

3️⃣ Creating Middleware to Restrict Access
In middlewares/auth.middleware.js:

javascript
Copy code
const jwt = require("jsonwebtoken");

const authenticate = (req, res, next) => {
const token = req.header("Authorization")?.split(" ")[1];

if (!token) return res.status(403).json({ message: "Access denied" });

try {
const decoded = jwt.verify(token, "SECRET_KEY");
req.user = decoded;
next();
} catch (err) {
res.status(401).json({ message: "Invalid token" });
}
};

const authorize = (roles) => {
return (req, res, next) => {
if (!roles.includes(req.user.role)) {
return res.status(403).json({ message: "Forbidden" });
}
next();
};
};

module.exports = { authenticate, authorize };
? authenticate – Ensures only logged-in users can access routes.
? authorize – Restricts access based on roles.

4️⃣ Protecting Routes Based on User Roles
In routes/admin.routes.js:

javascript
Copy code
const express = require("express");
const { authenticate, authorize } = require("../middlewares/auth.middleware");

const router = express.Router();

router.get("/admin-dashboard", authenticate, authorize(["admin"]), (req, res) => {
res.json({ message: "Welcome to the Admin Dashboard" });
});

module.exports = router;
? Only users with the admin role can access /admin-dashboard.

5️⃣ Implementing Role-Based UI in React
In App.js (Frontend):

javascript
Copy code
import { useState, useEffect } from "react";
import axios from "axios";

const App = () => {
const [role, setRole] = useState(null);

useEffect(() => {
const token = localStorage.getItem("token");
if (token) {
const decoded = JSON.parse(atob(token.split(".")[1]));
setRole(decoded.role);
}
}, []);

return (


Welcome to MERN Role-Based Authentication


{role === "admin" && Admin Dashboard}
{role === "seller" && Seller Dashboard}
{role === "customer" && Customer Dashboard}

);
};

export default App;
? The UI displays different dashboards based on the user's role.

Conclusion
Role-Based Authentication is an essential security measure in modern web applications. By implementing RBAC in MERN Stack, you can control user permissions efficiently.

? Next Steps:
? Add a role management panel for admins.
? Implement database encryption for passwords.
? Use Refresh Tokens for better security.

Want to learn more? Drop your questions in the comments! ?

The above is the detailed content of Role-Based Authentication in MERN Stack: A Complete Guide. For more information, please follow other related articles on the PHP Chinese website!

Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
JavaScript in Action: Real-World Examples and ProjectsJavaScript in Action: Real-World Examples and ProjectsApr 19, 2025 am 12:13 AM

JavaScript's application in the real world includes front-end and back-end development. 1) Display front-end applications by building a TODO list application, involving DOM operations and event processing. 2) Build RESTfulAPI through Node.js and Express to demonstrate back-end applications.

JavaScript and the Web: Core Functionality and Use CasesJavaScript and the Web: Core Functionality and Use CasesApr 18, 2025 am 12:19 AM

The main uses of JavaScript in web development include client interaction, form verification and asynchronous communication. 1) Dynamic content update and user interaction through DOM operations; 2) Client verification is carried out before the user submits data to improve the user experience; 3) Refreshless communication with the server is achieved through AJAX technology.

Understanding the JavaScript Engine: Implementation DetailsUnderstanding the JavaScript Engine: Implementation DetailsApr 17, 2025 am 12:05 AM

Understanding how JavaScript engine works internally is important to developers because it helps write more efficient code and understand performance bottlenecks and optimization strategies. 1) The engine's workflow includes three stages: parsing, compiling and execution; 2) During the execution process, the engine will perform dynamic optimization, such as inline cache and hidden classes; 3) Best practices include avoiding global variables, optimizing loops, using const and lets, and avoiding excessive use of closures.

Python vs. JavaScript: The Learning Curve and Ease of UsePython vs. JavaScript: The Learning Curve and Ease of UseApr 16, 2025 am 12:12 AM

Python is more suitable for beginners, with a smooth learning curve and concise syntax; JavaScript is suitable for front-end development, with a steep learning curve and flexible syntax. 1. Python syntax is intuitive and suitable for data science and back-end development. 2. JavaScript is flexible and widely used in front-end and server-side programming.

Python vs. JavaScript: Community, Libraries, and ResourcesPython vs. JavaScript: Community, Libraries, and ResourcesApr 15, 2025 am 12:16 AM

Python and JavaScript have their own advantages and disadvantages in terms of community, libraries and resources. 1) The Python community is friendly and suitable for beginners, but the front-end development resources are not as rich as JavaScript. 2) Python is powerful in data science and machine learning libraries, while JavaScript is better in front-end development libraries and frameworks. 3) Both have rich learning resources, but Python is suitable for starting with official documents, while JavaScript is better with MDNWebDocs. The choice should be based on project needs and personal interests.

From C/C   to JavaScript: How It All WorksFrom C/C to JavaScript: How It All WorksApr 14, 2025 am 12:05 AM

The shift from C/C to JavaScript requires adapting to dynamic typing, garbage collection and asynchronous programming. 1) C/C is a statically typed language that requires manual memory management, while JavaScript is dynamically typed and garbage collection is automatically processed. 2) C/C needs to be compiled into machine code, while JavaScript is an interpreted language. 3) JavaScript introduces concepts such as closures, prototype chains and Promise, which enhances flexibility and asynchronous programming capabilities.

JavaScript Engines: Comparing ImplementationsJavaScript Engines: Comparing ImplementationsApr 13, 2025 am 12:05 AM

Different JavaScript engines have different effects when parsing and executing JavaScript code, because the implementation principles and optimization strategies of each engine differ. 1. Lexical analysis: convert source code into lexical unit. 2. Grammar analysis: Generate an abstract syntax tree. 3. Optimization and compilation: Generate machine code through the JIT compiler. 4. Execute: Run the machine code. V8 engine optimizes through instant compilation and hidden class, SpiderMonkey uses a type inference system, resulting in different performance performance on the same code.

Beyond the Browser: JavaScript in the Real WorldBeyond the Browser: JavaScript in the Real WorldApr 12, 2025 am 12:06 AM

JavaScript's applications in the real world include server-side programming, mobile application development and Internet of Things control: 1. Server-side programming is realized through Node.js, suitable for high concurrent request processing. 2. Mobile application development is carried out through ReactNative and supports cross-platform deployment. 3. Used for IoT device control through Johnny-Five library, suitable for hardware interaction.

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Atom editor mac version download

Atom editor mac version download

The most popular open source editor

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

mPDF

mPDF

mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

MantisBT

MantisBT

Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.