Role-Based Access Control (RBAC) with granular scope evaluation. Simulate requests as admin, editor, viewer, or guest using custom simulation headers to test route authorization guards and HTTP 403 Forbidden responses.
Select an authorization scenario below to test permission enforcement on live backend endpoints:
Authorization privileges across system collections and operational action boundaries:
| Resource Domain | Read (GET) | Create (POST) | Update (PUT/PATCH) | Delete (DELETE) | Admin / Reset |
|---|---|---|---|---|---|
| Users & Profiles | All Roles | Editor, Admin | Editor, Admin | Admin Only | Admin Only |
| Posts & Comments | All Roles | Editor, Admin | Editor, Admin | Admin Only | Admin Only |
| Todos Checklist | All Roles | Editor, Admin | Editor, Admin | Admin Only | Admin Only |
| Media & File Uploads | All Roles | Editor, Admin | Editor, Admin | Admin Only | Admin Only |
| Sandbox Reset & Seeding | Editor, Admin | Admin Only | Admin Only | Admin Only | Admin Only |
Query system roles, persona definitions, and full permission matrix mappings directly via REST endpoints:
Returns all supported roles (admin, editor, viewer, guest), persona credentials, and default scopes:
Returns the system permission matrix, allowed action verbs per role, and wildcard matching syntax (*:read, posts:*):
Patterns for protecting sensitive components and action buttons in React 19: