ABAC in Node.js with Express
Role-based access control answers "what may an editor do?". Many real rules need more than a role: authors may edit their own drafts, editors may edit articles from their own department, anyone may read a published article. These depend on attributes of the user and of the resource, which is what attribute-based access control (ABAC) is for.
This tutorial builds a small article API with Express and puts all of those rules in a Casbin policy file. The same model and policy work unchanged in the Go and Python versions of this tutorial. If you are still choosing between RBAC and ABAC, read Choosing an access control model first.