RBAC in NestJS
This tutorial adds role-based access control (RBAC) to a NestJS API with node-casbin. Each route declares the permission it needs with a decorator, a global guard asks Casbin whether the current user has it, and roles inherit from each other, so an admin automatically gets everything an editor can do.
The permissions are named after resources and actions (articles, delete) instead of URL paths, which fits NestJS controllers well. For path-based rules, see the Express version.