RBAC in Node.js with Express
This tutorial adds role-based access control (RBAC) to a REST API built with Express. At the end, three roles (admin, editor, viewer) are allowed different HTTP methods on different routes, and the rules live in a policy file that you can change without touching the route handlers.
The same model and policy work in every Casbin implementation, so you can reuse them in the Go, Python, and Java versions of this tutorial.