Files
MC-SurvivalWiki-Tips/tips/2026-06-24-013-security-role-separation-editor-vs-moderator-vs-admin.md
T

1.2 KiB

Tip #13 — Role separation: editor vs moderator vs admin

Date: 2026-06-24
Category: security
Source: MC-Survival Wiki Daily Tip (backfilled from state.json)

Role separation: editor vs moderator vs admin

Split the single 'admin' role in Better Auth into four tiers (ADMIN, MODERATOR, EDITOR, USER) backed by a small permissions.ts matrix, and expose a typed can(action) helper through the existing use-auth.ts hook. It solves the too-coarse-grained problem: today anyone with the 'admin' flag can do anything, which means we either give out too much access or not enough. The signal is the editorial roadmap: we are about to invite moderators, and we need a clean way to say 'you can edit and soft-delete, but you cannot change roles'. A permission matrix is the right shape because it scales to new actions without restructuring the role enum, and the can() helper makes the call sites read like English.

Implementation tips

  1. Better Auth roles: ADMIN, MODERATOR, EDITOR, USER. Permission matrix in a small permissions.ts map.
  2. MODERATOR can edit + soft-delete. EDITOR can edit but not delete. ADMIN manages roles + sees audit log.
  3. Update the existing use-auth.ts hook to expose a typed role + a can(action) helper.