<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Mohame Ali Sraieb</title>
    <description>The latest articles on DEV Community by Mohame Ali Sraieb (@medalisraieb).</description>
    <link>https://dev.to/medalisraieb</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F890402%2Fbc3ece52-da89-478a-8171-ae51a6c6df04.png</url>
      <title>DEV Community: Mohame Ali Sraieb</title>
      <link>https://dev.to/medalisraieb</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/medalisraieb"/>
    <language>en</language>
    <item>
      <title>Stop Writing if (role === "admin") in React. It's a Code Smell.</title>
      <dc:creator>Mohame Ali Sraieb</dc:creator>
      <pubDate>Thu, 26 Mar 2026 13:45:08 +0000</pubDate>
      <link>https://dev.to/medalisraieb/stop-writing-if-role-admin-in-react-its-a-code-smell-5346</link>
      <guid>https://dev.to/medalisraieb/stop-writing-if-role-admin-in-react-its-a-code-smell-5346</guid>
      <description>&lt;p&gt;I'm going to say it:&lt;/p&gt;

&lt;p&gt;👉 &lt;strong&gt;Most React apps handle authorization terribly.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yeah... even the "well-structured" ones.&lt;/p&gt;




&lt;h2&gt;
  
  
  😬 The Problem Nobody Talks About
&lt;/h2&gt;

&lt;p&gt;If your codebase looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight tsx"&gt;&lt;code&gt;&lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;role&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;admin&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;or worse:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight tsx"&gt;&lt;code&gt;&lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;role&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;admin&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt;
  &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;role&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;manager&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;permissions&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;includes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;edit&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="p"&gt;...&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You already have a problem.&lt;/p&gt;

&lt;p&gt;And it's only going to get worse as your app grows.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why?
&lt;/h3&gt;

&lt;p&gt;Because authorization logic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  leaks into every component\&lt;/li&gt;
&lt;li&gt;  gets duplicated everywhere\&lt;/li&gt;
&lt;li&gt;  becomes impossible to reason about\&lt;/li&gt;
&lt;li&gt;  breaks silently when roles evolve&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 It's not just messy --- it's &lt;strong&gt;fragile architecture&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  🧠 The Real Issue
&lt;/h2&gt;

&lt;p&gt;We treat authorization like a UI concern.&lt;/p&gt;

&lt;p&gt;It's not.&lt;/p&gt;

&lt;p&gt;It's &lt;strong&gt;business logic&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And mixing business logic with UI is one of the fastest ways to kill&lt;br&gt;
scalability.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔥 So I Built Something About It
&lt;/h2&gt;

&lt;p&gt;After hitting this wall over and over while building dashboards and SaaS&lt;br&gt;
apps, I decided to fix it.&lt;/p&gt;

&lt;p&gt;I created &lt;strong&gt;react-ability-kit&lt;/strong&gt; --- a type-safe authorization toolkit&lt;br&gt;
for React.&lt;/p&gt;




&lt;h2&gt;
  
  
  ⚡ What Makes It Different?
&lt;/h2&gt;

&lt;p&gt;Instead of scattering role checks across your app, you define abilities&lt;br&gt;
once and reuse them everywhere.&lt;/p&gt;

&lt;h3&gt;
  
  
  ❌ The old way
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight tsx"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;role&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;admin&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;DeleteButton&lt;/span&gt; &lt;span class="p"&gt;/&amp;gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  ✅ The clean way
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight tsx"&gt;&lt;code&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;Can&lt;/span&gt; &lt;span class="na"&gt;I&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s"&gt;"delete"&lt;/span&gt; &lt;span class="na"&gt;a&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s"&gt;"Post"&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;DeleteButton&lt;/span&gt; &lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nc"&gt;Can&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  💡 Why This Matters More Than You Think
&lt;/h2&gt;

&lt;p&gt;When you centralize authorization:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  your UI becomes cleaner\&lt;/li&gt;
&lt;li&gt;  your logic becomes predictable\&lt;/li&gt;
&lt;li&gt;  your app becomes scalable\&lt;/li&gt;
&lt;li&gt;  your team stops breaking permissions accidentally&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And most importantly:&lt;/p&gt;

&lt;p&gt;👉 &lt;strong&gt;You stop rewriting the same logic 50 times.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🚀 Built for Real Apps
&lt;/h2&gt;

&lt;p&gt;This isn't a toy library.&lt;/p&gt;

&lt;p&gt;It's designed for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  SaaS platforms\&lt;/li&gt;
&lt;li&gt;  Admin dashboards\&lt;/li&gt;
&lt;li&gt;  Role-heavy applications\&lt;/li&gt;
&lt;li&gt;  Teams that actually care about maintainability&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  📦 Check It Out
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  NPM: &lt;a href="https://www.npmjs.com/package/react-ability-kit%5C" rel="noopener noreferrer"&gt;https://www.npmjs.com/package/react-ability-kit\&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  Docs &amp;amp; Demo: &lt;a href="https://dalisraieb.github.io/react-ability-kit/" rel="noopener noreferrer"&gt;https://dalisraieb.github.io/react-ability-kit/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  📈 Unexpected Traction
&lt;/h2&gt;

&lt;p&gt;I shared it... and it hit &lt;strong&gt;600+ downloads in 12 hours&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Which confirmed something:&lt;/p&gt;

&lt;p&gt;👉 Developers are tired of reinventing authorization logic.&lt;/p&gt;




&lt;h2&gt;
  
  
  🤝 Let's Be Honest
&lt;/h2&gt;

&lt;p&gt;Most of us didn't design our auth system.&lt;/p&gt;

&lt;p&gt;We just... added conditions until it worked.&lt;/p&gt;

&lt;p&gt;And now we're stuck maintaining it 😅&lt;/p&gt;




&lt;h2&gt;
  
  
  🧠 Final Take
&lt;/h2&gt;

&lt;p&gt;If your authorization logic lives inside your components...&lt;/p&gt;

&lt;p&gt;👉 it's already technical debt.&lt;/p&gt;




&lt;p&gt;If this resonates with you:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  ⭐ Star the repo\&lt;/li&gt;
&lt;li&gt;  💬 Drop feedback\&lt;/li&gt;
&lt;li&gt;  🔧 Contribute ideas&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Let's stop normalizing messy authorization in React.&lt;/p&gt;




&lt;h1&gt;
  
  
  react #typescript #opensource #javascript #webdev #frontend #saas
&lt;/h1&gt;

&lt;h1&gt;
  
  
  devtools #architecture
&lt;/h1&gt;

</description>
      <category>react</category>
      <category>typescript</category>
      <category>opensource</category>
      <category>javascript</category>
    </item>
  </channel>
</rss>
