# Access control in Cadence contract

**URL:** <https://forum.flow.com/t/access-control-in-cadence-contract/2752>\
**Category:** 🏄🏻‍♀️ Cadence\
**Created:** [January 23, 2022, 7:49pm UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752 "2022-01-23T19:49:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![p1xelch1ck](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/p1xelch1ck/32/638_2.png) [@p1xelch1ck](https://forum.flow.com/u/p1xelch1ck)\
**Post date:** [January 23, 2022, 7:49pm UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752/1 "2022-01-23T19:49:15Z")

</div>

Hi,

I’m following flow tutorials and need help with contract level access controls.

Example: I want to extend ExampleNFT to have a flag that can be set only by the NFT’s owner but read by everyone.

1. I added a pub var flag [isLostOrStolen]
2. Created a setter with access(account) access [setLostOrStolen]

See the code here: [https://testnet.flowscan.org/contract/A.b9af6584a32f2225.BlockchainBackedItem1](https://testnet.flowscan.org/contract/A.b9af6584a32f2225.BlockchainBackedItem1)

When I try to execute:

```auto
import BlockchainBackedItem1 from 0xb9af6584a32f2225

transaction(id: UInt64) {
    prepare(signer: AuthAccount) {
        let collectionRef = signer.getCapability(BlockchainBackedItem1.CollectionPublicPath)
            .borrow<&{BlockchainBackedItem1.BlockchainBackedItemCollectionPublic}>()
            ?? panic("Could not get receiver reference to the NFT Collection")

        let bbi = collectionRef.borrowBlockchainBackedItem(id: id)

        bbi.setLostOrStolen()
    }
}

```

I get

```auto
|
12 | bbi.setLostOrStolen()
   | ^^^^^^^^^^^^^^^ unknown member

```

It looks like I can’t access functions with account(access) using a transaction signed by the account owner.  
Am I doing something wrong?

I could create an Admin resource that has a public function that flips the flag and is stored in the account without creating a public capability, to restrict the access, but it sounds overcomplicated. What is an advised approach to implement a simple flag that is modified by the account owner?

---

<div class="post-metadata">

**Author:** ![j00lz](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/j00lz/32/1940_2.png) [@j00lz](https://forum.flow.com/u/j00lz)\
**Post date:** [January 24, 2022, 5:51am UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752/2 "2022-01-24T05:51:56Z")

</div>

Problem is `access(account) ` can only be accessed by other _contracts_ in the same _account_. (The account itself can’t access via a transaction)

In your case you can just make it `pub` which will make it readable by all and only settable by the current owner of the resource.

---

<div class="post-metadata">

**Author:** ![p1xelch1ck](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/p1xelch1ck/32/638_2.png) [@p1xelch1ck](https://forum.flow.com/u/p1xelch1ck)\
**Post date:** [January 24, 2022, 6:22am UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752/3 "2022-01-24T06:22:49Z")

</div>

Oh geez, 🤦‍♀️ so obvious. Thank you so much!

---

<div class="post-metadata">

**Author:** ![p1xelch1ck](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/p1xelch1ck/32/638_2.png) [@p1xelch1ck](https://forum.flow.com/u/p1xelch1ck)\
**Post date:** [January 31, 2022, 5:28am UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752/4 "2022-01-31T05:28:47Z")

</div>

I tried setting access to variables as pub, but if I try to change it directly using a signed transaction I get:

```auto
error: cannot assign to `isLostOrStolen`: field has public access

^^^^^^^^^ consider making it publicly settable with `pub(set)`

```

I’m guessing that’s because transaction is outside of the scope in which this variable lives.

Making it pub(set) will allow other accounts modify it, which I don’t want.  
I also tried using setters, but

```auto
pub fun setLost() {
    self.isLostOrStolen
}

```

also can be called by anyone.  
Any other suggestions?

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [February 1, 2022, 6:03pm UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752/5 "2022-02-01T18:03:17Z")

</div>

If you want to protect certain functionality from access by everyone and want to only grant access to certain users, have a read through [https://docs.onflow.org/cadence/language/capability-based-access-control/](https://docs.onflow.org/cadence/language/capability-based-access-control/) and [https://docs.onflow.org/cadence/msg-sender/](https://docs.onflow.org/cadence/msg-sender/). In particular, [https://docs.onflow.org/cadence/msg-sender/#admin-rights](https://docs.onflow.org/cadence/msg-sender/#admin-rights) shows how you can allow controlled access to e.g. `setLostOrStolen` in your case.

---

<div class="post-metadata">

**Author:** ![p1xelch1ck](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/p1xelch1ck/32/638_2.png) [@p1xelch1ck](https://forum.flow.com/u/p1xelch1ck)\
**Post date:** [February 5, 2022, 5:51am UTC](https://forum.flow.com/t/access-control-in-cadence-contract/2752/6 "2022-02-05T05:51:02Z")

</div>

Got it. Thanks for pointing me to the right direction @turbolent !
