InterviewDB Experience

Account Utility: Implement a User Account Manager with Role-Based Features

Interview Experience

Problem

Implement an AccountManager that handles user accounts with roles (admin, member, guest). Each role has different capabilities. The system must support:

python
class AccountManager:
    def create_account(self, username: str, role: str) -> str:

**returns** account_id
    def deactivate(self, account_id: str) -> bool:
    def change_role(self, requester_id: str, target_id: str, new_role: str) -> bool:
    def get_capabilities(self, account_id: str) -> list[str]:
    def audit_log(self) -> list[dict]:

**returns** all actions taken

Only admin accounts can change roles. Deactivated accounts cannot perform any actions. All state changes are logged.

Example

am = AccountManager()
admin_id = am.create_account("alice", "admin")
member_id = am.create_account("bob", "member")

am.change_role(member_id, admin_id, "guest")  -> False  # bob can't change roles
am.change_role(admin_id, member_id, "admin")  -> True
am.deactivate(member_id)
am.change_role(member_id, admin_id, "guest")  -> False  # deactivated

Follow-ups

  1. How do you prevent privilege escalation bugs when adding new roles?
  2. What test cases would you write to ensure role change authorization is correct?
  3. How would you extend this to support time-limited role grants?

Full Details

Problem

Implement an AccountManager that handles user accounts with roles (admin, member, guest). Each role has different capabilities. The system must support:

python
class AccountManager:
    def create_account(self, username: str, role: str) -> str:

**returns** account_id
    def deactivate(self, account_id: str) -> bool:
    def change_role(self, requester_id: str, target_id: str, new_role: str) -> bool:
    def get_capabilities(self, account_id: str) -> list[str]:
    def audit_log(self) -> list[dict]:

**returns** all actions taken

Only admin accounts can change roles. Deactivated accounts cannot perform any actions. All state changes are logged.

Example

am = AccountManager()
admin_id = am.create_account("alice", "admin")
member_id = am.create_account("bob", "member")

am.change_role(member_id, admin_id, "guest")  -> False  # bob can't change roles
am.change_role(admin_id, member_id, "admin")  -> True
am.deactivate(member_id)
am.change_role(member_id, admin_id, "guest")  -> False  # deactivated

Follow-ups

  1. How do you prevent privilege escalation bugs when adding new roles?
  2. What test cases would you write to ensure role change authorization is correct?
  3. How would you extend this to support time-limited role grants?

About This Question

This is a candidate experience report from a shopify interview.

It covers the following topics: Coding, Pair Programming .