You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Aptos中委托签名者权限?offer_signer_capability使用与权限粒度

Aptos中offer_signer_capability函数的使用与权限说明

权限粒度说明

offer_signer_capability提供的是细粒度权限,并非完整账户权限。它用于委托账户派生的受限签名者能力(signer capability),只能执行创建时明确指定的操作,无法接管整个账户的所有权限。

使用方法

1. 创建受限签名者能力

在委托前,需要先从账户主签名者派生一个受限的signer capability,明确指定允许调用的模块和函数:

// 导入必要模块
use aptos_framework::account;
use aptos_framework::coin;

fun delegate_capability(signer: &signer, recipient: address) {
    // 创建仅允许转账和自定义函数的受限capability
    let restricted_cap = account::create_restricted_signer_capability(
        signer,
        vector[
            (account::module_id(), account::function_name("transfer")),
            (module_id("0x123::your_custom_module"), function_name("authorized_action"))
        ]
    );
    // 后续执行委托操作
}

2. 执行委托操作

调用offer_signer_capability将创建好的受限capability发送给目标账户或合约:

// 承接上面的代码
account::offer_signer_capability(
    signer,
    recipient,
    restricted_cap
);

3. 接收方获取并使用权限

接收方需要调用claim_signer_capability获取权限,之后通过该capability创建受限签名者,执行授权操作:

fun use_delegated_capability(signer: &signer, target_addr: address, amount: u64) {
    let cap = account::claim_signer_capability(signer);
    let restricted_signer = account::create_signer_from_capability(&cap);
    // 执行授权的转账操作
    coin::transfer(&restricted_signer, target_addr, amount);
}

注意事项

  • 权限范围完全由创建受限capability时的函数列表决定,不在列表内的操作无法执行
  • 委托方可通过account::revoke_signer_capability随时撤销已委托的权限
  • 该capability仅能由指定接收方使用,不可二次转让,避免权限失控

内容的提问来源于stack exchange,提问作者mohan A

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 16:29:55