Hyperledger Fabric中为组织添加多用户及权限控制咨询
为Hyperledger Fabric组织添加多用户并配置权限控制策略
一、生成组织用户身份
根据身份管理方式,分两种操作路径:
1. 使用cryptogen工具(静态生成,适合测试环境)
- 修改
crypto-config.yaml中对应组织的用户数量:在PeerOrgs -> Users -> Count字段设置需要的用户数(比如从1改为3) - 重新生成组织加密材料:
cryptogen generate --config=./crypto-config.yaml - 新生成的用户证书和密钥会自动放到
organizations/peerOrganizations/[org域名]/users目录下,每个用户对应一个[用户名]@[org域名]子目录,包含完整的MSP结构。
2. 使用Fabric CA(动态管理,适合生产环境)
如果test network是CA模式启动的(执行./network.sh up -ca),可通过CA客户端注册生成用户身份:
- 注册新用户(以org1的user2为例):
fabric-ca-client register --caname ca-org1 --id.name user2 --id.secret user2pw --id.type client --url http://localhost:7054 - 生成用户的MSP材料:
fabric-ca-client enroll -u http://user2:user2pw@localhost:7054 --caname ca-org1 -M ./organizations/peerOrganizations/org1.example.com/users/user2@org1.example.com/msp - 复制CA根证书并添加配置文件(参考组织管理员MSP结构):
cp ./organizations/peerOrganizations/org1.example.com/msp/cacerts/* ./organizations/peerOrganizations/org1.example.com/users/user2@org1.example.com/msp/cacerts/ cp ./organizations/peerOrganizations/org1.example.com/msp/config.yaml ./organizations/peerOrganizations/org1.example.com/users/user2@org1.example.com/msp/
二、配置权限控制策略
Fabric权限控制分为通道级和链码级两个维度,按需配置:
1. 通道级权限(控制通道操作权限)
- 修改
configtx.yaml中Application部分的策略定义,比如新增允许org1普通用户读写通道的策略:Application: Policies: Org1UserPolicy: Type: Signature Rule: "OR('Org1MSP.client')" Readers: Type: ImplicitMeta Rule: "ANY Readers" Writers: Type: ImplicitMeta Rule: "ANY Writers" Admins: Type: ImplicitMeta Rule: "MAJORITY Admins" - 更新通道配置:
- 获取当前通道配置块:
peer channel fetch config config_block.pb -o localhost:7050 -c mychannel --tls --cafile $ORDERER_CA - 转换为JSON格式:
configtxlator proto_decode --input config_block.pb --type common.Block | jq .data.data[0].payload.data.config > config.json - 修改
config.json中策略引用(比如将通道Writers策略指向Org1UserPolicy) - 生成配置更新交易:
configtxlator proto_encode --input config.json --type common.Config --output config.pb configtxlator proto_encode --input updated_config.json --type common.Config --output updated_config.pb configtxlator compute_update --channel_id mychannel --original config.pb --updated updated_config.pb --output config_update.pb echo '{"payload":{"header":{"channel_header":{"channel_id":"mychannel", "type":2}},"data":{"config_update":'$(cat config_update.pb | base64)'}}}' | jq . > config_update_in_envelope.json - 签名并提交更新:
peer channel signconfigtx -f config_update_in_envelope.json peer channel update -f config_update_in_envelope.json -c mychannel -o localhost:7050 --tls --cafile $ORDERER_CA
- 获取当前通道配置块:
2. 链码级权限(控制链码调用权限)
方式一:使用ACL规则
- 在链码的
connection.json中定义ACL,比如限制只有org1用户可调用invoke方法:{ "acl": { "mycc:invoke": "OR('Org1MSP.client')", "mycc:query": "OR('Org1MSP.client', 'Org2MSP.client')" } } - 安装链码时指定该配置文件,或通过通道配置更新链码ACL策略。
方式二:链码逻辑内校验身份
直接在链码代码中判断调用者身份,以Go链码为例:
import ( "crypto/x509" "fmt" "github.com/hyperledger/fabric-contract-api-go/contractapi" ) func (s *SmartContract) Invoke(ctx contractapi.TransactionContextInterface) error { creator, err := ctx.GetClientIdentity().GetCreator() if err != nil { return err } cert, err := x509.ParseCertificate(creator) if err != nil { return err } // 校验用户是否为org1指定用户 if cert.Subject.CommonName != "user2@org1.example.com" { return fmt.Errorf("权限不足:仅允许user2调用此方法") } // 执行业务逻辑 return nil }
三、测试权限效果
切换不同用户身份,执行链码调用或通道操作验证权限:
- 切换用户身份:
export CORE_PEER_MSPCONFIGPATH=./organizations/peerOrganizations/org1.example.com/users/user2@org1.example.com/msp export CORE_PEER_ADDRESS=localhost:7051 export CORE_PEER_TLS_ROOTCERT_FILE=./organizations/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt - 执行链码调用测试:
peer chaincode invoke -o localhost:7050 --tls true --cafile $ORDERER_CA -C mychannel -n mycc -c '{"Args":["invoke","a","b","10"]}'
内容的提问来源于stack exchange,提问作者Heba
相关产品推荐
相关产品推荐

