Hyperledger Composer非管理员参与者访问控制配置问题求助
Hyperledger Composer 访问控制问题解决方案
问题诊断
你遇到的错误 AccessException: Participant 'org.pledger.PledgerParticipant#neo' does not have 'READ' access to resource 'org.hyperledger.composer.system.AssetRegistry#org.hyperledger.composer.system.HistorianRecord',核心原因有两个:
- 缺少普通参与者访问HistorianRecord资产注册表的权限:当用户尝试查看交易历史时,首先需要获取对应的AssetRegistry实例,当前规则未覆盖这个场景。
- 可能存在命名空间不一致问题:错误信息中的参与者是
org.pledger.PledgerParticipant,但你的ACL规则中写的是org.example.exampleParticipant,这会导致规则无法匹配实际参与者,需要修正命名空间保持一致。
分步解决方案
1. 添加HistorianRecord注册表访问规则
在permissions.acl中新增规则,授权参与者访问HistorianRecord对应的资产注册表:
rule Participant_CanReadHistorianRegistry { description: "Allow participants to access the HistorianRecord asset registry" participant(p): "org.example.exampleParticipant" // 替换为你实际的参与者命名空间 operation: READ resource(r): "org.hyperledger.composer.system.AssetRegistry#org.hyperledger.composer.system.HistorianRecord" action: ALLOW }
2. 调整ACL规则顺序(关键)
Hyperledger Composer的ACL规则是从上到下依次匹配,第一个匹配的规则生效。建议将默认拒绝规则放在允许规则之前,逻辑更清晰:
// 先默认拒绝所有参与者访问HistorianRecord rule Participants_DenyAccessToHistorian { description: "participants cannot access general historian records" participant: "org.example.exampleParticipant" operation: READ resource: "org.hyperledger.composer.system.HistorianRecord" action: DENY } // 再允许参与者查看自己发起的交易记录 rule Participant_CanOnlyReadOwnHistorian { description: "each party should be able to read its own transaction records" participant(p): "org.example.exampleParticipant" operation: READ resource(r): "org.hyperledger.composer.system.HistorianRecord" condition: (p == r.participantInvoking) action: ALLOW }
3. 优化抽象资产权限规则
你的抽象资产规则会自动应用到子类myAsset(Composer支持ACL继承),可以简化条件判断:
rule Participant_CanAccessOwnAssets { description: "owner has full access to their assets" participant(p): "org.example.exampleParticipant" operation: ALL resource(r): "org.example.assets.exampleAsset" condition: (p == r.owner) // 直接比较对象,无需调用getIdentifier() action: ALLOW }
4. 完整修正后的ACL文件
整合所有调整后的最终版本:
rule Participant_CanAccessOwnAssets { description: "owner has full access to their assets" participant(p): "org.example.exampleParticipant" operation: ALL resource(r): "org.example.assets.exampleAsset" condition: (p == r.owner) action: ALLOW } rule Participant_CanReadHistorianRegistry { description: "Allow participants to access the HistorianRecord asset registry" participant(p): "org.example.exampleParticipant" operation: READ resource(r): "org.hyperledger.composer.system.AssetRegistry#org.hyperledger.composer.system.HistorianRecord" action: ALLOW } rule Participants_DenyAccessToHistorian { description: "participants cannot access general historian records" participant: "org.example.exampleParticipant" operation: READ resource: "org.hyperledger.composer.system.HistorianRecord" action: DENY } rule Participant_CanOnlyReadOwnHistorian { description: "each party should be able to read its own transaction records" participant(p): "org.example.exampleParticipant" operation: READ resource(r): "org.hyperledger.composer.system.HistorianRecord" condition: (p == r.participantInvoking) action: ALLOW } rule Participant_CanReadNetwork { description: "participants can read (connect to) the business network" participant: "org.example.exampleParticipant" operation: READ resource: "org.hyperledger.composer.system.Network" action: ALLOW } rule NetworkAdminUser { description: "Grant business network administrators full access to user resources" participant: "org.hyperledger.composer.system.NetworkAdmin" operation: ALL resource: "**" action: ALLOW } rule NetworkAdminSystem { description: "Grant business network administrators full access to system resources" participant: "org.hyperledger.composer.system.NetworkAdmin" operation: ALL resource: "org.hyperledger.composer.system.**" action: ALLOW }
验证步骤
- 将修正后的ACL文件重新部署到业务网络。
- 使用管理员卡片重新生成参与者身份卡片。
- 用新卡片登录Composer Playground,验证:
- 仅能查看自己拥有的资产
- 仅能查看自己发起的交易历史
- 无权限访问其他参与者的资产和交易记录
内容的提问来源于stack exchange,提问作者Mahdad Baghani
相关产品推荐
相关产品推荐

