You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Hyperledger Composer非管理员参与者访问控制配置问题求助

Hyperledger Composer 访问控制问题解决方案

问题诊断

你遇到的错误 AccessException: Participant 'org.pledger.PledgerParticipant#neo' does not have 'READ' access to resource 'org.hyperledger.composer.system.AssetRegistry#org.hyperledger.composer.system.HistorianRecord',核心原因有两个:

  1. 缺少普通参与者访问HistorianRecord资产注册表的权限:当用户尝试查看交易历史时,首先需要获取对应的AssetRegistry实例,当前规则未覆盖这个场景。
  2. 可能存在命名空间不一致问题:错误信息中的参与者是org.pledger.PledgerParticipant,但你的ACL规则中写的是org.example.exampleParticipant,这会导致规则无法匹配实际参与者,需要修正命名空间保持一致。

分步解决方案

1. 添加HistorianRecord注册表访问规则

在permissions.acl中新增规则,授权参与者访问HistorianRecord对应的资产注册表:

rule Participant_CanReadHistorianRegistry {
    description: "Allow participants to access the HistorianRecord asset registry"
    participant(p): "org.example.exampleParticipant" // 替换为你实际的参与者命名空间
    operation: READ
    resource(r): "org.hyperledger.composer.system.AssetRegistry#org.hyperledger.composer.system.HistorianRecord"
    action: ALLOW
}

2. 调整ACL规则顺序(关键)

Hyperledger Composer的ACL规则是从上到下依次匹配,第一个匹配的规则生效。建议将默认拒绝规则放在允许规则之前,逻辑更清晰:

// 先默认拒绝所有参与者访问HistorianRecord
rule Participants_DenyAccessToHistorian {
    description: "participants cannot access general historian records"
    participant: "org.example.exampleParticipant"
    operation: READ
    resource: "org.hyperledger.composer.system.HistorianRecord"
    action: DENY
}

// 再允许参与者查看自己发起的交易记录
rule Participant_CanOnlyReadOwnHistorian {
    description: "each party should be able to read its own transaction records"
    participant(p): "org.example.exampleParticipant"
    operation: READ
    resource(r): "org.hyperledger.composer.system.HistorianRecord"
    condition: (p == r.participantInvoking)
    action: ALLOW
}

3. 优化抽象资产权限规则

你的抽象资产规则会自动应用到子类myAsset(Composer支持ACL继承),可以简化条件判断:

rule Participant_CanAccessOwnAssets {
    description: "owner has full access to their assets"
    participant(p): "org.example.exampleParticipant"
    operation: ALL
    resource(r): "org.example.assets.exampleAsset"
    condition: (p == r.owner) // 直接比较对象,无需调用getIdentifier()
    action: ALLOW
}

4. 完整修正后的ACL文件

整合所有调整后的最终版本:

rule Participant_CanAccessOwnAssets {
    description: "owner has full access to their assets"
    participant(p): "org.example.exampleParticipant"
    operation: ALL
    resource(r): "org.example.assets.exampleAsset"
    condition: (p == r.owner)
    action: ALLOW
}

rule Participant_CanReadHistorianRegistry {
    description: "Allow participants to access the HistorianRecord asset registry"
    participant(p): "org.example.exampleParticipant"
    operation: READ
    resource(r): "org.hyperledger.composer.system.AssetRegistry#org.hyperledger.composer.system.HistorianRecord"
    action: ALLOW
}

rule Participants_DenyAccessToHistorian {
    description: "participants cannot access general historian records"
    participant: "org.example.exampleParticipant"
    operation: READ
    resource: "org.hyperledger.composer.system.HistorianRecord"
    action: DENY
}

rule Participant_CanOnlyReadOwnHistorian {
    description: "each party should be able to read its own transaction records"
    participant(p): "org.example.exampleParticipant"
    operation: READ
    resource(r): "org.hyperledger.composer.system.HistorianRecord"
    condition: (p == r.participantInvoking)
    action: ALLOW
}

rule Participant_CanReadNetwork {
    description: "participants can read (connect to) the business network"
    participant: "org.example.exampleParticipant"
    operation: READ
    resource: "org.hyperledger.composer.system.Network"
    action: ALLOW
}

rule NetworkAdminUser {
    description: "Grant business network administrators full access to user resources"
    participant: "org.hyperledger.composer.system.NetworkAdmin"
    operation: ALL
    resource: "**"
    action: ALLOW
}

rule NetworkAdminSystem {
    description: "Grant business network administrators full access to system resources"
    participant: "org.hyperledger.composer.system.NetworkAdmin"
    operation: ALL
    resource: "org.hyperledger.composer.system.**"
    action: ALLOW
}

验证步骤

  1. 将修正后的ACL文件重新部署到业务网络。
  2. 使用管理员卡片重新生成参与者身份卡片。
  3. 用新卡片登录Composer Playground,验证:
    • 仅能查看自己拥有的资产
    • 仅能查看自己发起的交易历史
    • 无权限访问其他参与者的资产和交易记录

内容的提问来源于stack exchange,提问作者Mahdad Baghani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:23:25