You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需Passport启用Hyperledger Composer REST Server多用户模式可行吗?

Can I enable multi-user mode for Hyperledger Composer REST Server without using Passport?

Absolutely! You don’t have to rely on Passport to enable multi-user mode for your Hyperledger Composer REST Server. Since you’ve already covered permission requirements with ACL rules, using the built-in identity-based authentication tied to Hyperledger Fabric is a perfect fit—it keeps things simple while still enforcing multi-user isolation.

Here’s how to set it up step by step:

Prerequisites

First, make sure you’ve:

  • Defined Participant types in your business network model.
  • Issued unique Fabric identities for each participant using the composer identity issue command. Each identity will have an enrollment ID and secret that the user will use to authenticate.

Start the REST Server with Multi-User Mode (No Passport)

Use this command to launch the server with multi-user support and built-in authentication:

composer-rest-server -c admin@your-business-network-name -n never -w true --multiuser --authentication true

Let’s break down the key parameters:

  • -c admin@your-business-network-name: Points to your admin connection profile (replace with your actual business network name).
  • -n never: Disables automatic business network updates (optional, but recommended for stability).
  • -w true: Enables WebSocket support for real-time updates (optional).
  • --multiuser: Enables multi-user mode, so each user’s requests are tied to their own participant identity.
  • --authentication true: Turns on built-in authentication that uses Hyperledger Fabric’s identity system, no Passport required.

How Authentication Works

Once the server is running:

  1. Users authenticate via the /auth/login endpoint by sending their enrollment ID and secret in a POST request:
    {
      "enrollmentId": "user1-enroll-id",
      "enrollmentSecret": "user1-secret"
    }
    
  2. The server returns a JSON Web Token (JWT). Users include this token in the Authorization header of subsequent API requests (format: Bearer <your-jwt-token>).
  3. The REST Server automatically maps the authenticated user to their corresponding Participant in the business network, and your ACL rules will apply as expected.

Key Notes

  • This approach leverages Hyperledger Fabric’s native identity management, so you don’t need to set up any Passport strategies (like OAuth, Google, etc.).
  • Ensure each participant has a unique, valid Fabric identity—this is critical for the ACL rules to enforce proper permissions.
  • If you prefer basic authentication instead of JWT, you can also send the enrollment ID and secret as a Basic Auth header directly in API requests (though JWT is more secure for ongoing sessions).

内容的提问来源于stack exchange,提问作者Zytro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:13:47