开发Web应用需调用Composer Rest Server API,求端点文档
Hey there! Awesome that you're building a web app leveraging the Composer Rest Server—having clear docs for those API endpoints is absolutely critical for building out your multi-user UI flows. Here's what you need to know:
Built-in Swagger UI (Your Go-To Resource)
The easiest way to get detailed, interactive docs for your specific API endpoints is the Swagger Explorer that comes built-in with the Composer Rest Server. Once you start your server (with something like composer-rest-server -c admin@your-network -a true for multi-user auth), just navigate to:
http://<your-server-host>:<port>/explorer
This interface will show you every auto-generated endpoint tied to your business network—including all GET/POST routes for assets, participants, transactions, and identities. For each endpoint, you'll get:
- Exact URL structure and required parameters
- Sample request bodies (perfect for crafting your UI's POST calls)
- Expected response formats
- An option to test requests directly in the browser (great for debugging multi-user auth flows)
Endpoint Naming & Structure Basics
The Rest Server generates endpoints based directly on your business network definition. Here are the common patterns you'll use for multi-user scenarios:
- Fetch participants/assets:
GET /api/<ResourceType>(add query filters like?filter={"where":{"email":"user@example.com"}}to narrow results) - Get a single resource:
GET /api/<ResourceType>/<resourceID> - Submit a transaction:
POST /api/<TransactionType>(you'll need to include the full transaction JSON with the$classproperty matching your transaction definition) - User authentication endpoints: If you enabled Passport auth (with
-a true), you'll get routes likePOST /api/auth/loginto fetch JWT tokens for authenticated requests.
Multi-User Specific Notes
For your multi-user UI, make sure to:
- Enable authentication when starting the server (
-a true) so the Rest Server enforces ACL rules tied to each user's identity. - Include the user's JWT token in the
Authorizationheader of every request (the Swagger Explorer has an "Authorize" button to test this). - Reference your business network's ACL rules to ensure each user can only access the resources they're permitted to interact with—this will dictate which endpoints your UI can call on behalf of each user.
Example Request
Here's a quick example of a POST request to submit a transaction (you'd send this from your UI):
POST /api/TransferFunds Content-Type: application/json Authorization: Bearer <user-jwt-token> { "$class": "org.finance.TransferFunds", "amount": 500, "from": "resource:org.finance.Account#acc-123", "to": "resource:org.finance.Account#acc-456" }
内容的提问来源于stack exchange,提问作者user9040429

