You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

开启多用户认证后,如何在Composer-Rest-Server Explorer中颁发新身份?

解决Composer-Rest-Server Explorer颁发新身份时的授权失败问题

从你提供的日志能直接定位到问题:当前使用的身份jdoe没有被Fabric CA标记为registrar(注册员),所以没有权限执行注册新身份的操作,才会在调用POST /api/system/identities/issue时返回Authorization failure错误。

下面给你两种实用的解决方案:

方案一:用CA管理员身份执行操作

Fabric CA默认的管理员账号(比如admin)自带registrar权限,用它来操作最直接:

  • 切换到CA管理员身份登录Composer-Rest-Server Explorer;
  • 重新调用POST /api/system/identities/issue接口,确保请求体包含userId、roles等必要参数,此时应该能顺利完成身份颁发。

方案二:给现有身份jdoe配置registrar权限

如果想继续用jdoe身份操作,可以通过Fabric CA命令行工具给它添加注册权限:

  1. 执行以下命令,授予jdoe注册client类型身份的权限:
    fabric-ca-client identity add jdoe --attrs 'hf.Registrar.Roles=client' --id.type client
    
    要是需要jdoe能注册更多类型的身份(比如peer、orderer),可以把hf.Registrar.Roles设为*。
  2. 重启Composer-Rest-Server,让权限配置生效;
  3. 用jdoe身份重新调用颁发接口,授权错误应该就会消失。

另外要提醒下,调用POST /api/system/identities/issue时,请求体的参数格式要正确,至少得指定userId,可选的userSecret、roles等参数也要按需填写。

内容的提问来源于stack exchange,提问作者Gerard Duch

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:05:46