You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Apigee OAuth2实现Hyperledger Composer REST API多用户模式的配置问询

Using Apigee OAuth2 with Hyperledger Composer REST API (Multi-User Mode)

Great question! Let's walk through exactly how to set this up, including the correct Passport.js module and COMPOSER_PROVIDERS configuration.

1. Required Passport.js Module

You'll need the passport-oauth2 module. Apigee implements the standard OAuth2 protocol, so this generic OAuth2 strategy works perfectly for integrating with Apigee's authentication endpoints. Install it first with:

npm install passport-oauth2 --save

2. Configuring the COMPOSER_PROVIDERS Environment Variable

Here's a complete, tailored COMPOSER_PROVIDERS object for Apigee. I'll break down each key so you can adjust it to your Apigee setup:

COMPOSER_PROVIDERS='{
  "apigee": {
    "name": "Apigee OAuth2",
    "protocol": "oauth2",
    "module": "passport-oauth2",
    "authPath": "/auth/apigee",
    "callbackURL": "/auth/apigee/callback",
    "successRedirect": "/",
    "failureRedirect": "/",
    "auth": {
      "authorizeURL": "https://<YOUR_APIGEE_ORG>-<YOUR_ENV>.apigee.net/oauth/authorize",
      "tokenURL": "https://<YOUR_APIGEE_ORG>-<YOUR_ENV>.apigee.net/oauth/token"
    },
    "clientID": "<YOUR_APIGEE_CLIENT_ID>",
    "clientSecret": "<YOUR_APIGEE_CLIENT_SECRET>",
    "profile": {
      "profileURL": "https://<YOUR_APIGEE_ORG>-<YOUR_ENV>.apigee.net/userinfo",
      "strategy": "oauth2",
      "function": "function(profile, done) {
        process.nextTick(function () {
          profile.id = profile.username; // Adjust based on Apigee's userinfo response
          done(null, profile);
        });
      }"
    }
  }
}'

Key Configuration Details:

  • name: A friendly name for your authentication provider (can be anything you want).
  • authPath: The endpoint where users will start the OAuth2 flow (e.g., your REST API's /auth/apigee).
  • callbackURL: Must match the callback URL you configured for your Apigee app—this is where Apigee sends the authorization code after user login.
  • authorizeURL: Replace <YOUR_APIGEE_ORG> and <YOUR_ENV> with your Apigee organization and environment (e.g., myorg-test.apigee.net). This is Apigee's OAuth2 authorization endpoint.
  • tokenURL: Apigee's endpoint for exchanging the authorization code for an access token.
  • clientID / clientSecret: These are the credentials for the app you created in Apigee (find them in your Apigee app dashboard).
  • profileURL: Apigee's endpoint that returns user profile information (you may need to create a custom API proxy in Apigee to expose user details if it's not already available).
  • profile.function: A custom function to parse the user profile response from Apigee. Adjust profile.id = profile.username based on the actual structure of Apigee's userinfo response (e.g., if the user ID is in profile.user_id, use that instead).

3. Additional Setup Steps

  • Make sure you start the Composer REST API with the --multiuser flag to enable multi-user mode:
    composer-rest-server -c <YOUR_BUSINESS_NETWORK_CARD> -n never -w true --multiuser
    
  • Verify that your Apigee app has the correct scopes enabled (if required) and that the callback URL matches exactly what's in COMPOSER_PROVIDERS (including HTTP/HTTPS and port if applicable).
  • Ensure your Apigee OAuth2 flow is configured to issue access tokens that include the necessary user identifiers (like username or user ID) that your business network expects.

内容的提问来源于stack exchange,提问作者Krupakar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:12:39