如何配置ACL实现参与者全读权限及特定公司Person参与者只读权限
Got it, let's put together the ACL rules you need to meet those two permission requirements, while keeping the existing network admin access intact. Here's the complete, annotated configuration:
Hyperledger Composer ACL Configuration
// Existing network admin full access rules (kept as provided) rule NetworkAdminUser { description: "Grant business network administrators full access to user resources" participant: "org.hyperledger.composer.system.NetworkAdmin" operation: ALL resource: "**" action: ALLOW } rule NetworkAdminSystem { description: "Grant business network administrators full access to system resources" participant: "org.hyperledger.composer.system.NetworkAdmin" operation: ALL resource: "org.hyperledger.composer.system.**" action: ALLOW } // 1. Allow all participants full read access to all resources rule AllParticipantsFullRead { description: "Grant all participants full read access to all resources" participant: "org.yournamespace.**" // Replace with your actual business network namespace operation: READ resource: "**" action: ALLOW } // 2. Grant read-only access to Person participants in BORDER type companies rule BorderCompanyPersonReadOnly { description: "Grant read-only access to Person participants employed by BORDER type companies" participant(p): "org.yournamespace.Person" // Update to your Person participant's full type operation: READ resource: "**" action: ALLOW condition: (p.employer.companyType == "BORDER") // Adjust field names to match your data model }
Key Tweaks for Your Specific Network:
- Namespace Fix: Swap
org.yournamespace.**with the actual namespace used in your business network (where yourPersonandCompanydefinitions are stored). - Condition Adjustment: The rule assumes your
Personparticipant has anemployerfield linking to aCompanyentity (participant or asset) with acompanyTypeenum. If your model uses different field names (likeworkplaceinstead ofemployer), update the condition to match your schema. - Rule Priority: Composer evaluates ACL rules top-to-bottom, so keeping admin rules first ensures they override participant-level permissions (which is exactly what we want for admin access).
内容的提问来源于stack exchange,提问作者Lars
相关产品推荐
相关产品推荐

