You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Hyperledger Composer-Rest-Server关联多张用户卡片,实现单端口多用户访问

Got it, let's tackle this problem step by step. You want a single instance of Hyperledger Composer-Rest-Server running on one port to manage 5 user cards, each linked to an independent user. Here's a detailed, actionable solution:

解决方案:单端口Hyperledger Composer-Rest-Server管理多用户卡片

1. 前置准备

First, make sure you have these prerequisites sorted:

  • Hyperledger Composer CLI and Composer-Rest-Server installed (keep versions consistent across all components to avoid compatibility headaches)
  • All 5 user business network cards imported into the card store on the machine where you'll run the Rest Server. Import cards with this command:
    composer card import -f <user-card-filename>.card
    
  • An admin-level business network card (this is required to initialize the Rest Server and manage user identity access)

2. 配置多用户身份验证

Composer-Rest Server relies on Passport.js for multi-user support. We'll use a local authentication strategy for testing (swap to OAuth/OIDC for production):

Create a auth-config.json file in your working directory with this content:

{
  "authentication": {
    "secret": "your-strong-unique-secret-key",
    "strategies": [
      {
        "strategy": "local",
        "options": {
          "usernameField": "username",
          "passwordField": "password"
        }
      }
    ],
    "session": {
      "secret": "your-session-secret-key",
      "cookie": {
        "maxAge": 86400000
      },
      "resave": false,
      "saveUninitialized": false
    }
  }
}
  • Replace the placeholder secrets with secure, unique strings tailored to your environment.

3. 启动支持多用户的Rest Server

Run this command to start the server in multi-user mode, bound to your desired single port:

composer-rest-server -c <admin-card-name> -p 3000 -m true -a ./auth-config.json -n never -w true

Let's break down the key flags:

  • -c <admin-card-name>: Specifies the admin card to initialize the server and grant base access to the business network
  • -p 3000: Sets the single port for the server (replace with your preferred port number)
  • -m true: Enables multi-user mode — this is the critical flag for supporting multiple user cards
  • -a ./auth-config.json: Links to our authentication configuration file
  • -n never: Disables automatic npm dependency installs (adjust if your setup requires it)
  • -w true: Enables web sockets for real-time updates (optional but useful for live state changes)

4. 关联并管理5个用户卡片

Once the server is running, each user can authenticate to link their card to the server session:

  1. For each user, send a POST request to http://<server-ip>:3000/auth/local with this JSON body:

    {
      "username": "<user-card-identity-name>",
      "password": "<user-card-password>"
    }
    
    • Find the <user-card-identity-name> by running composer card list on the server machine
    • The <user-card-password> is the one set when creating the user's business network card
  2. On successful authentication, you'll get a JWT token in the response. Include this token in the Authorization header (formatted as Bearer <token>) for all subsequent API requests — this ties the request to the user's specific card identity.

  3. To manage user cards (e.g., revoke access), use the admin card to call the /api/system/identities endpoints, which let you view, enable, or disable user identities linked to the business network.

5. 测试与验证

  • Use tools like Postman or curl to confirm each user's access:
    • Authenticate as User 1, grab their token, then call GET http://<server-ip>:3000/api/Assets — you should only see assets User 1 has permission to access
    • Repeat this for all 5 users to verify each is operating under their own card's permissions

关键注意事项

  • ACL Permissions: Ensure your business network definition has correct Access Control Rules (ACLs) assigned to each user identity, otherwise users may get unauthorized errors
  • Production Security: Replace the local authentication strategy with a secure provider like Keycloak (OAuth2) instead of plain username/password for production environments
  • Card Persistence: If running the Rest Server in a container, mount the card store directory as a volume to persist user cards across restarts
  • Version Alignment: Keep Composer CLI, Rest Server, and your business network version matched to avoid unexpected bugs

内容的提问来源于stack exchange,提问作者Yogesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:54:09