如何让Hyperledger Composer-Rest-Server关联多张用户卡片,实现单端口多用户访问
Got it, let's tackle this problem step by step. You want a single instance of Hyperledger Composer-Rest-Server running on one port to manage 5 user cards, each linked to an independent user. Here's a detailed, actionable solution:
1. 前置准备
First, make sure you have these prerequisites sorted:
- Hyperledger Composer CLI and Composer-Rest-Server installed (keep versions consistent across all components to avoid compatibility headaches)
- All 5 user business network cards imported into the card store on the machine where you'll run the Rest Server. Import cards with this command:
composer card import -f <user-card-filename>.card - An admin-level business network card (this is required to initialize the Rest Server and manage user identity access)
2. 配置多用户身份验证
Composer-Rest Server relies on Passport.js for multi-user support. We'll use a local authentication strategy for testing (swap to OAuth/OIDC for production):
Create a auth-config.json file in your working directory with this content:
{ "authentication": { "secret": "your-strong-unique-secret-key", "strategies": [ { "strategy": "local", "options": { "usernameField": "username", "passwordField": "password" } } ], "session": { "secret": "your-session-secret-key", "cookie": { "maxAge": 86400000 }, "resave": false, "saveUninitialized": false } } }
- Replace the placeholder secrets with secure, unique strings tailored to your environment.
3. 启动支持多用户的Rest Server
Run this command to start the server in multi-user mode, bound to your desired single port:
composer-rest-server -c <admin-card-name> -p 3000 -m true -a ./auth-config.json -n never -w true
Let's break down the key flags:
-c <admin-card-name>: Specifies the admin card to initialize the server and grant base access to the business network-p 3000: Sets the single port for the server (replace with your preferred port number)-m true: Enables multi-user mode — this is the critical flag for supporting multiple user cards-a ./auth-config.json: Links to our authentication configuration file-n never: Disables automatic npm dependency installs (adjust if your setup requires it)-w true: Enables web sockets for real-time updates (optional but useful for live state changes)
4. 关联并管理5个用户卡片
Once the server is running, each user can authenticate to link their card to the server session:
For each user, send a POST request to
http://<server-ip>:3000/auth/localwith this JSON body:{ "username": "<user-card-identity-name>", "password": "<user-card-password>" }- Find the
<user-card-identity-name>by runningcomposer card liston the server machine - The
<user-card-password>is the one set when creating the user's business network card
- Find the
On successful authentication, you'll get a JWT token in the response. Include this token in the
Authorizationheader (formatted asBearer <token>) for all subsequent API requests — this ties the request to the user's specific card identity.To manage user cards (e.g., revoke access), use the admin card to call the
/api/system/identitiesendpoints, which let you view, enable, or disable user identities linked to the business network.
5. 测试与验证
- Use tools like Postman or curl to confirm each user's access:
- Authenticate as User 1, grab their token, then call
GET http://<server-ip>:3000/api/Assets— you should only see assets User 1 has permission to access - Repeat this for all 5 users to verify each is operating under their own card's permissions
- Authenticate as User 1, grab their token, then call
关键注意事项
- ACL Permissions: Ensure your business network definition has correct Access Control Rules (ACLs) assigned to each user identity, otherwise users may get unauthorized errors
- Production Security: Replace the local authentication strategy with a secure provider like Keycloak (OAuth2) instead of plain username/password for production environments
- Card Persistence: If running the Rest Server in a container, mount the card store directory as a volume to persist user cards across restarts
- Version Alignment: Keep Composer CLI, Rest Server, and your business network version matched to avoid unexpected bugs
内容的提问来源于stack exchange,提问作者Yogesh

