Hyperledger Composer中Seller执行OrderFromSupplier遇AccessException排查
问题排查与解决方案
我帮你梳理了当前的Permissions.acl文件,找到了导致Seller无法执行OrderFromSupplier交易的核心问题,同时补全了不完整的规则,具体如下:
核心问题分析
SellerOrderFromSupplier规则的条件逻辑错误
当前规则中,条件(v.seller.sellerID == m.getIdentifier())的v指向的是泛化的resource(即任意匹配的资源),但没有关联到OrderFromSupplier交易中实际操作的订单。在Hyperledger Composer的ACL规则中,验证交易权限时需要明确绑定交易内的资产与参与者的关系,否则权限校验会失败。SellerRefund规则不完整
你提供的文件末尾的SellerRefund规则没有写完,缺少交易的完整定义、条件和action部分,这会导致ACL文件解析错误,间接影响其他规则的正常生效。
修正后的完整Permissions.acl文件
rule NetworkAdminUser { description: "Grant business network administrators full access to user resources" participant: "org.hyperledger.composer.system.NetworkAdmin" operation: ALL resource: "**" action: ALLOW } rule NetworkAdminSystem { description: "Grant business network administrators full access to system resources" participant: "org.hyperledger.composer.system.NetworkAdmin" operation: ALL resource: "org.hyperledger.composer.system.**" action: ALLOW } /** * end of V0.14 additions */ /** * **/ rule BuyerACLCreate { description: "Enable Buyers to execute all actions on an Order" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.CreateOrder" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * **/ rule BuyerACLBuy { description: "Enable a Buyer to update an Order from Create to Buy" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.Buy" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * **/ rule BuyerACLCancel { description: "Enable a Buyer to CANCEL an Order" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE, DELETE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.OrderCancel" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * **/ rule BuyerACLDispute { description: "Enable a Buyer to raise a DISPUTE on an Order" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.Dispute" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * **/ rule BuyerACLResolve { description: "Enable a Buyer to RESOLVE a DISPUTEd Order" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.Resolve" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * **/ rule BuyerACLAuthorizePayment { description: "Enable a Buyer to AuthorizePayment for an Order" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.AuthorizePayment" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * **/ rule BuyerACL { description: "Allow Buyer full access to any order where they are listed as Buyer" participant(m): "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE, DELETE resource(v): "org.acme.Z2BTestNetwork.Order" condition: (v.buyer.buyerID == m.getIdentifier()) action: ALLOW } /** * */ rule netAccessBuyer { description: "Allow Buyers access to the network" participant: "org.acme.Z2BTestNetwork.Buyer" operation: READ, CREATE, UPDATE, DELETE resource: "org.hyperledger.composer.system.**" action: ALLOW } /** * **/ rule SellerOrderFromSupplier { description: "Enable a Seller to Submit an Order to a third party for fulfillment" participant(m): "org.acme.Z2BTestNetwork.Seller" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.Order" transaction(tx): "org.acme.Z2BTestNetwork.OrderFromSupplier" // 修改条件:验证交易中关联的订单的sellerID与当前Seller的ID一致 condition: (tx.order.seller.sellerID == m.getIdentifier()) action: ALLOW } /** * **/ rule SellerRequestPayment { description: "Enable a Seller to request payment for a fulfilled order" participant(m): "org.acme.Z2BTestNetwork.Seller" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.RequestPayment" condition: (v.seller.sellerID == m.getIdentifier()) action: ALLOW } /** * **/ rule SellerResolve { description: "Enable a Seller to resolve a dispute" participant(m): "org.acme.Z2BTestNetwork.Seller" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.Resolve" condition: (v.seller.sellerID == m.getIdentifier()) action: ALLOW } /** * **/ rule SellerRefund { description: "Enable a Seller to refund payment for a disputed order" participant(m): "org.acme.Z2BTestNetwork.Seller" operation: READ, CREATE, UPDATE resource(v): "org.acme.Z2BTestNetwork.**" transaction(tx): "org.acme.Z2BTestNetwork.Refund" condition: (v.seller.sellerID == m.getIdentifier()) action: ALLOW }
关键修改说明
SellerOrderFromSupplier规则调整- 将resource范围缩小为
org.acme.Z2BTestNetwork.Order,避免权限过度开放 - 条件改为
(tx.order.seller.sellerID == m.getIdentifier()),直接验证OrderFromSupplier交易中携带的订单所属的seller是否为当前操作的Seller,确保权限校验精准匹配交易场景
- 将resource范围缩小为
补全
SellerRefund规则
补充了交易定义、条件和action部分,确保ACL文件语法完整,避免解析错误导致的规则失效
另外,建议你同步验证OrderFromSupplier交易的模型定义,确保交易中包含order字段(类型为org.acme.Z2BTestNetwork.Order),这样ACL中的tx.order才能正确关联到目标订单。
内容的提问来源于stack exchange,提问作者Seetharaman Narayanan
相关产品推荐
相关产品推荐

