You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Hyperledger Composer中Seller执行OrderFromSupplier遇AccessException排查

问题排查与解决方案

我帮你梳理了当前的Permissions.acl文件,找到了导致Seller无法执行OrderFromSupplier交易的核心问题,同时补全了不完整的规则,具体如下:

核心问题分析

  1. SellerOrderFromSupplier规则的条件逻辑错误
    当前规则中,条件(v.seller.sellerID == m.getIdentifier())的v指向的是泛化的resource(即任意匹配的资源),但没有关联到OrderFromSupplier交易中实际操作的订单。在Hyperledger Composer的ACL规则中,验证交易权限时需要明确绑定交易内的资产与参与者的关系,否则权限校验会失败。

  2. SellerRefund规则不完整
    你提供的文件末尾的SellerRefund规则没有写完,缺少交易的完整定义、条件和action部分,这会导致ACL文件解析错误,间接影响其他规则的正常生效。

修正后的完整Permissions.acl文件

rule NetworkAdminUser {
 description: "Grant business network administrators full access to user resources"
 participant: "org.hyperledger.composer.system.NetworkAdmin"
 operation: ALL
 resource: "**"
 action: ALLOW
}
rule NetworkAdminSystem {
 description: "Grant business network administrators full access to system resources"
 participant: "org.hyperledger.composer.system.NetworkAdmin"
 operation: ALL
 resource: "org.hyperledger.composer.system.**"
 action: ALLOW
}
/**
 * end of V0.14 additions
 */
/**
 * **/
rule BuyerACLCreate {
 description: "Enable Buyers to execute all actions on an Order"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.CreateOrder"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule BuyerACLBuy {
 description: "Enable a Buyer to update an Order from Create to Buy"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.Buy"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule BuyerACLCancel {
 description: "Enable a Buyer to CANCEL an Order"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE, DELETE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.OrderCancel"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule BuyerACLDispute {
 description: "Enable a Buyer to raise a DISPUTE on an Order"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.Dispute"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule BuyerACLResolve {
 description: "Enable a Buyer to RESOLVE a DISPUTEd Order"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.Resolve"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule BuyerACLAuthorizePayment {
 description: "Enable a Buyer to AuthorizePayment for an Order"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.AuthorizePayment"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule BuyerACL {
 description: "Allow Buyer full access to any order where they are listed as Buyer"
 participant(m): "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE, DELETE
 resource(v): "org.acme.Z2BTestNetwork.Order"
 condition: (v.buyer.buyerID == m.getIdentifier())
 action: ALLOW
}
/**
 * */
rule netAccessBuyer {
 description: "Allow Buyers access to the network"
 participant: "org.acme.Z2BTestNetwork.Buyer"
 operation: READ, CREATE, UPDATE, DELETE
 resource: "org.hyperledger.composer.system.**"
 action: ALLOW
}
/**
 * **/
rule SellerOrderFromSupplier {
 description: "Enable a Seller to Submit an Order to a third party for fulfillment"
 participant(m): "org.acme.Z2BTestNetwork.Seller"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.Order"
 transaction(tx): "org.acme.Z2BTestNetwork.OrderFromSupplier"
 // 修改条件:验证交易中关联的订单的sellerID与当前Seller的ID一致
 condition: (tx.order.seller.sellerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule SellerRequestPayment {
 description: "Enable a Seller to request payment for a fulfilled order"
 participant(m): "org.acme.Z2BTestNetwork.Seller"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.RequestPayment"
 condition: (v.seller.sellerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule SellerResolve {
 description: "Enable a Seller to resolve a dispute"
 participant(m): "org.acme.Z2BTestNetwork.Seller"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.Resolve"
 condition: (v.seller.sellerID == m.getIdentifier())
 action: ALLOW
}
/**
 * **/
rule SellerRefund {
 description: "Enable a Seller to refund payment for a disputed order"
 participant(m): "org.acme.Z2BTestNetwork.Seller"
 operation: READ, CREATE, UPDATE
 resource(v): "org.acme.Z2BTestNetwork.**"
 transaction(tx): "org.acme.Z2BTestNetwork.Refund"
 condition: (v.seller.sellerID == m.getIdentifier())
 action: ALLOW
}

关键修改说明

  1. SellerOrderFromSupplier规则调整

    • 将resource范围缩小为org.acme.Z2BTestNetwork.Order,避免权限过度开放
    • 条件改为(tx.order.seller.sellerID == m.getIdentifier()),直接验证OrderFromSupplier交易中携带的订单所属的seller是否为当前操作的Seller,确保权限校验精准匹配交易场景
  2. 补全SellerRefund规则
    补充了交易定义、条件和action部分,确保ACL文件语法完整,避免解析错误导致的规则失效

另外,建议你同步验证OrderFromSupplier交易的模型定义,确保交易中包含order字段(类型为org.acme.Z2BTestNetwork.Order),这样ACL中的tx.order才能正确关联到目标订单。

内容的提问来源于stack exchange,提问作者Seetharaman Narayanan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:31:53