同一业务网络下两独立组织区分及权限规则配置咨询
Great questions—let's break them down clearly:
1. Can two independent organizations in the same business network be distinguished?
Absolutely! In Hyperledger Composer, every participant (including network admins like NetworkAdmin) is linked to their parent organization via the organization property. You can reliably tell apart users from org1 and org2 by checking the unique identifier of their organization using t.organization.getidentifier() (just like in your sample rule). This built-in association makes distinguishing separate organizations in the same network straightforward.
2. Can I add permission rules to restrict org1 admins to create Mailers and org2 admins to create Processors?
Yes, you can create granular, org-specific permission rules exactly like you're asking for. Building off the example rule you provided, here's how to set up both rules in your ACL (access control list) file:
rule enableOrg1ToCreateMailers { description: "Enable admin from org1 to create Mailers" participant(t): "org.hyperledger.composer.system.NetworkAdmin" operation: CREATE resource: "demonetwork1.Mailer" condition: (t.organization.getidentifier() == "org1") action: ALLOW } rule enableOrg2ToCreateProcessors { description: "Enable admin from org2 to create Processors" participant(t): "org.hyperledger.composer.system.NetworkAdmin" operation: CREATE resource: "demonetwork1.Processor" condition: (t.organization.getidentifier() == "org2") action: ALLOW }
Quick notes on these rules:
- We target
NetworkAdminaccounts (the org-level administrators) - We limit the operation to
CREATE(so admins can't modify or delete these participants unless you add additional rules) - The
resourcefield specifies exactly which participant type each org can create - The
conditionensures only admins from the correct org get permission - Double-check that the organization identifiers (
"org1"and"org2") match exactly what's defined in your business network's connection profile—mismatched IDs will cause the rules to fail.
内容的提问来源于stack exchange,提问作者David Zhou

