You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Hyperledger Composer中REST服务器身份识别及ACL规则生效问题咨询

How Hyperledger Composer REST Server Identifies Your Identity & Enforces ACL Rules

Great question—this is a common gotcha when getting started with Hyperledger Composer's REST server! Let's break down what's happening and how to fix your permission issue:

Why You're Seeing Unrestricted Access Right Now

By default, the Composer REST server starts without authentication enabled. That means it doesn't check who's making API calls—anyone can send requests to localhost:3000 and invoke any chaincode function, regardless of your ACL rules. This is why your trader participant can call function A even though your .acl file denies that access.

Step 1: Enable Authentication on the REST Server

To make the REST server recognize and enforce your identity-based ACLs, you need to start it in authenticated mode. Here's how:

  • When launching the server via command line, add the -a true flag:
    composer-rest-server -a true
    
  • If you use the interactive startup wizard, select Yes when prompted to "Enable authentication?".

Once enabled, the REST server will redirect all unauthenticated requests to a login page.

Step 2: How Identity Mapping Works with ACLs

When you issued identities to your participants (like trader), each identity is linked to a specific participant in your business network. Here's the flow once authentication is enabled:

  1. You log into the REST server using the identity credentials (username = identity ID, password = the one you set when issuing the identity).
  2. The REST server verifies this identity and maps it to the corresponding participant (e.g., a org.yourdomain.Trader instance).
  3. It then checks your .acl file to enforce permissions: if your rule denies trader access to function A, the API call will be blocked with a permission error.

Step 3: Testing the Restricted Access

Let's validate this with your scenario:

  1. Start the REST server with authentication enabled.
  2. Log in using the trader identity's credentials.
  3. Try calling function A via the API (either through the REST explorer or your HTML form). You should get a 403 Forbidden response—this means the ACL rule is working!
  4. Log out and log back in with an identity that has permission to call function A (like an admin identity), and the call should succeed.

Step 4: Authenticating from Your HTML Form

If you're using a simple HTML file to send POST requests, you'll need to handle the authentication flow:

  1. First, send a POST request to localhost:3000/api/login with the identity's username and password in the request body:
    {
      "username": "trader-id-123",
      "password": "your-trader-password"
    }
    
  2. The server will return a JWT token in the response.
  3. Include this token in the Authorization header of your subsequent POST requests to function A:
    Authorization: Bearer <your-jwt-token>
    

This tells the REST server exactly which identity is making the call, so it can apply the correct ACL rules.

内容的提问来源于stack exchange,提问作者张海华

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:07:03