Hyperledger Composer中REST服务器身份识别及ACL规则生效问题咨询
Great question—this is a common gotcha when getting started with Hyperledger Composer's REST server! Let's break down what's happening and how to fix your permission issue:
Why You're Seeing Unrestricted Access Right Now
By default, the Composer REST server starts without authentication enabled. That means it doesn't check who's making API calls—anyone can send requests to localhost:3000 and invoke any chaincode function, regardless of your ACL rules. This is why your trader participant can call function A even though your .acl file denies that access.
Step 1: Enable Authentication on the REST Server
To make the REST server recognize and enforce your identity-based ACLs, you need to start it in authenticated mode. Here's how:
- When launching the server via command line, add the
-a trueflag:composer-rest-server -a true - If you use the interactive startup wizard, select
Yeswhen prompted to "Enable authentication?".
Once enabled, the REST server will redirect all unauthenticated requests to a login page.
Step 2: How Identity Mapping Works with ACLs
When you issued identities to your participants (like trader), each identity is linked to a specific participant in your business network. Here's the flow once authentication is enabled:
- You log into the REST server using the identity credentials (username = identity ID, password = the one you set when issuing the identity).
- The REST server verifies this identity and maps it to the corresponding participant (e.g., a
org.yourdomain.Traderinstance). - It then checks your
.aclfile to enforce permissions: if your rule deniestraderaccess to function A, the API call will be blocked with a permission error.
Step 3: Testing the Restricted Access
Let's validate this with your scenario:
- Start the REST server with authentication enabled.
- Log in using the
traderidentity's credentials. - Try calling function A via the API (either through the REST explorer or your HTML form). You should get a
403 Forbiddenresponse—this means the ACL rule is working! - Log out and log back in with an identity that has permission to call function A (like an admin identity), and the call should succeed.
Step 4: Authenticating from Your HTML Form
If you're using a simple HTML file to send POST requests, you'll need to handle the authentication flow:
- First, send a POST request to
localhost:3000/api/loginwith the identity's username and password in the request body:{ "username": "trader-id-123", "password": "your-trader-password" } - The server will return a JWT token in the response.
- Include this token in the
Authorizationheader of your subsequent POST requests to function A:Authorization: Bearer <your-jwt-token>
This tells the REST server exactly which identity is making the call, so it can apply the correct ACL rules.
内容的提问来源于stack exchange,提问作者张海华

