From 441911aedf0ed786071c00f85f43706387bd1d64 Mon Sep 17 00:00:00 2001 From: Dean Amar Date: Fri, 2 Oct 2026 17:48:34 +0300 Subject: [PATCH 1/2] [sampleconfig] Add ACLs for the committer's exposed resources to configtx.yaml #### Type of change - New feature #### Description - Add the committer's Query (`/committerpb.QueryService/*`), Sidecar (`/committerpb.SidecarService/*`) and Deliver (`/protos.Deliver/*`) methods to `Application.ACLs`, each mapped to `/Channel/Application/Readers`. - The keys are gRPC full-method names, which is how the committer's Auth Service looks up each call's policy; the config parser keeps their dots intact. #### Related issues - related to #203 Signed-off-by: Dean Amar --- sampleconfig/configtx.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/sampleconfig/configtx.yaml b/sampleconfig/configtx.yaml index df8f2e913..f0836627c 100644 --- a/sampleconfig/configtx.yaml +++ b/sampleconfig/configtx.yaml @@ -162,6 +162,24 @@ Application: &ApplicationDefaults # Users can override these defaults using the ACLs section in their channel definition peer/Propose: /Channel/Application/Writers + # Fabric-X committer's exposed resources, keyed by gRPC full-method name. The committer's + # auth service authorizes each call against the policy its method maps to here. + /committerpb.QueryService/GetRows: /Channel/Application/Readers + /committerpb.QueryService/BeginView: /Channel/Application/Readers + /committerpb.QueryService/EndView: /Channel/Application/Readers + /committerpb.QueryService/GetNamespacePolicies: /Channel/Application/Readers + /committerpb.QueryService/GetConfigTransaction: /Channel/Application/Readers + /committerpb.QueryService/GetTransactionStatus: /Channel/Application/Readers + /committerpb.SidecarService/GetBlockchainInfo: /Channel/Application/Readers + /committerpb.SidecarService/GetBlockByNumber: /Channel/Application/Readers + /committerpb.SidecarService/GetBlockByTxID: /Channel/Application/Readers + /committerpb.SidecarService/GetTxByID: /Channel/Application/Readers + /committerpb.SidecarService/OpenNotificationStream: /Channel/Application/Readers + /committerpb.SidecarService/StreamBlocks: /Channel/Application/Readers + /protos.Deliver/Deliver: /Channel/Application/Readers + /protos.Deliver/DeliverFiltered: /Channel/Application/Readers + /protos.Deliver/DeliverWithPrivateData: /Channel/Application/Readers + # Organizations lists the orgs participating on the application side of the # network. Organizations: From 8b82f198b849138fd96c7aed7c4821d43374d745 Mon Sep 17 00:00:00 2001 From: Dean Amar Date: Fri, 2 Oct 2026 18:49:30 +0300 Subject: [PATCH 2/2] * reformat the configtx.yaml Signed-off-by: Dean Amar --- sampleconfig/configtx.yaml | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/sampleconfig/configtx.yaml b/sampleconfig/configtx.yaml index f0836627c..f5b8a2fa0 100644 --- a/sampleconfig/configtx.yaml +++ b/sampleconfig/configtx.yaml @@ -164,21 +164,21 @@ Application: &ApplicationDefaults # Fabric-X committer's exposed resources, keyed by gRPC full-method name. The committer's # auth service authorizes each call against the policy its method maps to here. - /committerpb.QueryService/GetRows: /Channel/Application/Readers - /committerpb.QueryService/BeginView: /Channel/Application/Readers - /committerpb.QueryService/EndView: /Channel/Application/Readers - /committerpb.QueryService/GetNamespacePolicies: /Channel/Application/Readers - /committerpb.QueryService/GetConfigTransaction: /Channel/Application/Readers - /committerpb.QueryService/GetTransactionStatus: /Channel/Application/Readers - /committerpb.SidecarService/GetBlockchainInfo: /Channel/Application/Readers - /committerpb.SidecarService/GetBlockByNumber: /Channel/Application/Readers - /committerpb.SidecarService/GetBlockByTxID: /Channel/Application/Readers - /committerpb.SidecarService/GetTxByID: /Channel/Application/Readers + /committerpb.QueryService/GetRows: /Channel/Application/Readers + /committerpb.QueryService/BeginView: /Channel/Application/Readers + /committerpb.QueryService/EndView: /Channel/Application/Readers + /committerpb.QueryService/GetNamespacePolicies: /Channel/Application/Readers + /committerpb.QueryService/GetConfigTransaction: /Channel/Application/Readers + /committerpb.QueryService/GetTransactionStatus: /Channel/Application/Readers + /committerpb.SidecarService/GetBlockchainInfo: /Channel/Application/Readers + /committerpb.SidecarService/GetBlockByNumber: /Channel/Application/Readers + /committerpb.SidecarService/GetBlockByTxID: /Channel/Application/Readers + /committerpb.SidecarService/GetTxByID: /Channel/Application/Readers /committerpb.SidecarService/OpenNotificationStream: /Channel/Application/Readers - /committerpb.SidecarService/StreamBlocks: /Channel/Application/Readers - /protos.Deliver/Deliver: /Channel/Application/Readers - /protos.Deliver/DeliverFiltered: /Channel/Application/Readers - /protos.Deliver/DeliverWithPrivateData: /Channel/Application/Readers + /committerpb.SidecarService/StreamBlocks: /Channel/Application/Readers + /protos.Deliver/Deliver: /Channel/Application/Readers + /protos.Deliver/DeliverFiltered: /Channel/Application/Readers + /protos.Deliver/DeliverWithPrivateData: /Channel/Application/Readers # Organizations lists the orgs participating on the application side of the # network.