You need to enable authentication in REST server.
export COMPOSER_CARD=name of your card that will be used to start the REST server
export COMPOSER_AUTHENTICATION=true
export COMPOSER_PROVIDERS='{
"github":{
},
...
}'
Also you need to switch on REST server Multi-user mode.
export COMPOSER_MULTIUSER=true
export COMPOSER_DATASOURCES='{
"db":{
"name":"db",
"host":"hostname",
"port":port number,
"database":"database name",
"user":"login",
"password":"password",
"connector":"mongodb"
}
}'
and then start the REST server
composer-rest-server
Now the composer REST server will start with the card COMPOSER_CARD with authentication and Multi-user enabled.
If you now visit http://localhost:3000 you will find a new set of APIs "Wallet". Here the wallet functions are defined.
Now the steps for the user will be as follows:
- System Admin creates your participant card and issue identity. He sends you the .card file to you.Or your application must have a process to send your card file as email attachment.
- He/she authenticates himself with Google or some other provider (what is configured in REST server).
- Capture the token returned from that OAuth
- Use that Token and call the REST web service /wallet/import to upload his card to be stored in the MongoDB. While uploading make sure that the Card name you input is exactly same as your card name.
- Now call any other core application Web Services. REST web service will use your uploaded card details to call the web service.
Hence even if you started the REST server with COMPOSER_CARD it is using your actual card to execute Web services.
Hope this clarifies.
Also you can go through the actual document related to this one for better understanding:
https://hyperledger.github.io/composer/latest/tutorials/google_oauth2_rest