Method, system and equipment for dynamically loading web API (Application Program Interface) based on express and medium
Through modular API design, dynamic routing and sandbox isolation technology, the problems of service restart and resource waste caused by API modifications in traditional Express applications are solved, efficient API loading and security isolation are achieved, and the flexibility and maintainability of the system are improved.
Patent Information
- Application Number
- CN202510895720.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-10-14
AI Technical Summary
API modifications in traditional Express applications lead to service restarts, resource waste, security risks, and code maintenance difficulties, which cannot meet modern business needs.
It adopts modular API definition, dynamic route pre-registration, on-demand instantiation and caching, and sandbox environment management to achieve dynamic loading and isolation of APIs, and support hot updates and version control.
It avoids service restart, reduces resource usage, improves response speed, ensures system security and stability, and simplifies the code maintenance process.
Smart Images

Figure CN120780375A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Web technology and relates to a method, system, device and medium for dynamically loading a web API based on Express. Background Art
[0002] In traditional Express applications, the drawbacks of hard-coding routes and API logic are becoming increasingly prominent, severely restricting the flexibility and maintainability of the application.
[0003] From a business continuity perspective, the requirement to restart services whenever adding or modifying an API is incompatible with today's rapidly iterating business environment. In the internet age, business needs are constantly changing, and frequent API adjustments make service restarts commonplace. Each restart represents a service interruption, which can lead to data loss, operational failures, and other negative experiences for users who rely on the service, directly impacting business operations and user satisfaction.
[0004] Complex inter-module dependencies and a lack of a unified management mechanism led to a chaotic code structure. Implicit dependencies between modules made it difficult to accurately assess the impact of changes to one module on other modules, increasing the difficulty and risk of code maintenance. Furthermore, the lack of unified management standards led to inconsistent coding styles, inefficient team collaboration, and difficulty for new members to quickly get started.
[0005] Third-party modules pollute the execution environment through global variables, posing a serious security risk to applications. The use of global variables obscures the scope of code, allowing different modules to accidentally modify the same global variable, leading to difficult-to-troubleshoot errors. Furthermore, the quality of third-party modules varies greatly, and they may contain security vulnerabilities that, if exploited by attackers, pose a serious threat to the entire application.
[0006] The resource waste caused by preloading all APIs is also a significant issue. Loading all APIs into memory at app startup, regardless of whether these APIs are frequently used, consumes valuable system resources. In the face of traffic bursts, this preloading approach fails to dynamically adjust resource allocation based on actual demand, potentially causing some APIs to respond slowly or even crash, impacting the user experience.
[0007] Therefore, this traditional Express application development model urgently needs to be improved to adapt to the needs of modern application development. Existing solutions, some of which separate routes through configuration files, cannot achieve dynamic loading and isolated execution at runtime, and still pose risks of service interruption and security risks. Summary of the Invention
[0008] In response to the problems existing in the prior art, the present invention provides a method, system, device and medium for dynamically loading web APIs based on Express, thereby realizing modular development and dynamic deployment of APIs, avoiding service restarts; on-demand loading reduces resource usage and improves response speed; dependency injection decouples module logic, improves maintainability, and ensures the security of the execution environment through sandbox isolation.
[0009] The present invention is achieved through the following technical solutions: A method for dynamically loading web API based on express, including: Modular API definition: define input parameters, business processing logic, HTTP request method and request path in the API module file; Dynamic route pre-registration: Scan the API module file directory, generate a complete dynamic route path based on the request path and input parameters, and pre-register it with the Express route along with the empty processing function; On-demand instantiation and caching: When a request reaches a pre-registered dynamic route, the API module is dynamically instantiated, the instance is encapsulated in a sandbox environment, associated with the route, and cached; Hot update and version switching: monitor the file change events of the API module, re-instantiate the changed API module, and update the cache; Sandbox environment management: Create an isolated execution environment for each API module and restrict variable access and resource operations.
[0010] Preferably, the modular API definition is as follows: Write API modules according to preset specifications and define the API modules, including: Input parameters, business processing logic, and specify supported HTTP request methods and request paths; The information defined by the API module is exported uniformly through the export function, named, and placed in the API module folder.
[0011] Preferably, the specified supported HTTP request method is selected from at least one of GET, POST, DELETE, and OPTIONS; the input parameter includes the parameter name and type; Preferably, dynamic routing pre-registration is as follows: Scan the API module file directory, extract the API module definition, create a complete routing path based on the request path and input parameters, and create an empty processing function. Then register the complete routing path and empty processing function as dynamic routing in the Express framework according to different request methods.
[0012] Preferably, instantiation and caching are performed on demand, specifically: When a user request reaches a pre-registered route, check whether the dynamic route has been bound to a processing function. If not, dynamically instantiate the business processing logic defined by the corresponding API module; Extract input parameters from the request context, merge them with the preset parameters in the dependency injection container, and inject them into the business logic instance through the bind method; use the Node.js vm module to create an isolated sandbox environment, encapsulate the business processing logic instance in the sandbox environment, and associate the sandbox environment with the route and cache it.
[0013] Preferably, hot update and version switching are as follows: Use the node-watch module to monitor the API module folder. When the file content changes, mark the corresponding sandbox environment in the cache pool as obsolete. Create a new sandbox environment and associate it with the route to ensure that new requests access the latest logic. When there are no active requests to the old sandbox environment, remove the sandbox from the cache pool and release resources.
[0014] Preferably, the sandbox environment management is specifically as follows: Use vm.createContext() to create an isolated context, rewrite the require module import function, perform permission verification, and only allow the API module to import predefined whitelist modules, thereby limiting the access rights of the API module, encapsulating sensitive network and file operations of the API module, and recording behavior logs.
[0015] A system for dynamically loading web API based on express, including: Modular API definition module, used to define input parameters, business processing logic, HTTP request method and request path in the API module file; Dynamic routing pre-registration module, used to scan the API module file directory, generate a complete dynamic routing path based on the request path and input parameters, and pre-register it with the processing empty function to the Express route; On-demand instantiation and caching module, which is used to dynamically instantiate the API module when a request reaches a pre-registered dynamic route, encapsulate the instance in a sandbox environment, associate the route, and cache it; Hot update and version switching module, used to monitor file change events of API modules, re-instantiate the changed API modules, and update the cache; The sandbox environment management module is used to create an isolated execution environment for each API module and restrict variable access and resource operations.
[0016] An electronic device includes a processor and a memory, wherein the memory stores a computer program, and when the processor executes the program, a method for dynamically loading a web API based on Express is implemented.
[0017] A computer-readable storage medium stores computer instructions, which, when executed by a processor, implement a method for dynamically loading a web API based on Express.
[0018] Compared with the prior art, the present invention has the following beneficial technical effects: This invention uses modular API design to independently encapsulate API business logic and route definitions, avoiding the service restart problem caused by API modification in traditional solutions and improving system continuity and availability. This invention adopts dynamic route pre-registration and on-demand instantiation to dynamically create API instances according to user requests and store them in a cache pool, realizing on-demand loading of APIs, effectively reducing system resource usage, improving response speed, and solving the resource waste problem caused by pre-loading all APIs in traditional solutions. The present invention supports hot updates and version control. By monitoring module file change events, it realizes the dynamic update of API logic, solving the problems of cumbersome API release process and difficult version management in traditional solutions. Furthermore, in order to prevent global variable pollution or sensitive information leakage, an isolation mechanism is provided. The present invention performs permission verification through the require function, limits the inter-module access rights of the API module, realizes true module isolation, and ensures the security and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0020] Figure 1 This is a system architecture diagram showing the collaborative relationship between module management, API routing, and sandbox environment; Figure 2 The flowchart for on-demand loading describes the complete process from empty route registration to instance caching; Figure 3 A diagram of the sandbox isolation mechanism, showing the resource access restriction layer. DETAILED DESCRIPTION
[0021] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work under the premise that the embodiments in the present application fall within the scope of protection of the present application.
[0022] Embodiment one The present application relates to a method and system for dynamically loading Web API based on Node.js Express framework, supporting modular development, on-demand loading, hot updating and security isolation, suitable for microservices and cloud native scenarios with high flexibility and high security requirements, such as Figure 1 As shown in the figure Step 1: Modular API definition Developers write API modules according to the specification, define input parameters (name, type) and business processing logic in the API module, and specify supported HTTP request methods (Get, Post, Delete, Options) and request paths. All definitions are exported through the export function, and the module file is named “module name.js” and placed in the API module folder.
[0023]
[0024] Step 2: Dynamic route pre-registration The system scans the API module file directory when starting, extracts the API module definition, and then creates a complete route path through router and inputDefine, such as “ / Service / getOrg / :org” in the example. Then create an empty processing function, and register the complete route path and empty processing function as routes in the Express framework according to different request methods, such as express.get, express.post, etc.
[0025] Step 3: On-demand instantiation and caching As shown in the figure Figure 2As shown, when a user request reaches a pre-registered route, the system checks whether a processing function has been bound to the route. If not, the business processing logic defined by the corresponding API module is dynamically instantiated. The system extracts the input parameters from the request context using the inputDefine definition, merges them with the parameters in the dependency injection container, and finally injects the merged parameters into the business processing logic instance through the bind method. For security and isolation, the system uses the Node.js vm module to create a sandbox environment and encapsulate the business processing logic instance within it. This sandbox environment is then associated with the route and stored in the cache pool. When the user accesses the route again, the system directly obtains the corresponding sandbox environment from the cache pool to process the request.
[0026] The dependency injection container manages dependencies such as database connections and tool classes through the IoC container. The required dependencies are declared in blocks and automatically injected by the container during instantiation. Each API instance runs in an independent sandbox, limiting access to system resources.
[0027] Step 4: Hot update and version switching The system uses the node-watch module to monitor the API module folder. When file content changes, the corresponding sandbox environment in the cache pool is marked as deprecated. A new sandbox environment is created in step 3. The new sandbox environment is associated with the route to ensure that new requests access the latest logic. When the old sandbox environment has no active requests, it is removed from the cache pool and its resources are released.
[0028] Listen for API module file change events and compare file hash values. When performing a differential update, retain the old version of the API instance until the request is completed. When the new version is ready, switch the route binding and clear the old cache. Step 5: Sandbox environment management like Figure 3 As shown, create an isolated context and use vm.createContext() to create a new context object. This context has an independent variable operation domain and execution environment, and is completely isolated from the main process. Rewrite the require module import function. The customized require function will perform permission verification and only allow the API module to import predefined whitelist modules. Any attempt to import other modules will be blocked, thereby limiting the access rights of the API module. The system encapsulates sensitive operations such as network requests and file operations. Network requests and file operations are recorded in the behavior log. Log information includes timestamp, API module name, operation type, parameters, results, etc.
[0029] Example 2: The present invention provides a method for dynamically loading a web API based on express, and the specific implementation steps are as follows: Step 1: Modular API design Step 101: Developers compile API modules according to the specifications. Define input parameters (name, type) and business processing logic within the module. Specify supported HTTP request methods (Get, Post, Delete, Options) and request paths. Export all definitions using the export function. Name the module file "getOrg.js" and place it in the API module folder. Step 102: Introduce a dependency injection container into the API module and define the dependencies required by the module through the configuration file "dependencies.json", including database connection pool, tool classes, etc., to ensure dependency injection between modules through the container. Step 103: Use the custom require function to verify module permissions. Only the API module is allowed to import predefined whitelist modules. Any attempt to import other modules will be blocked. Step 2: Dynamic routing pre-registration Step 201: When the system starts, it scans the API module directory, extracts the API module definition, and then creates a complete routing path through router and inputDefine, such as " / Service / getOrg / :org". Step 202: Create an empty processing function, and register the complete routing path and the empty function as a route in the Express framework according to different request methods, such as express.get, express.post, etc. Step 203: Separate the routing configuration through the configuration file "routes.json" to achieve flexible configuration and dynamic update of routing. Step 3: On-demand instantiation and caching Step 301: When a user request reaches a pre-registered route, the system checks whether the route has been bound to a processing function. If not, the system dynamically instantiates the business processing logic defined by the corresponding API module. Step 302: The system extracts input parameters from the request context through the definition of inputDefine, merges them with the parameters in the dependency injection container, and finally injects the merged parameters into the business processing logic instance through the bind method. Step 303: To ensure security and isolation, the system uses the VM module of Node.js to create a sandbox environment and encapsulates the business processing logic instance in it. Step 304: associate the created sandbox environment with the route and store it in the cache pool. When the user accesses the route again, the system directly obtains the corresponding sandbox environment from the cache pool to process the request. Step 4: Hot Update and Version Control Step 401: The system uses the node-watch module to monitor the API module folder. When the file content changes, the corresponding sandbox environment in the cache pool is first marked as eliminated. Step 402: Create a new sandbox environment through step 3 and associate it with the route to ensure that new requests access the latest logic. Step 403: After there are no active requests in the old sandbox environment, the sandbox is removed from the cache pool and resources are released. Step 5: Sandbox environment management Step 501: Create an isolation context. Use vm.createContext() to create a new context object. The context has an independent variable operation domain and execution environment and is completely isolated from the main process. Step 502: Rewrite the require module import function. The customized require function will perform permission verification and only allow the API module to import predefined whitelist modules. Step 503: Encapsulate sensitive operations such as network requests and file operations and record them in the behavior log. The log information includes timestamp, API module name, operation type, parameters, results, etc.
[0030] Example 3 A system for dynamically loading web API based on express, including: Modular API definition module, used to define input parameters, business processing logic, HTTP request method and request path in the API module file; Dynamic routing pre-registration module, used to scan the API module file directory, generate a complete dynamic routing path based on the request path and input parameters, and pre-register it with the processing empty function to the Express route; On-demand instantiation and caching module, which is used to dynamically instantiate the API module when a request reaches a pre-registered dynamic route, encapsulate the instance in a sandbox environment, associate the route, and cache it; Hot update and version switching module, used to monitor file change events of API modules, re-instantiate the changed API modules, and update the cache; The sandbox environment management module is used to create an isolated execution environment for each API module and restrict variable access and resource operations.
[0031] Example 4 In another embodiment of the present invention, a computer device is provided, comprising a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, and are suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions, thereby implementing the corresponding method flow or corresponding function. The processor executes, and the computer program implements the steps of dynamically loading a webAPI based on express.
[0032] Example 5 The present invention also provides a storage medium, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in a computer device, used to store programs and data. It is understood that the computer-readable storage medium herein may include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for being loaded and executed by a processor. These instructions may be one or more computer programs (including program code). It should be noted that the computer-readable storage medium herein may be high-speed RAM memory or non-volatile memory, such as at least one disk storage device. The processor may load and execute the one or more instructions stored in the computer-readable storage medium to implement the steps of the method for dynamically creating a Vue component using text in the above-mentioned embodiment when the computer program is executed by the processor.
[0033] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0034] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0035] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0036] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0037] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0038] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one skilled in the art to which this invention pertains. The terms used in this specification of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0039] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Any ordinary technician in this industry can smoothly implement the present invention as shown in the drawings and described above. However, any equivalent changes, modifications and evolutions made by technicians familiar with this profession without departing from the scope of the technical solution of the present invention using the technical content disclosed above are all equivalent embodiments of the present invention. At the same time, any equivalent changes, modifications and evolutions made to the above embodiments based on the essential technology of the present invention are still within the scope of protection of the technical solution of the present invention.
Claims
1. A method for dynamically loading a web API based on express, characterized in that: include, Modular API definition: define input parameters, business processing logic, HTTP request method and request path in the API module file; Dynamic route pre-registration: Scan the API module file directory, generate a complete dynamic route path based on the request path and input parameters, and pre-register it with the Express route along with the empty processing function; On-demand instantiation and caching: When a request reaches a pre-registered dynamic route, the API module is dynamically instantiated, the instance is encapsulated in a sandbox environment, associated with the route, and cached; Hot update and version switching: monitor the file change events of the API module, re-instantiate the changed API module, and update the cache; Sandbox environment management: Create an isolated execution environment for each API module and restrict variable access and resource operations.
2. The method for dynamically loading a web API based on express according to claim 1, characterized in that: Modular API definition, specifically: Developers write API modules according to preset specifications and define the API modules, including: Input parameters, business processing logic, and specify supported HTTP request methods and request paths; The information defined by the API module is exported uniformly through the export function, named, and placed in the API module folder.
3. The method for dynamically loading a web API based on express according to claim 2, characterized in that: The specified supported HTTP request method is selected from at least one of GET, POST, DELETE, and OPTIONS; the input parameters include parameter name and type.
4. The method for dynamically loading a web API based on express according to claim 1, characterized in that: Dynamic routing pre-registration, specifically: Scan the API module file directory, extract the API module definition, create a complete routing path based on the request path and input parameters, and create an empty processing function. Then register the complete routing path and empty processing function as dynamic routing in the Express framework according to different request methods.
5. The method for dynamically loading a web API based on express according to claim 1, characterized in that: On-demand instantiation and caching, specifically: When a user request reaches a pre-registered route, check whether the dynamic route has been bound to a processing function. If not, dynamically instantiate the business processing logic defined by the corresponding API module; Extract input parameters from the request context, merge them with the preset parameters in the dependency injection container, and inject them into the business logic instance through the bind method; Use the Node.js vm module to create an isolated sandbox environment, encapsulate the business processing logic instance in the sandbox environment, and associate the sandbox environment with the route and cache it.
6. The method for dynamically loading a web API based on express according to claim 1, characterized in that: Hot update and version switching, specifically: Use the node-watch module to monitor the API module folder. When the file content changes, mark the corresponding sandbox environment in the cache pool as obsolete. Create a new sandbox environment and associate it with the route to ensure that new requests access the latest logic. When there are no active requests to the old sandbox environment, remove the sandbox from the cache pool and release resources.
7. The method for dynamically loading a web API based on express according to claim 1, characterized in that: Sandbox environment management, specifically: Use vm.createContext() to create an isolated context, rewrite the require module import function, perform permission verification, and only allow the API module to import predefined whitelist modules, thereby limiting the access rights of the API module, encapsulating sensitive network and file operations of the API module, and recording behavior logs.
8. A system for dynamically loading web API based on express, characterized in that: include, Modular API definition module, used to define input parameters, business processing logic, HTTP request method and request path in the API module file; Dynamic routing pre-registration module, used to scan the API module file directory, generate a complete dynamic routing path based on the request path and input parameters, and pre-register it with the processing empty function to the Express route; On-demand instantiation and caching module, which is used to dynamically instantiate the API module when a request reaches a pre-registered dynamic route, encapsulate the instance in a sandbox environment, associate the route, and cache it; Hot update and version switching module, used to monitor file change events of API modules, re-instantiate the changed API modules, and update the cache; The sandbox environment management module is used to create an isolated execution environment for each API module and restrict variable access and resource operations.
9. An electronic device comprising a processor and a memory, characterized in that: The memory stores a computer program, and when the processor executes the program, it implements the method for dynamically loading a web API based on Express as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing computer instructions, characterized in that: When the instructions are executed by a processor, the method for dynamically loading a web API based on Express as described in any one of claims 1 to 7 is implemented.