Store identifier acquisition method and device for application program installation package, equipment and medium
By automatically obtaining the app store identifier through the generation of authorization requests and identifier query requests, the problem of low efficiency in passing in the store identifier in existing technologies is solved, and an efficient and secure installation package upload process is achieved.
Patent Information
- Application Number
- CN202510835665.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-11-11
AI Technical Summary
In existing technologies, the method of passing in the store identifier when uploading the application installation package to the app store is inefficient and prone to errors. This is especially complex and cumbersome when there are multiple App Store Connect accounts, and there is also a risk of leakage.
By obtaining the developer account and application key to generate an authorization request, obtaining temporary authorization information, extracting application identification information and generating an identification query request, automatically obtaining the store identification, and using two-factor authentication to improve security and efficiency.
It automates the acquisition of store identifiers, improves the efficiency of uploading installation packages, avoids manual input errors, and enhances security through two-factor authentication, reducing the risk of unauthorized access.
Smart Images

Figure CN120930116A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and more particularly to a method, apparatus, device, and medium for obtaining the store identifier of an application installation package. Background Technology
[0002] Currently, when developers need to publish their applications on the App Store, they must upload the application's installation package to the App Store for review and publication. When uploading the installation package to the App Store, a store identifier (Store ID) needs to be passed in. The store identifier usually needs to be manually entered by the developer, or it can be read and passed in through the App Store Connect API.
[0003] However, manually passing in the store identifier is inefficient and prone to upload errors. Passing in the store identifier via the App Store Connect API, especially with multiple App Store Connect accounts, requires configuring each account and storing its key, making the process complex and cumbersome. Summary of the Invention
[0004] This application provides a method, apparatus, device, and medium for obtaining the store identifier of an application installation package. This application can automatically obtain the store identifier corresponding to the application installation package, solving the technical problem of low upload efficiency in the process of uploading the application installation package to the app store in the prior art.
[0005] In a first aspect, this application provides a method for obtaining the store identifier of an application installation package, the method comprising: Obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and the application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier; Extract the application identifier information from the target installation package, and generate an identifier query request based on the temporary authorization information and the application identifier information; Send the identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package together with the target installation package to the application store corresponding to the target development platform.
[0006] The step of sending an authorization request generated based on the developer account and the application key to the target development platform includes: Construct a unique identifier based on the timestamp; Based on the developer account, the application key, and the identification information, the authorization request is generated and sent to the target development platform.
[0007] The temporary authorization information includes identity information and a shared key. The step of generating an identifier query request based on the temporary authorization information and the application identifier information includes: Based on the identity information and shared key in the temporary authorization information, a verification digest is generated; Generate a valid session token based on the identity information; An identifier query request is generated based on the valid session token, the verification digest information, and the application identifier information.
[0008] The step of generating verification digest information based on the identity information and shared key in the temporary authorization information includes: The identity information and the shared key are concatenated according to a preset rule, and a separator is added between them to obtain the first string; Embed the current timestamp into the first string to obtain the second string; Perform multiple hash calculations on the second string to obtain the verification digest information.
[0009] The step of generating an identifier query request based on the valid session token, the verification digest information, and the application identifier information includes: Determine the interface information corresponding to the identifier query interface, wherein the identifier query interface is a preset interface used to query the store identifier corresponding to the specified application identifier information; Generate an initial request body, construct a JSON object in the initial request body, and add the interface information and the application identification information to the JSON object to obtain the session request body; A session request header is generated based on the valid session token and the verification digest information; An identifier query request is generated based on the session request header and the session request body.
[0010] The temporary authorization information includes authorization validity period information, which is configured to represent the validity period of the temporary authorization information. The step of generating an identifier query request based on the temporary authorization information and the application identifier information includes: Based on the current time and the authorization validity period information, determine whether the temporary authorization information is valid; If the temporary authorization information is valid, an identifier query request is generated based on the temporary authorization information and the application identifier information.
[0011] This also includes: Once the target store identifier is obtained, a preset script is used to verify whether the target installation package can be uploaded to the app store corresponding to the target development platform. If the target installation package can be uploaded to the app store, the target store identifier and the target installation package are uploaded to the app store together.
[0012] Secondly, this application provides a device for obtaining the store identifier of an application installation package, the device comprising: The authorization request sending module is configured to obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and the application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier; The query request generation module is configured to extract application identification information from the target installation package and generate an identification query request based on the temporary authorization information and the application identification information. The query request sending module is configured to send the identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package together with the target installation package to the application store corresponding to the target development platform.
[0013] Thirdly, this application provides a device for obtaining the store identifier of an application installation package, the device for obtaining the store identifier of an application installation package including a processor and a memory; The memory is configured to store computer programs and transfer the computer programs to the processor; The processor is configured to execute, according to instructions in the computer program, the method for obtaining the store identifier of the application installation package as described in the first aspect.
[0014] Fourthly, this application provides a storage medium for storing computer-executable instructions, which, when executed by a computer processor, are configured to perform the store identifier acquisition method for an application installation package as described in the first aspect.
[0015] As described above, this application provides a method, apparatus, device, and medium for obtaining the store identifier of an application installation package. This application first sends an authorization request generated based on the developer account and application key to the target development platform. After obtaining temporary authorization information, it further generates an identifier query request based on the temporary authorization information and application identifier information and sends it to the target development platform to obtain the target store identifier corresponding to the application identifier information. This application's method of querying the store identifier based on application identifier information can automate the acquisition of the store identifier, improving the efficiency of uploading the installation package to the app store. It also effectively avoids errors in the store identifier caused by traditional manual entry methods, solving the technical problem of low upload efficiency in the process of uploading application installation packages to the app store in the prior art. Furthermore, this application's method of generating temporary authorization information through two-factor authentication of the developer account and application key effectively prevents unauthorized access. Because it uses the application key, only a small portion of the App Store Connect functionality can be used, making it more secure than using an account password and the App Store Connect API. Attached Figure Description
[0016] Figure 1 This is a flowchart illustrating a method for obtaining the store identifier of an application installation package, as provided in an embodiment of the present invention.
[0017] Figure 2 This is a timing diagram for obtaining the store identifier of a target installation package, provided as an embodiment of the present invention.
[0018] Figure 3 This is a flowchart illustrating another method for obtaining the store identifier of an application installation package provided in an embodiment of the present invention.
[0019] Figure 4 This is a schematic diagram of a device for obtaining the store identifier of an application installation package, provided in an embodiment of the present invention.
[0020] Figure 5 This is a schematic diagram of a device for obtaining the store identifier of an application installation package, provided as an embodiment of the invention. Detailed Implementation
[0021] The following description and accompanying drawings fully illustrate specific embodiments of this application to enable those skilled in the art to practice them. The embodiments represent only possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of embodiments of this application includes the entire scope of the claims and all available equivalents of the claims. In this document, each embodiment may be referred to individually or collectively by the term "invention," which is merely for convenience and is not intended to automatically limit the scope of the application to any single invention or inventive concept if more than one invention is disclosed. Relational terms such as "first" and "second" are used herein only to distinguish one entity or operation from another, without requiring or implying any actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed. The various embodiments in this document are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the structures, products, etc., disclosed in the embodiments, since they correspond to the disclosed parts, the descriptions are relatively simple; relevant details can be found in the method section.
[0022] Currently, when developers need to publish their applications on the App Store, they must upload the application's installation package (IPA file) to the App Store for review and publication. When uploading the installation package to the App Store, a series of parameters need to be passed in, such as the app's Apple ID (hereinafter referred to as the store identifier). The store identifier cannot be directly read from the application's installation package and must be manually entered by the developer, or read and passed in through the App Store Connect API.
[0023] However, manually submitting the store identifier requires developers to obtain the store identifier themselves and upload it along with the installation package to the App Store, which is inefficient and prone to errors when there are many installation packages to be uploaded. Submitting the store identifier via the App Store Connect API, on the other hand, requires developers to configure each App Store Connect account and store a key for each account if they have multiple App Store Connect accounts. This is complex and cumbersome, and there is also a risk of key leakage.
[0024] Based on this, in order to solve the above-mentioned technical problems, embodiments of the present invention provide a method for obtaining the store identifier of an application installation package, such as... Figure 1 As shown, Figure 1 This is a flowchart illustrating a method for obtaining the store identifier of an application installation package according to an embodiment of the present invention. The method for obtaining the store identifier of an application installation package provided in this embodiment can be executed by a store identifier acquisition device (hereinafter referred to as the store identifier acquisition device). This device can be implemented through software and / or hardware, and can consist of two or more physical entities, or a single physical entity. For example, the store identifier acquisition device can be a computer, a host computer, a tablet, or other devices. The method for obtaining the store identifier of an application installation package includes the following steps: Step 101: Obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier.
[0025] In this embodiment, the store identifier acquisition device first needs to obtain the developer account and the application key of the target installation package to be uploaded. The developer account is the account the developer uses to log in to the app store, and the application key is a key file that provides authentication and authorization credentials for a specific service, such as a key file for connecting to Apple services (e.g., in-app purchases, App Store Connect API), containing a private key in .p8 format. The developer account can be pre-stored locally on the store identifier acquisition device, which directly obtains the developer account locally. Additionally, each application corresponds to an installation package, and the application key of the target installation package needs to be obtained by the developer in advance from the target development platform corresponding to the target installation package. For example, the developer can log in to App Store Connect, go to "Users & Access" → "Keys" → "App Store Connect API," click "Generate API Key," enter the key name, and select the relevant permissions (permissions apply to all apps). After the key is generated, the developer needs to immediately download the .p8 format private key file to obtain the application key. After obtaining and storing the application key, the developer can also encrypt the application key and store it locally on the store identifier acquisition device. The store identifier acquisition device can then obtain and crack the encrypted application key.
[0026] After obtaining the developer account and application key, the store identification acquisition device generates an authorization request based on the developer account and application key, such as an iTunes Connect authorization request. This authorization request is used for authentication and permission acquisition on the target development platform. For example, the target development platform generates a token using the developer account and application key in the authorization request to verify the legitimacy of the requester and prevent unauthorized access. Furthermore, the functional permissions bound in the authorization request (such as application management, data access, etc.) determine the operational scope of the store identification acquisition device. In one embodiment, step 101, sending the authorization request generated based on the developer account and application key to the target development platform, includes: Step 1011: Construct a unique identifier based on the timestamp.
[0027] Specifically, when constructing an authorization request, a unique identifier must first be built based on the timestamp. This identifier serves as the unique identifier for the authorization request. The timestamp can be a UNIX timestamp (accurate to milliseconds or microseconds) to ensure the base time value has sufficient granularity. When generating the identifier, the timestamp can be concatenated with the developer account or its unique identifier (such as Team ID or Issuer ID, obtainable from the target development platform) to avoid conflicts between different accounts. Then, a randomly generated string is appended between the two to further enhance uniqueness. Finally, the combined information is output in a fixed format (e.g., TeamID_timestamp_random string) to obtain the unique identifier.
[0028] Step 1012: Based on the developer account, application key, and identification information, generate an authorization request and send the authorization request to the target development platform.
[0029] After generating the identification information, an authorization request can be generated based on the developer account, application key, and identification information. For example, the device acquiring the store identification can send a JSON-RPC format authorization request to the iTunes Connect authentication interface via HTTPS, using the developer account and application key for session authentication, and declaring the client tools and supported JSON data formats in the request header. The request body contains the authentication method and unique identification information. In one embodiment, a code example for constructing an iTunes Connect authorization request is as follows: Request URL: https: / / contentdelivery.itunes.apple.com / WebObjects / MZLabelService.woa / json / MZITunesProducerService (The API endpoint used by iTunes Connect to handle JSON-RPC requests) Request headers: {'User-Agent': 'iTMSTransporter / 2.0.0', 'Accept-Encoding': 'gzip,deflate', 'Accept': '* / *', 'Connection': 'keep-alive', 'Content-Type': 'application / json', 'Content-Length': '161'} Request Body: b'{"jsonrpc": "2.0", "method": "authenticateForSession", "id": "20250417123638-291", "params": {"Username": "XXXXXX", "Password": "***"}}' Session authentication is implemented using the MZITunesProducerService endpoint, which is dedicated to handling communication between developer tools (such as iTMSTransporter) and Apple services. The User-Agent identifies the client type and must strictly match the Apple tool's identifier to avoid interception. In the request body, Username is the developer account, Password is the application key, and id is a unique identifier constructed based on a timestamp, used to prevent duplicate requests and for log tracking.
[0030] In another embodiment, the store identifier acquisition device can also construct an authorization request based on the OAuth 2.0 client credential method to obtain temporary authorization information. Specifically, the store identifier acquisition device generates an API key in its Apple developer account, obtains the Issuer ID (client_id) and a .p8 private key file (client_secret), and records the associated Key ID. Then, it uses the .p8 private key to generate a JWT token, containing claims such as Issuer ID, Key ID, and validity period, and specifies the scope as appstoreconnect-v1. Finally, it sends a POST request to the Apple authentication server, submitting the JWT token as client credentials in exchange for an access_token (Bearer type) valid for one hour.
[0031] The above describes the specific process of a store identifier acquisition device constructing an authorization request. After generating the authorization request, the store identifier acquisition device needs to send it to the target development platform. The target development platform verifies the legitimacy of the developer account based on the authorization request and then returns response data containing temporary authorization information. This temporary authorization information includes a temporary token, which can replace plaintext passwords in subsequent requests, improving security. In one embodiment, an example of the response body code returned by the target development platform based on the authorization request is as follows: Body Response: {"id":"20250417123638-291","jsonrpc":"2.0","result":{"SharedSecret":"00d55332-aa1e-4849-ae36-30faac1ecfb3","MultipartUploadsEnabled":true ,"SessionExpiration":"2025-04-21T04:36:39.139Z","SessionId":"CIiuDBIQWQKNGf24RAeZzlglVH3rwg==","ShouldUseRESTAPIs":false,"Success":true}} The `id` field (20250417123638-291) is a unique identifier matching the original authorization request and is used to track transactions. The `SessionId` (CIiuDBIQWQKNGf24RAeZzlglVH3rwg==) is a temporary token that must be included in subsequent request headers to maintain authentication status. `SharedSecret` can be used for two-factor authentication or data encryption for sensitive operations.
[0032] Step 102: Extract the application identification information from the target installation package, and generate an identification query request based on the temporary authorization information and the application identification information.
[0033] After obtaining the temporary authorization information, it is necessary to further extract the application identification information from the target installation package. This application identification information is used to uniquely identify the application. For example, the application identification information can be the application's Bundle ID. The Bundle ID is a unique identifier for iOS / macOS applications on Apple's platform, typically in a reverse domain name structure (e.g., com.company.appname). This ensures the application's uniqueness within the App Store, developer accounts, and devices. The Bundle ID is deeply bound to the developer certificate and provisioning profile; all three must match for application signing and installation to be completed. The Bundle ID can be obtained from the Info.plist file of the IPA package. The specific acquisition process can be found in existing technologies and will not be elaborated upon in this embodiment.
[0034] After obtaining the application identifier information, the store identifier acquisition device needs to further generate an identifier query request based on the temporary authorization information and the application identifier information. This identifier query request is used to query information corresponding to the application identifier information of the target installation package, including the corresponding target store identifier. For example, the store identifier acquisition device can use Python's requests library to generate the identifier query request. The identifier query request is an HTTPS request, and its header includes temporary authorization information and standard HTTP fields, declaring the use of the JSON-RPC 2.0 protocol. The request body includes the application identifier information and the called store identifier query interface to query the target store identifier corresponding to the application identifier information.
[0035] In one embodiment, the temporary authorization information includes authorization validity period information, which is configured to characterize the validity period of the temporary authorization information. An identifier query request is generated based on the temporary authorization information and application identifier information, including: Based on the current time and the authorization validity period, determine whether the temporary authorization information is valid.
[0036] If the temporary authorization information is valid, an identifier query request is generated based on the temporary authorization information and the application identifier information.
[0037] Specifically, the temporary authorization information includes the authorization validity period information SessionExpiration. SessionExpiration is configured to represent the validity period of the temporary authorization information, such as SessionExpiration (2025-04-21T04:36:39.139Z) in the code above. If the temporary authorization information expires, re-authorization is required. In one embodiment, the temporary authorization information can be re-obtained via an iTunes Connect authorization request before each query request to obtain the store ID through iTunes Connect, or the temporary authorization information can be stored after it is obtained, and re-authorization is not required until the temporary authorization information expires. In this embodiment, before generating the identifier query request, the store identifier acquisition device will determine whether the temporary authorization information has expired based on the current time and the authorization validity period information to determine whether the temporary authorization information is valid. If the temporary authorization information is valid, the store identifier acquisition device can generate an identifier query request based on the temporary authorization information and the application identifier information. If the temporary authorization information expires, the store identifier information needs to resend the authorization request to update the temporary authorization information.
[0038] Based on the above embodiments, the temporary authorization information includes identity information and a shared key, corresponding to the response parameters "SessionId" and "SharedSecret" returned by the target development platform based on the iTunes Connect authorization request. Step 102 generates an identifier query request based on the temporary authorization information and application identifier information, including: Step 1021: Generate verification digest information based on the identity information and shared key in the temporary authorization information.
[0039] When constructing an identifier query request, the first step is to generate a verification digest, "x-session-digest," based on the identity identifier information and shared key from the temporary authorization information. The verification digest "x-session-digest" is a combination of the identity identifier "SessionId" and the shared key "SharedSecret." The MD5 value generated using fixed rules is used for parameter verification on the target development platform. For example, when generating the verification digest, the identity information and shared key can be concatenated according to preset rules, with a separator added between them, to obtain the first string. For instance, concatenating them in the order of "SessionId" + "SharedSecret" requires ensuring the parameter order is fixed to avoid verification failure due to differences in concatenation order. Then, the current timestamp is embedded into the first string to obtain the second string. For example, inserting the UTC timestamp between "SessionId" and "SharedSecret" results in the second string "SessionId" + "timestamp" + "SharedSecret". Finally, the second string is hashed multiple times to obtain the verification digest. For example, after performing an MD5 hash on the second string, the first hash result is concatenated with a fixed salt value (such as #Alt2025) and hashed again to generate the verification digest "x-session-digest". The salt value must be consistent with the server-side value to prevent rainbow table attacks.
[0040] Step 1022: Generate a valid session token based on the identity information.
[0041] While generating the verification digest information, a valid session token needs to be generated based on the identity information. Specifically, the store identification acquisition device can directly use the identity information "SessionId" as the valid session token "x-session-id".
[0042] Step 1023: Generate an identifier query request based on the valid session token, verification digest information, and application identifier information.
[0043] Finally, the store identifier acquisition device can generate an identifier query request based on the valid session token, verification digest information, and application identifier information. Specifically, the store identifier acquisition device can construct a request header, including x-session-id (valid session token) and x-session-digest (verification digest information), for authentication. Then, it assembles the request body, which encapsulates parameters in JSON-RPC 2.0 format, including the name of the store identifier query interface and the application identifier information BundleId. Finally, it assembles the request header and request body to generate the identifier query request.
[0044] Based on the above embodiments, step 1023 generates an identifier query request based on the valid session token, verification digest information, and application identifier information, including: Step 10231: Determine the interface information corresponding to the identifier query interface. The identifier query interface is a preset interface used to query the store identifier corresponding to the specified application identifier information.
[0045] In this embodiment, it is first necessary to determine the interface information corresponding to the identifier query interface. The identifier query interface is a preset interface used to query the store identifier corresponding to the specified application identifier information. For example, it is determined that lookupSoftwareForBundleId is used as the identifier query interface. This interface is used to query the application information of a specified BundleId. The interface information includes the name information of the identifier query interface, etc.
[0046] Step 10232: Generate the initial request body. Construct a JSON object in the initial request body and add the interface information and application identification information to the JSON object to obtain the session request body.
[0047] Next, an initial request body needs to be generated, and a JSON object needs to be constructed within the initial request body. The JSON object is then populated with request parameters. The request parameters include interface information identifying the query interface (lookupSoftwareForBundleId), a unique ID (used to match the response), and the params parameter. The params parameter needs to include application identification information, such as the query BundleId (e.g., "com.global.piggy.ios") and optional Version information (e.g., ".. ()"), used to specify a specific version; this can be omitted if a specific version is not needed. After populating the parameters, the session request body is obtained.
[0048] Step 10233: Generate a session request header based on a valid session token and verification digest information.
[0049] When generating the session request body, it is necessary to generate session request headers based on a valid session token and verification digest information. For example, standard HTTP request headers should be set, such as User-Agent (client identifier, e.g., "iTMSTransporter / .."), Accept-Encoding (supported compression formats, e.g., "gzip, deflate"), Accept (accepted content type, usually " / "), Connection (connection type, e.g., "keep-alive"), and Content-Type (request body content type, e.g., "application / json"). Session-related request headers should also be added, including x-session-id and x-session-digest, as well as x-session-version (session version, usually a fixed value).
[0050] Step 10234: Generate an identifier query request based on the session request header and session request body.
[0051] Finally, the request URL, session request headers, and session request body are combined into a complete HTTP request to obtain the identifier query request. For example, the following is a sample of constructing a query request for iTunes Connect: Request URL: https: / / contentdelivery.itunes.apple.com / WebObjects / MZLabelService.woa / json / MZITunesSoftwareService Request headers: {'User-Agent': 'iTMSTransporter / 2.0.0', 'Accept-Encoding': 'gzip,deflate', 'Accept': '* / *', 'Connection': 'keep-alive', 'Content-Type': 'application / json', 'x-request-id': '20250417123639-418', 'x-session-digest': '790c689308bbe295fb6cadd49d6b4d74', 'x-session-id': 'CIiuDBIQWQKNGf24RAeZzlglVH3rwg==', 'x-session-version': '2', 'Content-Length': '235'} Request Body: b'{"jsonrpc": "2.0", "method": "lookupSoftwareForBundleId", "id": "20250417123639-418", "params": {"Application": "altool", "ApplicationBundleId": "com.apple.itunes.altool", "BundleId": "com.global.piggy.ios", "Version": "4.0.1 (1182)"}}'.
[0052] In another embodiment, the store identifier acquisition device can also construct an iTunes Connect query request based on the OAuth 2.0 client credentials method. Specifically, the store identifier acquisition device obtains the application identifier information BundleId by decompiling or parsing metadata. Then, it assembles the authorization request, setting Authorization: Bearer in the request header.<access_token> The query parameters are bound to BundleId, thereby generating an identifier query request.
[0053] The above describes the specific process of constructing an identifier query request.
[0054] Step 103: Send an identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package to the application store corresponding to the target development platform.
[0055] Finally, the store identifier acquisition device can send an identifier query request to the target development platform. Upon receiving the identifier query request, the target development platform extracts the application identifier information, valid session token, and verification digest information from the request, and verifies the valid session token and verification digest information. If the verification is successful, it performs an exact match query in the database using the application identifier information field to obtain the target store identifier (target store ID) corresponding to the application identifier information, and then returns the target store identifier to the store identifier acquisition device. For example, as shown... Figure 2 As shown, Figure 2 This is a timing diagram for obtaining the store identifier of a target installation package, provided as an embodiment of the present invention.
[0056] In one embodiment, the response body of the response data returned by the target development platform is as follows: Body Response: {"id":"20250417123639-418","jsonrpc":"2.0","result":{"ProviderPublicId":"69a6de95-cff5-47e3-e053-5b8c7c11a4d1", "Applications":{"AAAAAAA(iOS App)":"6505052381"}, "SessionExpiration":"2025-04-21T04:36:40.537Z", "Attributes":[{"Apple ID":"6505052381","AppleID":"6505052381", "WWDRIdentifier":"3RSS4SJQ44", "ExistingBundleIdentifier":"com.global.piggy.ios", "SKU Number":"com.global.piggy.ios", Type:"iOS App", "Primary Language":"zh-Hant","ReservedBundleIdentifier":"com.global.piggy.ios", "DidOptInToMacAppStore":"true","DidOptInToXROSAppStore":"true","SoftwareTypeEnum":"Purple","Application":" AAAAAAA","MarketingVersion":"1.0"}],"Success":true,"ProviderName":"3RSS4SJQ44","ShouldUseRESTAPIs":false}}.
[0057] The "Apple ID": "6505052381" is the target store identifier to be retrieved. "jsonrpc": "2.0" indicates that the response follows the JSON-RPC 2.0 protocol specification. ProviderPublicId: A unique identifier for the developer account (UUID format). Applications: A list of applications, in key-value pair format: application name(type): store ID. In the example, the store ID for application AAAAAAAA is 65050523815. SessionExpiration: Session expiration time (ISO 8601 format). ExistingBundleIdentifier: The application's Bundle ID (com.global.piggy.ios). Type: Application type (iOS App), MarketingVersion: Current market version number (1.0), SoftwareTypeEnum: Apple's internal category identifier ("Purple" may represent a specific application category).
[0058] Additionally, it should be noted that when generating an identifier query request, the target development platform will automatically load the permission list of all associated App Store Connect sub-accounts under the developer account corresponding to the temporary authorization information, and intelligently match the corresponding sub-account store identifier based on the application identifier information (such as BundleID), thereby achieving permission inheritance and isolation of multiple sub-accounts under the main account.
[0059] After obtaining the target store identifier, the device that obtained the store identifier can then upload the target installation package and the target store identifier together to the app store for publication.
[0060] The above-described embodiments of the present invention provide a method for obtaining the store identifier of an application installation package. This application first sends an authorization request generated based on the developer account and application key to the target development platform. After obtaining temporary authorization information, it further generates an identifier query request based on the temporary authorization information and application identifier information and sends it to the target development platform to obtain the target store identifier corresponding to the application identifier information. This method of querying the store identifier based on application identifier information enables automated acquisition of the store identifier, improving the efficiency of uploading the installation package to the app store. It also effectively avoids errors in the store identifier caused by traditional manual input methods, solving the technical problem of low upload efficiency in the process of uploading application installation packages to the app store in the prior art. Furthermore, the method of generating temporary authorization information through two-factor authentication of the developer account and application key effectively prevents unauthorized access. Because the application key is used, only a small portion of the App Store Connect functionality can be used, making it more secure than using an account password and the App Store Connect API.
[0061] This invention also provides another method for obtaining the store identifier of an application installation package, such as... Figure 3 As shown, Figure 3 This is a flowchart illustrating another method for obtaining the store identifier of an application installation package according to an embodiment of the present invention. Figure 3 The method for obtaining the store identifier of the application installation package shown is a concretization of the method for obtaining the store identifier of the application installation package described above, and specifically includes the following steps: Step 201: Obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier; Step 202: Extract application identification information from the target installation package, and generate an identification query request based on the temporary authorization information and the application identification information; Step 203: Send an identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package to the application store corresponding to the target development platform.
[0062] Step 204: After obtaining the target store identifier, verify whether the target installation package can be uploaded to the app store corresponding to the target development platform using a preset script.
[0063] Specifically, the process of obtaining the App Store ID, verifying the device, and uploading the IPA package can use pre-defined scripts, such as Apple's tools iTMSTransporter and altool. The App Store ID verification process first verifies whether the target installation package can be uploaded to the App Store; if the verification is successful, the upload proceeds. Specifically, during verification, the App Store ID verification process requires the user to enter their developer account, application key, and the storage address of the target installation package into the pre-defined script. Below is an example command for verifying whether an IPA package can be uploaded to the App Store (requires a macOS system with Xcode installed): xcrun altool --validate-app -f {IPA package path} --type ios -u {username} -p{password} --output-format json.
[0064] The command above requires the parameters indicated in square brackets. The account and password must be the same as those used in "Building an iTunes Connect Authorization Request," i.e., the developer account and application key. The IPA package path is the address of the target IPA package to be uploaded to the App Store. The default script performs identity and permission verification in the App Store based on the developer account and application key, retrieves the target installation package from the storage address, and verifies whether the target installation package meets the upload requirements of the App Store corresponding to the target development platform.
[0065] Step 205: If the target installation package can be uploaded to the app store, upload the target store identifier and the target installation package to the app store together.
[0066] If the identity and permissions verification is successful and the target installation package meets the upload conditions, the device that obtains the store identifier can input the target store identifier into the preset script. This allows the preset script to log in to the app store based on the developer account and application key, and then upload the target installation package and the target store identifier to the app store.
[0067] The following is a command example for uploading an IPA file to an app store: `xcrun altool --upload-package "{IPA package path}" --type ios --team-id{team_id} --apple-id {target store ID} --bundle-version "{bundle_version}" --bundle-short-version-string "{bundle_short_version}" --bundle-id "{bundle_id}" -u {username} -p {password} --show-progress --output-format json` The parameters such as team_id, bundle_version, bundle_short_version, and bundle_id can be obtained by parsing the decompressed file after uncompressing the IPA package.
[0068] As described above, the present invention's embodiment, based on querying store identifiers using application identifier information, can automate the acquisition of store identifiers, thereby improving the efficiency of uploading installation packages to app stores. It also effectively avoids errors in store identifiers caused by traditional manual entry methods, solving the technical problem of low upload efficiency in the existing technology for uploading application installation packages to app stores. Furthermore, by automatically verifying the compatibility of the installation package with the store identifier through a preset script, common problems such as signature conflicts and version incompatibility can be intercepted in advance, reducing manual review costs. Additionally, the actual upload operation is triggered only after verification, saving bandwidth and storage resources consumed by invalid transmissions.
[0069] This invention also provides a device for obtaining the store identifier of an application installation package, such as... Figure 4 As shown, Figure 4 This is a schematic diagram of a device for obtaining the store identifier of an application installation package according to an embodiment of the present invention. The device includes: The authorization request sending module 301 is configured to obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and the application key to the target development platform to obtain the temporary authorization information of the developer account authenticated by the temporary identifier; The query request generation module 302 is configured to extract application identification information from the target installation package and generate an identification query request based on temporary authorization information and application identification information. The query request sending module 303 is configured to send an identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package together with the target installation package to the application store corresponding to the target development platform.
[0070] The authorization request sending module 301 includes: The identification information construction submodule is configured to construct unique identification information based on timestamps. The authorization request sending submodule is configured to generate an authorization request based on the developer account, application key, and identification information, and send the authorization request to the target development platform.
[0071] The temporary authorization information includes identity information and a shared key, and the query request generation module 302 includes: The verification digest generation submodule is configured to generate verification digest information based on the identity information and shared key in the temporary authorization information; The session token generation submodule is configured to generate valid session tokens based on identity information. The query request generation submodule is configured to generate an identifier query request based on a valid session token, verification digest information, and application identifier information.
[0072] The verification digest generation submodule includes: The first string generation unit is configured to concatenate the identity information and the shared key according to a preset rule, and add a separator between the two to obtain the first string; The second string generation unit is configured to embed the current timestamp into the first string to obtain the second string; The verification digest information generation unit is configured to perform multiple hash calculations on the second string to obtain the verification digest information.
[0073] The query request generation submodule includes: The interface determination unit is configured to determine the interface information corresponding to the identifier query interface, which is a preset interface used to query the store identifier corresponding to the specified application identifier information. The request body generation unit is configured to generate an initial request body. A JSON object is constructed in the initial request body, and interface information and application identification information are added to the JSON object to obtain the session request body. The request header generation unit is configured to generate session request headers based on a valid session token and verification digest information. The request generation unit is configured to generate an identifier query request based on the session request header and session request body.
[0074] The temporary authorization information includes authorization validity period information, which is configured to represent the validity period of the temporary authorization information. The query request generation module 302 is specifically configured to determine whether the temporary authorization information is valid based on the current time and the authorization validity period information; if the temporary authorization information is valid, an identifier query request is generated based on the temporary authorization information and the application identifier information.
[0075] This also includes: The upload verification module is configured to verify, upon obtaining the target store identifier, whether the target installation package can be uploaded to the app store corresponding to the target development platform using a preset script. The installation package upload module is configured to upload the target store identifier and the target installation package together to the app store if the target installation package can be uploaded to the app store.
[0076] The application installation package store identifier acquisition device provided in this embodiment of the invention is included in the application installation package store identifier acquisition device and can be used to execute the application installation package store identifier acquisition method provided in the above embodiment, and has corresponding functions and beneficial effects.
[0077] It is worth noting that in the embodiments of the above-mentioned application installation package store identifier acquisition device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.
[0078] This invention also provides a device for obtaining the store identifier of an application installation package, such as... Figure 5 As shown, Figure 5 This is a schematic diagram of the structure of a device for obtaining the store identifier of an application installation package, provided for an embodiment of the invention. The device 40 for obtaining the store identifier of an application installation package includes a processor 400 and a memory 401. Memory 401 is used to store computer program 402 and transfer computer program 402 to processor 400; The processor 400 is configured to execute the steps in the above embodiment of the method for obtaining the store identifier of an application installation package according to the instructions in the computer program 402.
[0079] For example, computer program 402 may be divided into one or more modules / units, one or more of which are stored in memory 401 and executed by processor 400 to complete this application. One or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of computer program 402 in application installation package store identifier acquisition device 40.
[0080] The application installation package store identifier acquisition device 40 can be a computing device such as a desktop computer, laptop, PDA, or cloud server. The application installation package store identifier acquisition device 40 may include, but is not limited to, a processor 400 and a memory 401. Those skilled in the art will understand that... Figure 5 This is merely an example of the application installer's store identifier acquisition device 40 and does not constitute a limitation on the application installer's store identifier acquisition device 40. It may include more or fewer components than illustrated, or combine certain components, or different components. For example, the application installer's store identifier acquisition device 40 may also include input / output devices, network access devices, buses, etc.
[0081] The processor 400 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0082] The memory 401 can be an internal storage unit of the application installation package store identification acquisition device 40, such as a hard disk or memory of the application installation package store identification acquisition device 40. The memory 401 can also be an external storage device of the application installation package store identification acquisition device 40, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the application installation package store identification acquisition device 40. Furthermore, the memory 401 can include both internal and external storage units of the application installation package store identification acquisition device 40. The memory 401 is used to store computer programs and other programs and data required by the application installation package store identification acquisition device 40. The memory 401 can also be used to temporarily store data that has been output or will be output.
[0083] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0084] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
[0085] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0086] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0087] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing computer programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0088] This invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform a method for obtaining the store identifier of an application installation package. The method includes the following steps: Obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier; Extract application identification information from the target installation package, and generate an identification query request based on temporary authorization information and application identification information; Send an identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package to the application store corresponding to the target development platform.
[0089] Note that the above are merely preferred embodiments and the technical principles applied in this invention. Those skilled in the art will understand that the embodiments of this invention are not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the protection scope of this invention. Therefore, although the embodiments of this invention have been described in detail above, the embodiments of this invention are not limited to the above embodiments. More other equivalent embodiments may be included without departing from the concept of the embodiments of this invention, and the scope of the embodiments of this invention is determined by the scope of the appended claims.
Claims
1. A method for obtaining the store identifier of an application installation package, characterized in that, The method includes: Obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and the application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier; Extract the application identifier information from the target installation package, and generate an identifier query request based on the temporary authorization information and the application identifier information; Send the identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package together with the target installation package to the application store corresponding to the target development platform.
2. The method for obtaining the store identifier of an application installation package according to claim 1, characterized in that, Sending an authorization request generated based on the developer account and the application key to the target development platform includes: Construct a unique identifier based on the timestamp; Based on the developer account, the application key, and the identification information, an authorization request is generated and sent to the target development platform.
3. The method for obtaining the store identifier of an application installation package according to claim 1, characterized in that, The temporary authorization information includes identity information and a shared key. Generating an identifier query request based on the temporary authorization information and the application identifier information includes: Based on the identity information and shared key in the temporary authorization information, a verification digest is generated; Generate a valid session token based on the identity information; An identifier query request is generated based on the valid session token, the verification digest information, and the application identifier information.
4. The method for obtaining the store identifier of an application installation package according to claim 3, characterized in that, The step of generating verification digest information based on the identity information and shared key in the temporary authorization information includes: The identity information and the shared key are concatenated according to a preset rule, and a separator is added between them to obtain the first string; Embed the current timestamp into the first string to obtain the second string; Perform multiple hash calculations on the second string to obtain the verification digest information.
5. The method for obtaining the store identifier of an application installation package according to claim 3, characterized in that, The step of generating an identifier query request based on the valid session token, the verification digest information, and the application identifier information includes: Determine the interface information corresponding to the identifier query interface, wherein the identifier query interface is a preset interface used to query the store identifier corresponding to the specified application identifier information; Generate an initial request body, construct a JSON object in the initial request body, and add the interface information and the application identification information to the JSON object to obtain the session request body; A session request header is generated based on the valid session token and the verification digest information; An identifier query request is generated based on the session request header and the session request body.
6. The method for obtaining the store identifier of an application installation package according to claim 1, characterized in that, The temporary authorization information includes authorization validity period information, which is configured to characterize the validity period of the temporary authorization information. The step of generating an identifier query request based on the temporary authorization information and the application identifier information includes: Based on the current time and the authorization validity period information, determine whether the temporary authorization information is valid; If the temporary authorization information is valid, an identifier query request is generated based on the temporary authorization information and the application identifier information.
7. The method for obtaining the store identifier of an application installation package according to any one of claims 1 to 6, characterized in that, Also includes: Once the target store identifier is obtained, a preset script is used to verify whether the target installation package can be uploaded to the app store corresponding to the target development platform. If the target installation package can be uploaded to the app store, the target store identifier and the target installation package are uploaded to the app store together.
8. A device for obtaining the store identifier of an application installation package, characterized in that, The device includes: The authorization request sending module is configured to obtain the developer account and the application key of the target installation package to be uploaded, and send an authorization request generated based on the developer account and the application key to the target development platform to obtain temporary authorization information of the developer account authenticated by the temporary identifier; The query request generation module is configured to extract application identification information from the target installation package and generate an identification query request based on the temporary authorization information and the application identification information. The query request sending module is configured to send the identifier query request to the target development platform to obtain the target store identifier corresponding to the application identifier information, which is used to upload the application package together with the target installation package to the application store corresponding to the target development platform.
9. A device for obtaining the store identifier of an application installation package, characterized in that, The device that obtains the store identifier of the application installation package includes a processor and memory; The memory is configured to store computer programs and transfer the computer programs to the processor; The processor is configured to execute the store identifier acquisition method for the application installation package as described in any one of claims 1 to 7 according to instructions in the computer program.
10. A storage medium for storing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a computer processor, are configured to perform the store identifier acquisition method for the application installation package as described in any one of claims 1 to 7.