Data processing method, service platform, computer-readable storage medium, and processor
By automatically updating API-related data between the gateway backend and permission platform of the service platform, the problem of inefficiency and high failure rate caused by developers' need to manually configure APIs is solved, more efficient and accurate API data updates are achieved, and separation of responsibilities is achieved.
Patent Information
- Application Number
- CN202210147896.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-17
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-02-17
AI Technical Summary
In the service platform, developers need to manually configure the newly developed API to the permission platform and gateway backend, resulting in inefficiency and high failure rates and the inability to achieve separation of responsibilities.
By obtaining API-related information reported by the business development system in the gateway background, automatically update the business relationship data, and sending this information to the permission platform to automatically update the permission relationship data, thereby realizing automatic update of the API data.
Improves the efficiency and accuracy of API data updates in gateways and permission platforms, reduces the steps of manual configuration, reduces the failure rate, and achieves separation of responsibilities.
Smart Images

Figure CN114546470B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of software development, and in particular, to a data processing method, a service platform, a computer-readable storage medium, and a processor. Background Art
[0002] In the related art, the permission control of the API interface in the service platform is jointly completed by the permission platform and the gateway in the service platform. However, when developers develop new service functions, the newly developed APIs need to be manually configured by the developers in the gateway background of the permission platform and the gateway, resulting in that the developers not only need to care about their own responsible development environment, but also need to operate other environments that are not originally the responsibility of the developers, and it is impossible to achieve separation of responsibilities. There are problems of low efficiency in manually configuring APIs and many fault points may be generated due to possible mistakes in manual addition.
[0003] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0004] Embodiments of the present invention provide a data processing method, a service platform, a computer-readable storage medium, and a processor, so as to at least solve the technical problems of low efficiency and high failure rate caused by manual updating of data in the gateway background and the permission platform after platform developers develop APIs.
[0005] According to one aspect of the embodiments of the present invention, a data processing method is provided, including: the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system, where the gateway background is used to maintain business relationship data, the business relationship data includes the call correspondence between the API and the business microservice, the reported resource information includes the target API and the permission information corresponding to the target API, and the permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the business microservice; the gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the business relationship data; the gateway background sends the reported resource information to the permission platform corresponding to the target gateway, where the permission platform is used to maintain permission relationship data, and the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role; the permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information.
[0006] Optionally, when the target gateway is started, the method further includes: the permission platform obtains the permission relationship data from the permission database, where the permission database is further used to store the permission relationship data in the permission platform after the permission platform is updated; the gateway background obtains the service relationship data from the service database, where the service database is further used to store the service relationship data in the gateway background after the gateway background is updated.
[0007] Optionally, the method further includes: after the target gateway is started, the target gateway monitors the update of the permission relationship data of the permission platform and / or the update of the service relationship data of the gateway background, and performs permission authentication on the service data request sent by the user through the client according to the updated data of the permission platform and the gateway background.
[0008] Optionally, the performing permission authentication on the service data request sent by the user through the client includes: the target gateway obtains the service data request sent by the user through the client, where the service data request includes the user ID of the user and the user requests to call the target API; the target gateway determines whether the user role corresponding to the user ID has the permission to call the target API according to the permission relationship data; when the user role corresponding to the user ID has the permission to call the target API, the target gateway calls the service microservice corresponding to the target API according to the service relationship data.
[0009] Optionally, after the permission platform updates the permission relationship data according to the permission information of the target API, it further includes: the permission platform obtains incremental data, where the incremental data is used to describe the newly added permission relationship data in the permission platform; the permission platform sends the incremental data to the asynchronous message transceiver module; the gateway background obtains the incremental data from the asynchronous message transceiver module and updates the service relationship data of the gateway background according to the incremental data.
[0010] Optionally, the permission platform obtains incremental data, including: the permission platform receives a permission modification instruction, where the permission modification instruction is used to change the correspondence between the user role and the API in the permission platform; according to the permission modification instruction, update the correspondence between the user role and the API in the permission relationship data; determine the incremental data of the permission platform according to the update of the permission relationship data in the permission platform.
[0011] Optionally, the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system, including: the gateway background monitors an asynchronous message sending and receiving module, where the asynchronous message sending and receiving module is used to store the reported resource information associated with the target API reported by the service development system; when the reported resource information is stored in the asynchronous message sending and receiving module, the gateway background obtains the reported resource information from the asynchronous message sending and receiving module.
[0012] According to another aspect of the embodiments of the present invention, there is also provided a service platform, including: an obtaining module, configured to obtain, by the gateway background corresponding to the target gateway, the reported resource information associated with the target API reported by the service development system, where the gateway background is used to maintain service relationship data, and the service relationship data includes the call correspondence between the API and the service microservices, and the reported resource information includes the target API and the permission information corresponding to the target API, and the permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the service microservices; a first updating module, configured to update, by the gateway background, the target API included in the reported resource information and the microservice information corresponding to the target API to the service relationship data; a sending module, configured to send, by the gateway background, the reported resource information to the permission platform corresponding to the target gateway, where the permission platform is used to maintain permission relationship data, and the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role; a second updating module, configured to update, by the permission platform, the permission relationship data according to the permission information corresponding to the target API in the reported resource information.
[0013] According to still another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium, where the computer-readable storage medium includes a stored program, and when the program runs, it controls the device where the computer-readable storage medium is located to execute the data processing method described in any one of the above.
[0014] According to still another aspect of the embodiments of the present invention, there is also provided a processor, where the processor is used to run a program, and when the program runs, it executes the data processing method described in any one of the above.
[0015] In an embodiment of the present invention, the gateway background for maintaining business relationship data obtains the reported resource information associated with the target API reported by the business development system. The business relationship data includes the call correspondence between the API and the business microservices, and the reported resource information includes the target API and the permission information corresponding to the target API. The gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the business relationship data, and sends the reported resource information to the permission platform for maintaining the permission relationship data. The permission relationship data includes the call permission relationship between the user role and the API. The permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information, achieving the purpose of automatically updating the API data in the gateway background and the permission platform in the service platform after the developer develops a new API, thereby realizing the technical effect of improving the update efficiency and accuracy of the API data in the gateway and the permission platform, and further solving the technical problem of low efficiency and high failure rate caused by the need for platform developers to manually update the data in the gateway background and the permission platform after developing the API. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention, and do not constitute an improper limitation of the present invention. In the drawings:
[0017] Figure 1 A hardware structure block diagram of a computer terminal for implementing a data processing method is shown;
[0018] Figure 2 It is a flowchart of the data processing method provided by an embodiment of the present invention;
[0019] Figure 3 A schematic diagram of the permission relationship data provided by an optional embodiment of the present invention is shown;
[0020] Figure 4 It is a schematic diagram of the API reporting process provided by an optional embodiment of the present invention;
[0021] Figure 5 It is a startup flowchart of the target gateway provided by an optional embodiment of the present invention;
[0022] Figure 6 It is a structure block diagram of the service platform provided by an embodiment of the present invention;
[0023] Figure 7 It is a structure block diagram of the data processing device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0026] First, some nouns or terms that appear in the process of describing the embodiments of the present application are applicable to the following explanations:
[0027] Application programming interface (API for short) can be a predefined function or an HTTP interface, which is used to provide the interaction and connection between different components of an application or software system.
[0028] Redis, Remote Dictionary Server, an open-source network-supported persistent K-V database.
[0029] RocketMQ, a software product that can realize asynchronous message sending and receiving. It can store the received messages in a topic, and other devices listen to the topic messages to realize asynchronous message reception and storage.
[0030] Embodiment 1
[0031] According to an embodiment of the present invention, there is provided an embodiment of a data processing method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described here can be executed in a different order from that here.
[0032] The method embodiment provided by the first embodiment of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 The following shows a hardware block diagram of a computer terminal for implementing a data processing method. As Figure 1 shown, the computer terminal 10 may include one or more processors (in the figure, 102a, 102b,..., 102n are used to illustrate), and the processor may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA, a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.
[0033] It should be noted that the above one or more processors and / or other data processing circuits are generally referred to as "data processing circuits" in this article. The data processing circuit may be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any one of the other elements in the computer terminal 10. As involved in the embodiments of this application, the data processing circuit is a processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0034] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data processing method in the embodiments of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the data processing method of the above application program. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely provided with respect to the processor, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0035] The transmission module 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission module 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission module 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0036] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 10.
[0037] For the service platform that provides services, it is necessary to implement the authentication of access traffic through the API gateway and the permission platform, identify the identity information of the access traffic, determine the service functions that this traffic can use according to the identity information, and then the API gateway determines the permissions for this access traffic to call APIs according to the API set corresponding to the service functions that this traffic can use. Therefore, authentication is to perform API permission identification on the access traffic. It should be noted that the service functions that the background can provide can be some business microservices. The identity information of the access traffic can be the identity information of the user corresponding to this traffic. The categories of identity information can include, for example, visitors, registered users or members, and can also include maintenance personnel of the service platform, such as developers, testers, and operators. The above-mentioned identity information can all be referred to as the user roles of the access traffic. Different user roles can call different APIs, so different user roles can also call different service functions. The APIs that each user role can call, or the user roles matched by each API, are called the permission information of the API. When developers develop new business services for this service platform, they will also develop multiple APIs related to this business service. At this time, in the related art, the staff will manually input the newly developed API functions and the initial permission information of the APIs into the gateway background of the API gateway and the permission platform. This process is manually completed by the staff, so the efficiency is low and it is easy to make mistakes.
[0038] Figure 2 It is a schematic flowchart of the data processing method provided by the embodiment of the present invention. As Figure 2 shown, the method includes the following steps:
[0039] Step S202: The gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system. The gateway background is used to maintain business relationship data, where the business relationship data includes the call correspondence between the API and the business microservices. The reported resource information includes the target API and the permission information corresponding to the target API. The permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the business microservices.
[0040] In this step, the service development system reports the reported resource information associated with the target API to the gateway background corresponding to the target gateway. The gateway background can be used to maintain business relationship data. Based on the business relationship data, it can be determined whether an API has the right to call the business microservices in the background to provide microservices. The target API included in the reported resource information is the API reported this time. The permission information corresponding to the target API can be used to describe the relationship between the API and the role and the relationship between the API and the business microservices respectively. Among them, the target role can be the role of the user. For example, only users who meet a specific role can call this API. The correspondence between the target API and the business microservices can be used to describe the permissions that the target API can have to call which business microservices. Furthermore, through the target API, the permission correspondence relationship between the target role and the business microservices can be determined.
[0041] It should be noted that the business development system can be a system for developers to develop business services, and then deploy the developed business service function modules to the server for users to use. The target API can be a new API developed by developers in the development environment of the business development system. Developers can newly develop multiple APIs in a business service, and by associating a target API with a reported resource information, realize the automatic reporting of the target API. Specifically, the reported resource information associated with the target API can include the function constructed by the developer when developing the target API, and the permission information of the target API. During the process of automatically reporting the target API, the business development system can scan multiple newly developed APIs. If an API is associated with reported resource information, the reported resource information of the API is encapsulated and reported; if an API is not associated with reported resource information, no automatic reporting process is performed on the API. Optionally, the reported resource information can be referred to as ApiResource, and the ApiResource includes the uri of the newly developed target API (access path: such as the http interface path for querying points), the name of the target API, and the permission information of the target API. The permission information of the API can be used to determine which user role corresponding to the access traffic allowed by the service platform can call the API. Therefore, through the permission information of the target API, it can be determined which functions in the service platform providing services can be established in correspondence with the user role matching the target API through binding.
[0042] Optionally, the target gateway can be a component in the service platform. The service platform is used to provide functional services for users, and the functional services provided for users can be decomposed into business microservices in the background. The user first sends a request to call the functional services provided by the service platform (or a request to call the API of the service platform). The target gateway of the service platform authenticates the user's request to determine whether the user's corresponding role has the permission to call the API corresponding to the corresponding functional service. If the user has the permission, the request is directly released, allowing the user to call the corresponding API. If the user does not have the permission, the information that the user does not have the corresponding API permission is fed back to the user. The above request is the access traffic in the present invention. The target gateway determines whether different types of users have the qualification to call the corresponding functional service through the target API based on the permission information, and the permission information can be initialized and set by the developer when developing the target API.
[0043] Step S204, the gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the business relationship data.
[0044] Optionally, the business relationship data may include APIs stored locally and the permission information of the APIs. The local APIs may include all the APIs loaded locally when the target gateway is started. Preferably, when the target gateway is not started, all the data of all the APIs of the service platform may be stored elsewhere and loaded into the local memory of the target gateway when the target gateway is started. The all data of the APIs may include functions, URL addresses, permission information, etc. of the APIs. The access traffic of the user is used to request to call the functional services of the service platform. Therefore, the target gateway of the service platform may authenticate the access traffic according to the data of the local APIs to determine whether the user has the permission to call the APIs corresponding to the functional services. Since the access traffic of the user includes the identity information of the user, i.e., the user role, when the target gateway performs the authentication action on the access traffic, it may determine the APIs that the access traffic can call through the user role of the access traffic, and then determine whether the APIs requested by the access traffic are within the APIs that it has the right to call.
[0045] Optionally, after comparing the target API in the reported resource information with the data of the locally stored APIs by the gateway background, any one of the following two methods may be adopted to update the data of the target API to the local of the target gateway.
[0046] First, in the case where the data of the target API does not exist in the data of the local APIs, it means that the target API is a brand-new API. At this time, a new entry is created in the local memory of the gateway background, and the data of the target API is added to this entry to expand the data of the local APIs.
[0047] Or, when there is an API in the data of the local APIs with the same uri as the target API, the data of the target API is used to update the data of the local API corresponding to the same uri.
[0048] Step S206, the gateway background sends the reported resource information to the permission platform corresponding to the target gateway, where the permission platform is used to maintain the permission relationship data, and the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role.
[0049] Optionally, the gateway background may send the permission information of the target API to the permission platform of the target gateway, where the permission platform is used to maintain the permission relationship data, and the permission relationship data is used to describe the call permission relationship between the API and the user role, that is, whether the user role has the right to call the API. The target gateway may authenticate whether the access traffic has the right to call the local APIs according to the permission relationship data. For example, according to the role corresponding to the access traffic, it is determined whether the role has the right to call the corresponding API.
[0050] Optionally, the permission platform may be a visual permission operation platform, and the permission information of the API can be visually presented on the permission platform. Staff can change the correspondence between the API and the user role by operating on the permission platform. The permission relationship data is the data recording the correspondence between any API and the user role. For example, the permission relationship data can be used to record the correspondence between the user identity, user role, and service function. When the user role is "developer", "tester", or "operator", each role corresponds to a different combination of service functions, and each service function corresponds to an API set. The above correspondences can all be recorded through the permission relationship data.
[0051] Optionally, Figure 3 shows a schematic diagram of the permission relationship data provided according to an optional embodiment of the present invention, as Figure 3 shown, each user can correspond to multiple user roles, each user role can correspond to multiple service functions, and each service function can correspond to multiple APIs, so as to obtain data related to the service function from multiple APIs. When the access traffic sent by the user is received by the target gateway, the user ID can be obtained by parsing the access traffic. The user role corresponding to the user can be found in the permission platform, and the API set that the user is authorized to call can be determined step by step. This API set is the set of APIs related to the service function that the user is authorized to use. Further, the API corresponding to the service function requested in the user access traffic can be compared to see if the requested API is in the above API set. If it is in the set, it is determined that the user is authorized to call the corresponding API. If not, it is determined that the user is not authorized to call the corresponding API, and the authentication action of the access traffic is completed.
[0052] Step S208, the permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information.
[0053] In this step, the permission platform can update the permission relationship data according to the permission information of the target API, achieving the purpose of comprehensively reporting information related to the APIs developed by the business development system. Since the permission information of the target API can determine which service functions or user roles the target API can correspond to, the permission relationship data of the permission platform can be updated through the permission information of the target API, realizing the automatic update of the permission platform.
[0054] Through the above steps, the purpose of automatically updating the API data in the gateway and the permission platform in the service platform after the developer develops a new API is achieved, thereby realizing the technical effect of improving the update efficiency and accuracy of the API data in the gateway and the permission platform, and further solving the technical problems of low efficiency and high failure rate caused by manually updating the data of the gateway background and the permission platform after the platform developer develops the API.
[0055] As an alternative embodiment, when the target gateway is started, the permission platform can also obtain the permission relationship data from the permission database, where the permission database is also used to store the permission relationship data in the permission platform after the permission platform is updated; the gateway background obtains the service relationship data from the service database, where the service database is also used to store the service relationship data in the gateway background after the gateway background is updated.
[0056] In this alternative embodiment, the permission relationship data and the service relationship data can be stored in the permission database and the service database respectively, avoiding data loss caused by the failure of the target gateway. When the target gateway is started, the permission platform and the gateway background can directly obtain the data required to implement their functions from the corresponding databases, and then complete the authentication of the traffic according to the obtained data.
[0057] As an alternative embodiment, after the target gateway is started, the target gateway monitors the update of the permission relationship data of the permission platform and / or the update of the service relationship data of the gateway background, and performs permission authentication on the service data request sent by the user through the client according to the updated data of the permission platform and the gateway background.
[0058] In this alternative embodiment, after the service development system reports the reported resource information of the API, the target gateway completes the update of the permission platform and the gateway background, and can perform permission authentication on the service data request sent by the user according to the updated data, where the service data request may be included in the access traffic of the user, and the access traffic of the user may include the identity information of the user, such as the user role of the user. Through this alternative embodiment, a method for updating the data in the target gateway at any time is provided, realizing the instant update of the data in the permission platform and the gateway background and further authentication.
[0059] As an alternative embodiment, to perform permission authentication on the service data request sent by the user through the client, the following method can be adopted: The target gateway obtains the service data request sent by the user through the client, and the service data request includes the user ID of the user and the user's request to call the target API; the target gateway determines whether the user role corresponding to the user ID has the permission to call the target API according to the permission relationship data; in the case where the user role corresponding to the user ID has the permission to call the target API, the target gateway calls the service microservice corresponding to the target API according to the service relationship data.
[0060] Optionally, the target gateway can determine the user role of the user based on the user ID in combination with the data of the permission platform. Among them, the user role can include the VIP level, payment status, etc. of the user who is a service user, and can also include the identities of the internal maintenance personnel of the service platform, such as developers, testers, etc. The data stored in the permission platform can be used to determine whether the user has the permission to call the API based on the user role, and whether the API has the permission to call the microservice in the background of the service platform. Therefore, in the case where the service data request includes the user ID of the user and the user's request to call the target API, it can be determined according to the permission data whether the access traffic of the user can be released by the target gateway, that is, whether to allow the access traffic to call the API it wants to call.
[0061] As an alternative embodiment, the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system, and the following method can be adopted: The gateway background listens to the asynchronous message receiving and sending module, where the asynchronous message receiving and sending module is used to store the reported resource information associated with the target API reported by the service development system; in the case where the reported resource information is stored in the asynchronous message receiving and sending module, the gateway background obtains the reported resource information from the asynchronous message receiving and sending module.
[0062] As an alternative embodiment, the service development system can encapsulate the target API in the following manner to obtain the reported resource information: During the service development phase, a certain service may involve many APIs, such as the balance query service and the points query service. When developing the corresponding API of this service, such as an http interface, create an ApiResource for each API that needs to be reported and establish an association with the corresponding API. This ApiResource contains the uri of the API (the uri is the access path of the API, such as the http interface path of the points query service), the name of the API, and the permission information of the API; when the service starts, the spring framework scans all newly developed APIs, loads all the API interfaces associated with ApiResource into memory, and then uses a multi-threaded asynchronous method to parse each API one by one to obtain the ApiResource associated with each API to be reported. Among them, ApiResource can include permission information, API name, API URI, API ID, and methodtype.
[0063] In this alternative embodiment, the asynchronous message sending and receiving module can decouple the sending and receiving of data, avoiding data reporting errors caused by failures in the gateway background. Compared with the synchronous sending and receiving method for transmitting information, asynchronous message sending and receiving has the following advantages: First, using the asynchronous message sending and receiving method can avoid the process of API data transmission from affecting the normal startup of the service system. After the service system is developed, the newly developed API data can be directly sent to the asynchronous message sending and receiving module without waiting for the gateway background and the permission platform to process the reported API data. Second, using the asynchronous message sending and receiving method can avoid uncontrollable problems during the data update process resulting in data asynchronization. For example, when there is a problem in the gateway background and the data of the target API is not updated successfully in the gateway background, the asynchronous message sending and receiving module can continue to save the data of the target API and send it to the gateway background again until the gateway background updates the data successfully, avoiding data asynchronization caused by the data receiving party not updating successfully while the data sending party has defaulted to sending the data successfully during synchronous data transmission.
[0064] As an alternative embodiment, the asynchronous message sending and receiving module may adopt RocketMQ. RocketMQ is an asynchronous message sending and receiving software product. The gateway platform can subscribe to a topic in RocketMQ. For example, the topic can be named API-gateway. The gateway background listens to the topic messages at all times. When the business development system reports a target API, it can send the reported resource information of the target API to RocketMQ and save it in the topic: API-gateway. After the gateway background learns through listening that the data of the target API has been stored in the topic, it pulls the corresponding data from the topic and updates the local API data.
[0065] As an alternative embodiment, the permission platform can obtain incremental data in the following manner: The permission platform receives a permission modification instruction, where the permission modification instruction is used to change the correspondence between user roles and APIs in the permission platform; according to the permission modification instruction, update the correspondence between user roles and APIs in the permission relationship data; according to the update of the permission relationship data in the permission platform, determine the incremental data of the permission platform.
[0066] In this alternative embodiment, a method for modifying permission data is provided for the permission platform. In addition to updating the permission relationship data according to the newly developed target API, the permission platform can also update the permission relationship data according to the user's permission modification instruction. For example, a user can manually add a service function for a certain user role in the visual permission platform, or adjust the API set corresponding to a service function. After the permission platform updates the data corresponding to the target API in the permission relationship data according to the instruction, it can generate incremental data according to the data changes and send it to the gateway background through the asynchronous message sending and receiving module to realize data synchronization between the permission platform and the gateway background.
[0067] For example, the permission administrator can manually modify the permission data in the permission platform, add corresponding permissions for a certain role, or associate a corresponding role with a personal ID. For example, change the role of an individual from a developer to a tester. Further, the permission platform can record the above modified content in the form of incremental data, realizing free modification and reliable recording of the data in the permission platform.
[0068] As an alternative embodiment, after the permission platform updates the permission relationship data according to the permission information of the target API, the permission platform may also obtain incremental data, where the incremental data is used to describe the newly added permission relationship data in the permission platform; the permission platform sends the incremental data to the asynchronous message transceiver module; the gateway background obtains the incremental data from the asynchronous message transceiver module and updates the service relationship data of the gateway background according to the incremental data. In this alternative embodiment, the updated content in the permission platform can be synchronized to the gateway background, achieving data consistency between the gateway background and the permission platform.
[0069] As an alternative embodiment, the process of the gateway background sending the permission information of the target API to the permission platform may be as follows: the gateway background sends the permission information of the target API to the asynchronous message transceiver module; when the permission platform monitors that the asynchronous message transceiver module receives the permission information of the target API, the permission platform obtains the permission information of the target API from the asynchronous message transceiver module. In this alternative embodiment, the process of the gateway background sending the permission information to the permission platform may also be implemented by RocketMQ, and the specific implementation method is the same as the method for the service development system to report data to the gateway background.
[0070] The permission platform can also synchronize the incremental data to the gateway background with the participation of the asynchronous message transceiver module: send the incremental data to the asynchronous message transceiver module; when the gateway background monitors that the asynchronous message transceiver module receives the incremental data, the gateway background obtains the incremental data from the asynchronous message transceiver module; the gateway background updates the data of the local API according to the incremental data.
[0071] It should be noted that when the target gateway performs authentication, it can perform permission comparison based on the data stored in the local memory of the target gateway. Therefore, when the permission platform makes changes to the correspondence between user roles, service functions, and APIs, the specific changes can be notified to the target gateway in the form of incremental data, and the target gateway updates the data of the local API according to the incremental data, realizing synchronous update of the data between the permission platform and the gateway background of the target gateway. Optionally, the process of the permission platform sending the incremental data to the gateway background can also be carried out using the asynchronous message transceiver module RocketMQ.
[0072] As an alternative embodiment, determining the incremental data of the permission platform further includes receiving a permission modification instruction, where the permission modification instruction is used to change the correspondence between the user role and the target API; updating the data corresponding to the target API in the permission relationship data according to the permission modification instruction; determining the incremental data of the permission platform according to the update of the data corresponding to the target API in the permission relationship data.
[0073] The following uses a preferred embodiment to illustrate the data processing method of the present invention. It should be noted that this preferred embodiment is only one of the various embodiments that can be selected to implement the technical solution of the present invention, and does not constitute a limitation on the technical solution claimed by the present invention.
[0074] Figure 4 It is a schematic diagram of the API reporting process according to an optional embodiment of the present invention. As Figure 4 shown, the automatic reporting of newly developed APIs can include the following steps:
[0075] 1. The API synchronization layer of the business development system scans the newly developed APIs, encapsulates the data of the target APIs associated with ApiResource into reporting resource information, and then sends the reporting resource information to the asynchronous message transceiver module RocketMQ through the sending layer and saves it in topic1 of RocketMQ. In this step, the API synchronization layer first traverses and parses all newly developed APIs, determines whether each API corresponds to the reporting resource information, and if there is corresponding information, encapsulates the data and sends it to the sending layer to send to the target gateway. This step realizes the identification of the target APIs in the business development system, as well as the packaging and reporting of the reporting resource information of the target APIs to the target gateway. During the process of reporting information to the target gateway, through the introduction of the asynchronous message transceiver module, the decoupling of data transceiver between the business development system and the target gateway is realized, improving the efficiency and reliability of data transmission.
[0076] 2. The gateway background of the target gateway can subscribe to topic1 in RocketMQ, receive the reporting resource information of the target APIs from RocketMQ, and update the data of the local APIs in the local memory.
[0077] 3. The gateway background parses the encapsulated reporting resource information and can obtain the permission information of the target APIs. When the gateway background updates all the data of the target APIs to the local memory, it can send the permission information of the target APIs to RocketMQ and save it in topic2. This step can use the same asynchronous message transceiver module as in step 1 to decouple the process of sending and receiving permission information between the gateway background and the permission platform, ensuring that the permission platform can receive the permission information of the target APIs parsed by the gateway background. If the asynchronous message transceiver module is not used and the gateway background and the permission platform directly exchange data, if a data transmission error occurs, it will lead to data inconsistency between the gateway background and the permission platform, and further lead to authentication failure or authentication error of the target gateway. Using the asynchronous message transceiver module can avoid the above problems.
[0078] 4. The permission platform subscribes to topic2 of RocketMQ, obtains the permission information of the target API, and updates the permission relationship data in the permission platform.
[0079] 5. The permission platform generates incremental data based on the update of the permission relationship data, sends the incremental data to RocketMQ, and saves it in topic3. The permission platform can handle both ToB and ToC business. For example, ToB business can include functions such as "application management", "function management", "menu management", and "user role", which are used by the operation staff, developers, or testers of the service platform to view, manage, or modify permission data. ToC business is the service provided to consumers or general users requesting services. The permission information stored at the C end can be used to determine whether the general user has the right to call the microservices in the background of the service platform. The permission data in the permission platform can be stored in the Mysql database to ensure data is not lost and can be called quickly. This step is to further confirm the data synchronization between the gateway platform and the permission platform after updating the data in the gateway background and the permission platform according to the target API. In addition, if the operator directly modifies the user role corresponding to the user, or the service function corresponding to the user role, or the API set corresponding to the service function in the permission platform, these modifications can also generate incremental data in the permission platform. The permission platform can send the incremental data to the gateway background through RocketMQ to achieve data synchronization between the gateway background and the permission platform for this manual modification.
[0080] 6. The gateway background subscribes to topic3, obtains the incremental data, and updates the local API data according to the incremental data.
[0081] 7. The gateway background sends the updated API data in the local memory to redis for storage. When the target gateway is not started, all local API data is stored in redis. When the target gateway is started, it can first download the data from redis and save it in the local memory of the gateway background, and perform data processing and permission comparison and other tasks locally in the gateway.
[0082] Figure 5 is the startup flowchart of the target gateway provided according to an optional embodiment of the present invention, as Figure 5 shown, the startup of the target gateway can include the following steps:
[0083] 1. The target gateway (i.e., the tsp gateway in the figure) starts and requests all local API data from redis. All local API data is stored in redis; when the target gateway is closed, all data in the target gateway will be sent to redis for storage backup;
[0084] 2. Redis returns all the data of the local API to the target gateway;
[0085] 3. The target gateway loads all the data of the local API into local memory for use when the target gateway authenticates access traffic;
[0086] 4. After the target gateway starts, the permission platform can request permission relationship data from Redis and cache the permission relationship data returned by Redis in a more lightweight database;
[0087] 5. When the permission relationship data in the permission platform changes, the incremental data recording the change of the permission relationship data is sent to RocketMQ;
[0088] 6. The gateway background can subscribe to the topic in the asynchronous message transceiver module RocketMQ for storing the incremental data of the permission platform. When the topic is updated, the gateway background obtains the incremental data of the permission platform from the topic;
[0089] 7. The gateway background of the target gateway updates the permission data of the local API according to the obtained incremental data, realizing the data synchronization between the API permission information stored in the permission platform and the API permission information stored in the local memory of the gateway background.
[0090] Embodiment 2
[0091] According to an embodiment of the present invention, a service platform for implementing the above data processing method is further provided. Figure 6 It is a structural block diagram of the service platform provided according to an embodiment of the present invention, as Figure 6 shown. The service platform 60 includes: an acquisition module 62, a first update module 64, a sending module 66, and a second update module 68. The service platform 60 will be described below.
[0092] The acquisition module 62 is used for the gateway background corresponding to the target gateway to acquire the reported resource information associated with the target API reported by the service development system. Among them, the gateway background is used to maintain business relationship data, and the business relationship data includes the call correspondence between the API and the business microservice. The reported resource information includes the target API and the permission information corresponding to the target API. The permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the business microservice;
[0093] The first update module 64 is used for the gateway background to update the target API included in the reported resource information and the microservice information corresponding to the target API to the business relationship data;
[0094] A sending module 66, configured to send the reported resource information by the gateway background to the permission platform corresponding to the target gateway, where the permission platform is used to maintain permission relationship data, and the permission relationship data includes the call permission relationship between user roles and APIs, and the user roles include target roles;
[0095] A second update module 68, configured to update the permission relationship data by the permission platform according to the permission information corresponding to the target API in the reported resource information.
[0096] It should be noted here that the above-mentioned obtaining module 62, the first update module 64, the sending module 66, and the second update module 68 correspond to steps S202 to S208 in Embodiment 1. The instances and application scenarios implemented by the multiple modules and the corresponding steps are the same, but are not limited to the content disclosed in the above-mentioned Embodiment 1. It should be noted that the above-mentioned modules can run in the computer terminal 10 provided in Embodiment 1 as a part of the service platform.
[0097] Embodiment 3
[0098] According to an embodiment of the present invention, there is also provided a data processing device, Figure 7 which is a structural block diagram of the data processing device provided according to an embodiment of the present invention, as Figure 7 shown. The data processing device includes: a service development system 72, a target gateway 74, a permission platform 76, and an asynchronous message transceiver module 78. The data processing device will be described below.
[0099] The service development system 72 is configured to report the reported resource information associated with the target API to the gateway background of the target gateway through the asynchronous message transceiver module, where the gateway background is used to maintain the data of the local API stored in the target gateway, and the reported resource information includes the permission information of the target API;
[0100] The target gateway 74 is configured to authenticate whether the access traffic received by the service platform has the right to call the local API;
[0101] The target gateway 74 further includes: a gateway background 75 and a permission platform 76, where the gateway background 75 is configured to update the reported resource information to the data of the local API stored in the target gateway, and is further configured to send the permission information of the target API to the permission platform 76 through the asynchronous message transceiver module 78;
[0102] The permission platform 76 is configured to maintain permission relationship data, the permission relationship data is used to describe the corresponding relationship between user roles and local APIs, and to update the permission relationship data according to the permission information of the target API, where the permission relationship data is used for the target gateway to authenticate whether the access traffic with user roles has the right to call the local API;
[0103] The asynchronous message sending and receiving module 78 is used to realize the asynchronous sending and receiving of data between multiple modules.
[0104] Embodiment 4
[0105] An embodiment of the present invention may provide a computer device. Optionally, in this embodiment, the above computer device may be located in at least one network device among multiple network devices of a computer network. The computer device includes a memory and a processor.
[0106] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the data processing method and device in the embodiment of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, to implement the above data processing method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories can be connected to the computer terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and their combinations.
[0107] The processor can call the information and application programs stored in the memory through a transmission device to execute the following steps: the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system. Among them, the gateway background is used to maintain service relationship data, and the service relationship data includes the call correspondence between the API and the service microservice. The reported resource information includes the target API and the permission information corresponding to the target API. The permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the service microservice; the gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the service relationship data; the gateway background sends the reported resource information to the permission platform corresponding to the target gateway. Among them, the permission platform is used to maintain permission relationship data, and the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role; the permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information.
[0108] Optionally, the above processor may also execute the program code of the following steps: when the target gateway is started, the method further includes: the permission platform obtains the permission relationship data from the permission database, where the permission database is also used to store the permission relationship data in the permission platform after the permission platform is updated; the gateway background obtains the service relationship data from the service database, where the service database is also used to store the service relationship data in the gateway background after the gateway background is updated.
[0109] Optionally, the above-mentioned processor may also execute the program code of the following steps: after the target gateway is started, the target gateway monitors the update of the permission relationship data of the permission platform and / or the update of the service relationship data of the gateway background, and performs permission authentication on the service data request sent by the user through the client according to the updated data of the permission platform and the gateway background.
[0110] Optionally, the above-mentioned processor may also execute the program code of the following steps: performing permission authentication on the service data request sent by the user through the client, including: the target gateway obtains the service data request sent by the user through the client, and the service data request includes the user ID of the user and the user requests to call the target API; the target gateway determines whether the user role corresponding to the user ID has the permission to call the target API according to the permission relationship data; in the case where the user role corresponding to the user ID has the permission to call the target API, the target gateway calls the service microservice corresponding to the target API according to the service relationship data.
[0111] Optionally, the above-mentioned processor may also execute the program code of the following steps: after the permission platform updates the permission relationship data according to the permission information of the target API, it further includes: the permission platform obtains incremental data, where the incremental data is used to describe the newly added permission relationship data in the permission platform; the permission platform sends the incremental data to the asynchronous message transceiver module; the gateway background obtains the incremental data from the asynchronous message transceiver module and updates the service relationship data of the gateway background according to the incremental data.
[0112] Optionally, the above-mentioned processor may also execute the program code of the following steps: the permission platform obtains incremental data, including: the permission platform receives a permission modification instruction, where the permission modification instruction is used to change the corresponding relationship between the user role and the API in the permission platform; according to the permission modification instruction, update the corresponding relationship between the user role and the API in the permission relationship data; determine the incremental data of the permission platform according to the update of the permission relationship data in the permission platform.
[0113] Optionally, the above-mentioned processor may also execute the program code of the following steps: the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system, including: the gateway background monitors the asynchronous message transceiver module, where the asynchronous message transceiver module is used to store the reported resource information associated with the target API reported by the service development system; in the case where the reported resource information is stored in the asynchronous message transceiver module, the gateway background obtains the reported resource information from the asynchronous message transceiver module.
[0114] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, and the storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.
[0115] Embodiment 5
[0116] An embodiment of the present invention further provides a computer-readable storage medium. Optionally, in this embodiment, the above computer-readable storage medium can be used to save the program code executed by the data processing method provided in the above Embodiment 1.
[0117] Optionally, in this embodiment, the above computer-readable storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0118] Optionally, in this embodiment, the computer-readable storage medium is set to store program code for performing the following steps: the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system. The gateway background is used to maintain service relationship data, and the service relationship data includes the call correspondence between the API and the service microservices. The reported resource information includes the target API and the permission information corresponding to the target API. The permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the service microservices; the gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the service relationship data; the gateway background sends the reported resource information to the permission platform corresponding to the target gateway, where the permission platform is used to maintain permission relationship data, and the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role; the permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information.
[0119] Optionally, in this embodiment, the computer-readable storage medium is set to store program code for performing the following steps: when the target gateway is started, the method further includes: the permission platform obtains the permission relationship data from the permission database, where the permission database is also used to store the permission relationship data in the permission platform after the permission platform is updated; the gateway background obtains the service relationship data from the service database, where the service database is also used to store the service relationship data in the gateway background after the gateway background is updated.
[0120] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: after the target gateway is started, the target gateway listens for updates to the permission relationship data of the permission platform and / or updates to the service relationship data of the gateway background, and performs permission authentication on the service data request sent by the user through the client according to the updated data of the permission platform and the gateway background.
[0121] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: performing permission authentication on the service data request sent by the user through the client, including: the target gateway obtains the service data request sent by the user through the client, and the service data request includes the user ID of the user and the user requests to call the target API; the target gateway determines whether the user role corresponding to the user ID has the permission to call the target API according to the permission relationship data; in the case that the user role corresponding to the user ID has the permission to call the target API, the target gateway calls the service microservice corresponding to the target API according to the service relationship data.
[0122] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: after the permission platform updates the permission relationship data according to the permission information of the target API, it further includes: the permission platform obtains incremental data, where the incremental data is used to describe the newly added permission relationship data in the permission platform; the permission platform sends the incremental data to the asynchronous message transceiver module; the gateway background obtains the incremental data from the asynchronous message transceiver module and updates the service relationship data of the gateway background according to the incremental data.
[0123] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: the permission platform obtains incremental data, including: the permission platform receives a permission modification instruction, where the permission modification instruction is used to change the correspondence between the user role and the API in the permission platform; according to the permission modification instruction, update the correspondence between the user role and the API in the permission relationship data; determine the incremental data of the permission platform according to the update of the permission relationship data in the permission platform.
[0124] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: the gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system, including: the gateway background listens to the asynchronous message transceiver module, where the asynchronous message transceiver module is used to store the reported resource information associated with the target API reported by the service development system; in the case that the reported resource information is stored in the asynchronous message transceiver module, the gateway background obtains the reported resource information from the asynchronous message transceiver module.
[0125] The serial numbers of the embodiments of the present invention above are only for description and do not represent the superiority or inferiority of the embodiments.
[0126] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0127] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0128] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0129] In addition, the functional units in the various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0130] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.
[0131] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A data processing method, characterized in that, Including: The gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the service development system. Among them, the gateway background is used to maintain service relationship data, the service relationship data includes the call correspondence between the API and the service microservices, the reported resource information includes the target API and the permission information corresponding to the target API, and the permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the service microservices; The gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the service relationship data; The gateway background sends the reported resource information to the permission platform corresponding to the target gateway. Among them, the permission platform is used to maintain permission relationship data, and the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role; The permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information; Among them, the gateway background updates the target API included in the reported resource information and the microservice information corresponding to the target API to the service relationship data. The service relationship data includes the APIs stored locally, including: in the case where the data of the target API does not exist in the local API data, the gateway background creates a new entry in the local memory and adds the data of the target API to the new entry; or, in the case where there is an API with the same uri as the target API in the local API data, the gateway background updates the data of the local API with the data of the target API.
2. The data processing method according to claim 1, characterized in that, When the target gateway is started, the method further includes: The permission platform obtains the permission relationship data from the permission database, where the permission database is also used to store the permission relationship data in the permission platform after the permission platform is updated; The gateway background obtains the service relationship data from the service database, where the service database is also used to store the service relationship data in the gateway background after the gateway background is updated.
3. The data processing method according to claim 2, characterized in that, The method further includes: After the target gateway is started, the target gateway monitors the update of the permission relationship data of the permission platform and / or the update of the service relationship data of the gateway background, and performs permission authentication on the service data request sent by the user through the client according to the updated data of the permission platform and the gateway background.
4. The data processing method according to claim 3, characterized in that, The performing permission authentication on the service data request sent by the user through the client includes: The target gateway obtains the service data request sent by the user through the client, and the service data request includes the user ID of the user and the user requests to call the target API; The target gateway determines whether the user role corresponding to the user ID has the permission to call the target API according to the permission relationship data; When the user role corresponding to the user ID has the permission to call the target API, the target gateway calls the business microservice corresponding to the target API according to the business relationship data.
5. The data processing method according to claim 1, characterized in that, After the permission platform updates the permission relationship data according to the permission information corresponding to the target API in the reported resource information, it further includes: The permission platform obtains incremental data, where the incremental data is used to describe the newly added permission relationship data in the permission platform; The permission platform sends the incremental data to the asynchronous message transceiver module; The gateway background obtains the incremental data from the asynchronous message transceiver module and updates the business relationship data of the gateway background according to the incremental data.
6. The data processing method according to claim 5, characterized in that, The permission platform obtaining incremental data includes: The permission platform receives a permission modification instruction, where the permission modification instruction is used to change the corresponding relationship between the user role and the API in the permission platform; According to the permission modification instruction, update the corresponding relationship between the user role and the API in the permission relationship data; Determine the incremental data of the permission platform according to the update of the permission relationship data in the permission platform.
7. The data processing method according to claim 1, characterized in that, The gateway background corresponding to the target gateway obtains the reported resource information associated with the target API reported by the business development system, including: The gateway background listens to the asynchronous message transceiver module, where the asynchronous message transceiver module is used to store the reported resource information associated with the target API reported by the business development system; When the reported resource information is stored in the asynchronous message transceiver module, the gateway background obtains the reported resource information from the asynchronous message transceiver module.
8. A service platform, characterized in that, It includes: An obtaining module, configured to enable the gateway background corresponding to the target gateway to obtain the reported resource information associated with the target API reported by the business development system, where the gateway background is used to maintain business relationship data, the business relationship data includes the call correspondence between the API and the business microservice, the reported resource information includes the target API and the permission information corresponding to the target API, and the permission information is used to describe the call permission relationship between the target API and the target role and the correspondence between the target API and the business microservice; A first update module, configured to enable the gateway background to update the target API included in the reported resource information and the microservice information corresponding to the target API to the business relationship data; A sending module, configured to enable the gateway background to send the reported resource information to the permission platform corresponding to the target gateway, where the permission platform is used to maintain permission relationship data, the permission relationship data includes the call permission relationship between the user role and the API, and the user role includes the target role; A second update module, configured to enable the permission platform to update the permission relationship data according to the permission information corresponding to the target API in the reported resource information; Among them, the service relationship data includes APIs stored locally. The first update module is further configured to, when the data of the target API does not exist in the data of the local API, the gateway background creates a new entry in the local memory and adds the data of the target API to the new entry; or, when there is an API with the same uri as the target API in the data of the local API, the gateway background updates the data of the local API with the data of the target API.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program runs, it controls the device where the computer-readable storage medium is located to execute the data processing method according to any one of claims 1 to 7.
10. A processor, characterized in that, The processor is used to run a program, wherein, when the program runs, it executes the data processing method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Open API full-life-cycle management method based on micro-service
CN111181727A
Authority management system
CN113239373A