Mini Program Authorization Agent Control Method, Device, Electronic Device and Storage Medium
By generating and cacheing tokens on the mini program backend, verifying their validity and directly returning authorization results, the problem of long response time of WeChat mini program authorization interface in low-frequency and high-concurrency scenarios is solved, and the performance and user experience of the authorization interface are improved.
Patent Information
- Application Number
- CN202211196754.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-29
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-09-29
AI Technical Summary
In low-frequency and high-concurrency business scenarios, the response time of the authorization interface of WeChat applets becomes longer, resulting in a decrease in functional stability and poor user experience.
By setting up an authorization proxy control system on the backend of the applet, generating and cacheing the token token, verifying its validity, and directly returning the authorization result when it is valid, and only calling the target authorization interface when it is invalid, reducing dependence on the server.
It improves the calling performance of authorized interfaces, shortens response time, improves user experience, reduces dependence on third-party interfaces, and enhances system stability.
Smart Images

Figure CN115550033B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of applets, and in particular to a method, device, electronic device, and storage medium for controlling applet authorization agents. Background Art
[0002] Currently, every time a user opens a WeChat applet, they need to call the WeChat service to remotely access the WeChat authorization service interface. In related technologies, for business scenarios with low frequency and high concurrency, the response time may become longer due to centralized access, resulting in a decline in the functional stability of the applet and a poor user experience. For example, for the health code display, the current method may cause the RT (interface response time) of the display code interface to increase during centralized display, resulting in a decline in the display performance. Summary of the Invention
[0003] The purpose of this application is to provide a method, device, electronic device, and storage medium for controlling applet authorization agents, which improves the call performance of the authorization interface, shortens the response time, and thus improves the user experience on the premise of ensuring security.
[0004] In a first aspect, the present invention provides a method for controlling applet authorization agents, which is applied to the backend of the applet; the method includes: in response to an access request initiated by the front end of the applet, verifying whether the token carried in the access request is valid; where the token is generated based on a preset token generation algorithm and cached in the local cache component of the pre-configured authorization agent control system; if it is valid, return the authorization result; if it is invalid, obtain the target authorization number and key information, call the target authorization interface based on the target authorization number and key information, and receive the authorization result returned by the target authorization interface.
[0005] In an optional implementation, when generating the token based on the preset token generation algorithm, it includes: obtaining the current timestamp and the key information cached in the local cache component; performing signature processing on the current timestamp based on the key information and a preset encryption algorithm to obtain the first signature information; generating a verification string based on the current timestamp, key information, and the first signature information, and encoding the verification string based on a preset encoding algorithm to generate the token.
[0006] In an optional implementation, verifying whether the token carried in the access request is valid includes: parsing the token based on a preset token parsing algorithm, and verifying whether the token carried in the access request is valid based on the parsing result.
[0007] In an alternative embodiment, the token carried in the access request is parsed based on a preset token parsing algorithm, and it is checked whether the token carried in the access request is valid based on the parsing result, including: decoding the token carried in the verification request based on a preset decoding algorithm to obtain a verification string; obtaining the key information cached in the local cache component, and performing signature processing on the verification string based on a preset encryption algorithm and the key information to obtain a second signature information; determining whether the first signature information and the second signature information are consistent; if so, determining that the token is valid; if not, determining that the token is invalid.
[0008] In an alternative embodiment, after determining that the token is valid, the method further includes: obtaining the expiration time information cached in the local cache component; determining whether the token has expired based on the signature timestamp and the expiration time information; wherein, the signature timestamp is the current timestamp obtained when the corresponding token is generated; if so, regenerating the token based on a preset token generation algorithm.
[0009] In an alternative embodiment, obtaining a target authorization number and key information, calling a target authorization interface based on the target authorization number and the key information, and receiving an authorization result returned by the target authorization interface, including: obtaining the target authorization number and the key information obtained by the mini-program front end through the target SDK, and sending the target authorization number and the key information to the target authorization interface; receiving the authorization result returned by the target authorization interface in response to the target authorization number and the key information; wherein, the authorization result includes user information.
[0010] In an alternative embodiment, the method further includes: generating a token based on a preset token generation algorithm, determining a target key-value pair based on the token and user information, and caching the target key-value pair; wherein, the user information at least includes OpenID, identity information, mobile phone number, and business information to be configured.
[0011] In a second aspect, the present invention provides a mini-program authorization proxy control device, which is applied to the mini-program backend; the device includes: a verification module, configured to verify whether the token carried in an access request is valid in response to an access request initiated by the mini-program front end; wherein, the token is generated based on a preset token generation algorithm and cached in the local cache component of a pre-configured authorization proxy control system; a first authorization result return module, configured to return an authorization result if it is valid; a second authorization result return module, configured to, if it is invalid, obtain a target authorization number and key information, call a target authorization interface based on the target authorization number and the key information, and receive an authorization result returned by the target authorization interface.
[0012] In a third aspect, the present invention provides an electronic device, including a processor and a memory. The memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the mini-program authorization proxy control method according to any one of the foregoing embodiments.
[0013] In a fourth aspect, the present invention provides a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions cause the processor to implement the mini-program authorization proxy control method according to any one of the foregoing embodiments.
[0014] The mini-program authorization proxy control method, device, electronic device, and storage medium provided by this application are applied to the mini-program backend. First, in response to an access request initiated by the mini-program front end, it is verified whether the token carried in the access request (generated based on a preset token generation algorithm and cached in the local cache component of a pre-configured authorization proxy control system) is valid. If it is valid, the authorization result is returned. If it is invalid, the target authorization number and key information are obtained, the target authorization interface is called based on the target authorization number and key information, and the authorization result returned by the target authorization interface is received. By verifying the token, when it is valid, the authorization result is directly returned to the front end, so there is no need to call the server for authorization every time. Only when the verification is invalid, the authorization process is entered, and the target authorization interface is called based on the target authorization number and key information for authorization. Thus, on the premise of ensuring security, the call performance of the authorization interface is improved, the response time is shortened, and the user experience is enhanced. Description of the Drawings
[0015] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0016] Figure 1 It is a flowchart of authorization in the prior art provided by an embodiment of the present application;
[0017] Figure 2 It is a structural diagram of a mini-program authorization proxy control system provided by an embodiment of the present application;
[0018] Figure 3 It is a flowchart of a mini-program authorization proxy control method provided by an embodiment of the present application;
[0019] Figure 4Flow chart of a specific mini-program authorization proxy control method provided by an embodiment of the present application;
[0020] Figure 5 Schematic diagram of an authorization sub-process provided by an embodiment of the present application;
[0021] Figure 6 Structural diagram of a mini-program authorization proxy control device provided by an embodiment of the present application;
[0022] Figure 7 Structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0023] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some but not all of the embodiments of the present application. Components of the embodiments of the present application described and illustrated herein generally may be arranged and designed in a variety of different configurations.
[0024] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but is merely representative of selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application.
[0025] It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.
[0026] Currently, when invoking WeChat services, each time a user opens a WeChat mini-program, the code is obtained through the WeChat front-end SDK and passed to the server login interface. The mini-program backend uses the code passed back by the front-end and the secret key SK issued by WeChat to the mini-program to invoke the WeChat authorization service to obtain relevant user information UI and a temporary token. After caching the information in the format of token = UI, the token is returned to the front-end. Refer to Figure 1 the original authorization process shown.
[0027] However, currently when invoking WeChat services, it is necessary to remotely access the WeChat authorization service interface. For low-frequency and high-concurrency business scenarios (such as displaying health codes), it may cause an increase in the RT (interface response time) of the health code display interface during concentrated health code displays, thereby resulting in a decline in the performance of health code display. Over-reliance on third-party interfaces will also cause a decline in the stability of the health code display function.
[0028] Based on this, the embodiments of the present application provide a mini-program authorization proxy control method, device, electronic device, and storage medium, which can improve the call performance of the authorization interface and shorten the response time on the premise of ensuring security, thereby enhancing the user experience.
[0029] The embodiments of the present application provide a mini-program authorization proxy control method, which is applied to the mini-program backend. The mini-program backend is pre-set with a mini-program authorization proxy control system. Refer to Figure 2 As shown, the mini-program authorization proxy control system at least includes a configuration database 21, a token generation and parsing component 22, a local cache component 23, and a key-value pair database 24. Among them:
[0030] The configuration database 21 is used to maintain user information and related token configuration information. The user information can at least include the following fields: WeChat openId, ID number, mobile phone number, name, and other business fields (depending on specific business requirements); the token configuration information can at least include the following fields: token expiration time (in minutes), token encryption key.
[0031] The token generation and parsing component 22 includes a preset token generation algorithm and a preset token parsing algorithm, which are respectively used to generate a token and parse the token.
[0032] The local cache component 23 is used to regularly obtain the latest token configuration information from the configuration database and perform local caching for use by the token generation and parsing component.
[0033] The key-value pair database 24 is used to cache user login information and login status.
[0034] Based on the above mini-program authorization proxy control system, the mini-program authorization proxy control method provided by the present application, refer to Figure 3 As shown, mainly includes the following steps:
[0035] Step S302, in response to an access request initiated by the mini-program front end, verify whether the token carried in the access request is valid; wherein, the token is generated based on a preset token generation algorithm and cached in the local cache component of the pre-configured authorization proxy control system;
[0036] Step S304, if it is valid, return the authorization result;
[0037] Step S306, if it is invalid, obtain the target authorization number and key information, call the target authorization interface based on the target authorization number and key information, and receive the authorization result returned by the target authorization interface.
[0038] For ease of understanding, the following provides a detailed description of the authorization proxy control method for this mini-program.
[0039] First, when generating a token based on a preset token generation algorithm, the following steps 1.1) to 1.3) may be included:
[0040] Step 1.1), obtain the current timestamp and the key information cached in the local cache component.
[0041] Step 1.2), perform signature processing on the current timestamp based on the key information and a preset encryption algorithm to obtain the first signature information. Among them, the preset encryption algorithm may include the SHA256 algorithm.
[0042] Step 1.3), generate a verification string based on the current timestamp, key information, and the first signature information, and perform encoding processing on the verification string based on a preset encoding algorithm to generate a token. Among them, the verification string may be generated by storing it in a JSON structure, and the preset encoding algorithm may include BASE64 encoding.
[0043] In one example, when the mini-program needs to obtain authorization on WeChat, it can first obtain the WeChat user OpenID and the current system timestamp T, obtain the encryption key (i.e., key information) K through the local cache component 23, encrypt the string in the format of OpenID_T using the encryption key K by SM4-EBC to obtain the signature value S, store OpenID, T, and S in the following JSON structure to generate the string JT: {"S": "#{S}", "T": "#{T}", "O": "#{OpenId}"}, and perform BASE64 encoding on JT to obtain a new token.
[0044] After obtaining the token using the preset token generation algorithm, in order to facilitate verifying whether the token in the access request is valid, and thus facilitate subsequent processing, in an optional implementation manner, when step S102 verifies whether the token carried in the access request is valid, it can parse the token based on a preset token parsing algorithm, and verify whether the token carried in the access request is valid based on the parsing result.
[0045] Specifically, parsing the token based on a preset token parsing algorithm and verifying whether the token carried in the access request is valid based on the parsing result may include the following steps in specific implementation:
[0046] Step 2.1), decode the token carried in the verification request based on a preset decoding algorithm to obtain a verification string. Among them, the preset decoding algorithm may include the BASE64 decoding algorithm.
[0047] Step 2.2), obtain the key information cached in the local cache component, and perform signature processing on the verification string based on the preset encryption algorithm and the key information to obtain the second signature information; the preset encryption algorithm may include the SM4-EBC algorithm, the SHA256 algorithm, etc.
[0048] Step 2.3), determine whether the first signature information and the second signature information are consistent;
[0049] Step 2.4), if so, determine that the token is valid;
[0050] Step 2.5), if not, determine that the token is invalid.
[0051] In an example, obtain the token, perform BASE64 decoding on the token to obtain the verification JSON string JT, obtain the encryption key (i.e., the key information) K through the local cache component 23, and use the SM4-EBC algorithm with K to encrypt T and O in JT to obtain ST (i.e., the second signature information). Compare S (the first signature information) in JT and ST (the second signature information). If they are the same, the token is valid. If they are different, return a token invalidation exception.
[0052] Further, after determining that the token is valid, the above method further includes the following steps:
[0053] Step 3.1), obtain the expiration time information cached in the local cache component;
[0054] Step 3.2), determine whether the token is invalid based on the signature timestamp and the expiration time information; among them, the signature timestamp is the current timestamp obtained when the corresponding token is generated;
[0055] Step 3.3), if so, regenerate the token based on a preset token generation algorithm.
[0056] Regarding the above Step 3.2), to determine whether the token is invalid based on the signature timestamp and the expiration time information, it can be determined by judging whether the signature timestamp T + the expiration time E > the current time N. If the judgment is true, the token verification passes and the original token is returned; if it is false, it means the token is invalid, and then a preset token generation algorithm is called to generate a new token and return it.
[0057] Further, when the token is invalid, re - authorization is required. Therefore, in one implementation, the above - mentioned steps of obtaining the target authorization number and key information, calling the target authorization interface based on the target authorization number and key information, and receiving the authorization result returned by the target authorization interface can include the following steps in specific implementation:
[0058] Step 4.1), obtain the target authorization number and key information obtained by the front - end of the applet through the target SDK, and send the target authorization number and key information to the target authorization interface. The target authorization number is an authorization number applied by the front - end page in the applet environment to the applet platform through the specified JavaScript SDK. In one example, the format can be: code = abd042kdjjike89022jdk38dufnnf.
[0059] Step 4.2), receive the authorization result returned by the target authorization interface after it responds to the target authorization number and key information; the authorization result includes user information.
[0060] In one example, the front - end obtains the code through the WeChat SDK and passes it to the back - end login interface; the login interface passes the code and the key SK issued by WeChat to the WeChat server authorization interface.
[0061] In addition, the above - mentioned method further includes:
[0062] Generate a token based on a preset token generation algorithm, determine the target key - value pair based on the token and user information, and cache the target key - value pair; the user information includes at least OpenID, identity information, mobile phone number, and business information to be configured.
[0063] In one example, user information U can be obtained, T can be generated through a preset token generation algorithm, the data can be stored in the cache database in the key - value pair format of T = U, and T can be loaded into Header(AUTH_TOKEN) and returned to the front - end.
[0064] In summary, this embodiment also provides a specific applet authorization proxy control method. In this method, the target authorization interface is the WeChat authorization interface. As shown in Figure 4 During this authorization call process, the WeChat server is not involved, so the access pressure caused by repeatedly accessing the WeChat server in the case of low - frequency and high - concurrency is avoided. This process can include the following steps:
[0065] Step 0, open the applet, and obtain the cached information T with key = authToken through the local cache of the applet. If T is not empty, go to Step 1. If it is empty, execute the authorization sub - process.
[0066] Step 1: Load T into the HTTP Header (AUTH_TOKEN) of the backend request interface and send it to the backend service along with the interface request.
[0067] Step 2: Obtain the token value in the Header (AUTH_TOKEN) of the request and pass it to the token parsing component to parse whether the token is valid (see the description of the token generation and parsing component 22). If it has expired, the interface returns a failed login verification and the authorization sub - process is executed. If the token is valid, continue to determine whether the token has expired. If it has not expired, continue with the interface call and return the original token along with the Header (AUTH_TOKEN). If it has expired, update the token (see the description of the token generation and parsing component 22). And load the new token into the Header (AUTH_TOKEN) and return it along with the interface call result.
[0068] Step 3: The front - end program gets the token returned by the backend and compares it with the local cached token. If they are inconsistent, update the local cached token.
[0069] Step 4: The front - end calls the WeChat SDK to obtain the code and calls the backend login interface through the code. Proceed to Step 5.
[0070] Step 5: The backend service calls the WeChat authorization interface through the code passed back by the front - end and the applied mini - program APP SK, and obtains the WeChat user information. Generate a new token and store the token as the key and the user information as the value in the cache database 14.
[0071] Regarding the authorization sub - process in the above steps, see Figure 5 As shown below, it may include the following steps:
[0072] Step 0: The front - end obtains the code through the WeChat SDK and passes it to the backend login interface.
[0073] Step 1: The login interface passes the code and the key SK issued by WeChat to the WeChat server authorization interface. Obtain the user information U.
[0074] Step 2: Generate T through the token generation algorithm and store the data in the cache database in the key - value pair format of T = U.
[0075] Step 3: Load T into the Header (AUTH_TOKEN) and return it to the front - end.
[0076] In summary, the mini-program authorization proxy control method provided by this application effectively improves the interface call performance in scenarios of frequent authentication by verifying the token in the access request and combining methods such as the random number signature algorithm. On the premise of ensuring security, this method also reduces the service's dependence on third-party interfaces and improves the system robustness.
[0077] Based on the above method embodiments, this application embodiment also provides a mini-program authorization proxy control device, which is applied to the mini-program backend; see Figure 6 As shown, this device mainly includes the following parts:
[0078] A verification module 62, configured to verify whether the token carried in the access request is valid in response to an access request initiated by the mini-program front end; wherein, the token is generated based on a preset token generation algorithm and cached in the local cache component of the pre-configured authorization proxy control system;
[0079] A first authorization result return module 64, configured to return an authorization result if it is valid;
[0080] A second authorization result return module 66, configured to, if it is invalid, obtain a target authorization number and key information, call a target authorization interface based on the target authorization number and key information, and receive the authorization result returned by the target authorization interface.
[0081] The mini-program authorization proxy control device provided by this application embodiment verifies the token. When it is valid, it directly returns the authorization result to the front end, so that there is no need to call the server for authorization every time. Only when the verification is invalid, it enters the authorization process and calls the target authorization interface for authorization based on the target authorization number and key information. Therefore, on the premise of ensuring security, the call performance of the authorization interface is improved, the response time is shortened, and the user experience is enhanced.
[0082] In some embodiments, when generating a token based on a preset token generation algorithm, the above device further includes: a token generation module, configured to: obtain the current timestamp and the key information cached in the local cache component; perform signature processing on the current timestamp based on the key information and a preset encryption algorithm to obtain a first signature information; generate a verification string based on the current timestamp, the key information, and the first signature information, and perform encoding processing on the verification string based on a preset encoding algorithm to generate a token.
[0083] In some embodiments, verifying whether the token carried in the access request is valid includes:
[0084] Parse the token based on a preset token parsing algorithm, and verify whether the token carried in the access request is valid based on the parsing result.
[0085] In some embodiments, the verification module 62 is further configured to: decode the token carried in the verification request based on a preset decoding algorithm to obtain a verification string; obtain the key information cached in the local cache component, and sign the verification string based on a preset encryption algorithm and the key information to obtain a second signature information; determine whether the first signature information and the second signature information are consistent; if so, determine that the token is valid; if not, determine that the token is invalid.
[0086] In some embodiments, after determining that the token is valid, the above device further includes: a judgment module, configured to: obtain the expiration time information cached in the local cache component; judge whether the token is invalid based on the signature timestamp and the expiration time information; wherein, the signature timestamp is the current timestamp obtained when the corresponding token is generated; if so, regenerate the token based on a preset token generation algorithm.
[0087] In some embodiments, the second authorization result return module 66 is further configured to: obtain the target authorization number and the key information obtained by the applet front end through the target SDK, and send the target authorization number and the key information to the target authorization interface; receive the authorization result returned by the target authorization interface in response to the target authorization number and the key information; wherein, the authorization result includes user information.
[0088] In some embodiments, the above device further includes: a key-value pair generation and caching module, configured to generate a token based on a preset token generation algorithm, determine a target key-value pair based on the token and user information, and cache the target key-value pair; wherein, the user information at least includes OpenID, identity information, mobile phone number, and service information to be configured.
[0089] The applet authorization proxy control device provided by the embodiments of the present application has the same implementation principle and technical effects as those of the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the embodiments of the applet authorization proxy control device, reference may be made to the corresponding content in the foregoing applet authorization proxy control method embodiments.
[0090] Embodiments of the present application also provide an electronic device, such as Figure 7As shown, it is a schematic structural diagram of the electronic device. Among them, the electronic device 100 includes a processor 71 and a memory 70. The memory 70 stores computer-executable instructions that can be executed by the processor 71. The processor 71 executes the computer-executable instructions to implement any one of the above-mentioned mini-program authorization proxy control methods.
[0091] In Figure 7 the illustrated embodiment, the electronic device further includes a bus 72 and a communication interface 73. Among them, the processor 71, the communication interface 73, and the memory 70 are connected through the bus 72.
[0092] Among them, the memory 70 may include a high-speed random access memory (RAM, Random Access Memory), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 73 (which can be wired or wireless), a communication connection is realized between the system network element and at least one other network element. The Internet, wide area network, local area network, metropolitan area network, etc. can be used. The bus 72 can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 72 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 7 only a single bidirectional arrow is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0093] The processor 71 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 71 or the instructions in the form of software. The above-mentioned processor 71 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or can be executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor 71 reads the information in the memory and combines its hardware to complete the steps of the small program authorization proxy control method in the foregoing embodiments.
[0094] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by the processor, the computer-executable instructions cause the processor to implement the above-mentioned small program authorization proxy control method. For the specific implementation, reference can be made to the foregoing method embodiments, and details are not described herein again.
[0095] The computer program product of the small program authorization proxy control method, device, electronic device, and storage medium provided by the embodiments of the present application includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the method described in the foregoing method embodiments. For the specific implementation, reference can be made to the method embodiments, and details are not described herein again.
[0096] Unless otherwise specifically stated, the relative steps, numerical expressions, and numerical values of the components and steps set forth in these embodiments do not limit the scope of the present application.
[0097] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.
[0098] In the description of this application, it should be noted that "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0099] In the description of this application, it should also be noted that unless otherwise clearly specified and limited, the terms "set", "install", "connect", and "couple" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific situations.
[0100] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of this application and are not intended to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of various embodiments of this application.
Claims
1. A method for controlling mini-program authorization agency, characterized in that, The method is applied to the back end of the mini program; the method includes: In response to an access request initiated by the front end of the mini program, verifying whether the token carried in the access request is valid; wherein, the token is generated based on a preset token generation algorithm and cached in the local cache component of a pre-configured authorization proxy control system; the token includes first signature information obtained by signing the current timestamp. If it is valid, return the authorization result. If it is invalid, obtain the target authorization number and key information, call the target authorization interface based on the target authorization number and key information, and receive the authorization result returned by the target authorization interface. Verifying whether the token carried in the access request is valid includes: parsing the token based on a preset token parsing algorithm, and verifying whether the token carried in the access request is valid based on the parsing result; specifically including: decoding the token carried in the access request based on a preset decoding algorithm to obtain a verification string; obtaining the key information cached in the local cache component, and signing the verification string based on a preset encryption algorithm and the key information to obtain second signature information; determining whether the first signature information and the second signature information are consistent; if so, determining that the token is valid; if not, determining that the token is invalid.
2. The small program authorization agency control method according to claim 1, wherein When generating the token based on a preset token generation algorithm, the method further includes: Obtaining the current timestamp and the key information cached in the local cache component. Signing the current timestamp based on the key information and a preset encryption algorithm to obtain first signature information. Generating a verification string based on the current timestamp, the key information, and the first signature information, and encoding the verification string based on a preset encoding algorithm to generate a token.
3. The small program authorization proxy control method according to claim 1, wherein, After determining that the token is valid, the method further includes: Obtaining the expiration time information cached in the local cache component. Judging whether the token is expired based on the signature timestamp and the expiration time information; wherein, the signature timestamp is the current timestamp obtained when the corresponding token is generated. If so, regenerate the token based on the preset token generation algorithm.
4. The small program authorization proxy control method according to claim 1, wherein Obtaining the target authorization number and key information, calling the target authorization interface based on the target authorization number and key information, and receiving the authorization result returned by the target authorization interface includes: Obtaining the target authorization number and key information obtained by the front end of the mini program through the target SDK, and sending the target authorization number and key information to the target authorization interface. Receiving the authorization result returned by the target authorization interface in response to the target authorization number and key information; wherein, the authorization result includes user information.
5. The small program authorization proxy control method according to claim 4, wherein The method further includes: Generate a token based on a preset token generation algorithm, determine a target key-value pair based on the token and the user information, and cache the target key-value pair; wherein, the user information at least includes OpenID, identity information, mobile phone number, and service information to be configured.
6. A mini-program authorization proxy control device, characterized in that, The device is applied to the back end of the applet; the device includes: A verification module, configured to verify whether the token carried in the access request is valid in response to an access request initiated by the front end of the applet; wherein, the token is generated based on a preset token generation algorithm and cached in a local cache component of a pre-configured authorization proxy control system; the token includes first signature information obtained by performing signature processing on the current timestamp. A first authorization result return module, configured to return an authorization result if it is valid. A second authorization result return module, configured to, if it is invalid, obtain a target authorization number and key information, call a target authorization interface based on the target authorization number and key information, and receive the authorization result returned by the target authorization interface. The verification module is further configured to: parse the token based on a preset token parsing algorithm, and verify whether the token carried in the access request is valid based on the parsing result; specifically including: decoding the token carried in the access request based on a preset decoding algorithm to obtain a verification string; obtaining the key information cached in the local cache component, and performing signature processing on the verification string based on a preset encryption algorithm and the key information to obtain second signature information; determining whether the first signature information and the second signature information are consistent; if so, determining that the token is valid; if not, determining that the token is invalid.
7. An electronic device, characterized in that, It includes a processor and a memory, the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the applet authorization proxy control method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are called and executed by the processor, the computer-executable instructions cause the processor to implement the applet authorization proxy control method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Business request processing method, device and system, electronic equipment and storage medium
CN110730171A
Token-based user identity auxiliary encryption method
CN110891065A
Identity verification method and device
CN112788036A