A source code authorization method and system based on an approval flow
Patent Information
- Application Number
- CN202211498898.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-28
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2042-11-28
AI Technical Summary
[0020] 1. In this invention, the approvers of source code authorization do not need to access the source code or grant access permissions, which greatly improves source code security and reduces the risk of source code leakage. The core of the authorization is automatically completed through the source code authorization service middleware without manual intervention.
Smart Images

Figure CN115934153B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of source code licensing technology, specifically to a source code licensing method and system based on an approval flow. Background Technology
[0002] Currently, there are several mainstream source code version control software, such as TFS (Microsoft Team Foundation Server), GitLab, and Subersion. Among them, TFS and GitLab are more frequently used within enterprises. The source code authorization provided by these software is based on users or roles / groups. When a developer needs to use a part of the source code, the administrator needs to authorize the developer through the authorization function provided by the software. Only after authorization can the developer access the source code. For security reasons, after the developer completes the development and checks in the source code, the administrator needs to revoke the authorization for the authorized source code.
[0003] Existing technologies lack source code licensing methods and systems based on approval flows. Compared to the source code licensing method and system based on approval flows of this invention, these have the following drawbacks and shortcomings:
[0004] 1. In existing technologies, source code licensing administrators have access to the source code they can license. Therefore, it is necessary for the administrator to be stable and reliable, and to sign a confidentiality agreement. However, there is still a high risk of leakage.
[0005] 2. In existing technologies, source code version control software cannot perform cross-approval authorization by multiple people through the source code management interface on a computer; it can only authorize one person at a time.
[0006] 3. In the existing technology, most source code version control software for source code authorization lacks authorization process records and authorization audit logs, which does not meet the requirements of Level 3 Information Security Protection 2.0.
[0007] 4. In existing technologies, source code authorization requires dedicated personnel. For security reasons, most small and medium-sized enterprises have their managers take on this role, which consumes a lot of the managers' time and increases management costs.
[0008] The purpose of this invention is to provide a source code licensing method and system based on an approval flow to solve the problems mentioned in the background art.
[0009] To achieve the above objectives, the present invention provides the following technical solution: a source code authorization system based on an approval flow, comprising a workflow approval system, a source code authorization service, and source code version control software. The workflow approval system is the main user interface, provided on PC and APP platforms. The source code authorization service is the core component of the entire system and also serves as middleware, enabling the connection between the workflow approval system and the source code version control software. The source code version control software is professional software for source code version control.
[0010] A source code authorization method based on an approval flow includes the following steps:
[0011] Step 1: Fill out the authorization application form;
[0012] Step Two: Approval Application Form;
[0013] Step 3: Request source code authorization;
[0014] Step 4: Perform source code authorization.
[0015] Preferably, step one is: filling out an authorization application form. Developers fill out a source code authorization application form in the workflow approval system and obtain the source code directory structure from the source code authorization service for selecting the authorized source code location in the application form. Once the application form is filled out, the approval process is triggered and the application enters the approval stage.
[0016] Preferably, in step two: approval application form, the source code administrator approves the applicant and the content of the applied source code after receiving the source code authorization application form approval task in the process approval system.
[0017] Preferably, in step three: requesting source code authorization, after the source code authorization service receives the request for source code authorization message, it automatically calls the authorization API interface of the source code version control software.
[0018] Preferably, step four involves performing source code authorization. After the source code version control software receives the API interface call request, it authorizes the source code to complete the entire authorization process.
[0019] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0020] 1. In this invention, the approvers of source code authorization do not need to access the source code or grant access permissions, which greatly improves source code security and reduces the risk of source code leakage. The core of the authorization is automatically completed through the source code authorization service middleware without manual intervention.
[0021] 2. This invention introduces a process approval system, which can flexibly define approval processes and approvers, realize complex authorization modes, and improve authorization security.
[0022] 3. In this invention, the authorization process and authorization flowchart can be easily viewed in the workflow approval system, and the authorization audit log can be viewed in the source code authorization service middleware, which fully complies with the security audit requirements of Level 3 Information Security Protection 2.0.
[0023] 4. The workflow approval system in this invention serves as the main user interface, providing an app that allows for source code authorization anytime, anywhere, with an average authorization time of no more than one minute. This saves administrators a significant amount of time. Attached Figure Description
[0024] Figure 1 This is a diagram of the source code licensing system for this invention;
[0025] Figure 2 This is a logic diagram of the source code licensing system for this invention. Detailed Implementation
[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0027] In the description of this invention, it should be noted that the terms "upper," "lower," "inner," "outer," "front end," "rear end," "both ends," "one end," and "the other end," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0028] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installed," "equipped with," "connected," etc., should be interpreted broadly. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be a connection within two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0029] Please see Figure 1 and Figure 2A source code authorization method and system based on approval flow, the source code authorization system based on approval flow includes (1) a process approval system, (2) a source code authorization service and (3) source code version control software. The (1) process approval system is the main user interface, provided on PC and APP, to realize the filling and approval of source code authorization application forms, and to trigger the (2) source code authorization service for authorization after approval. The DingTalk OA process approval is adopted. The application form is provided by the (2) source code authorization service. The application form must include at least the applicant, application time, requested source code directory, and application reason. The developer can initiate the approval process after filling it out. The source code administrator or approver approves the application in the (1) process approval system DingTalk. If the approval fails, the authorization is terminated and the approval opinion is fed back to the developer who applied. If the approval is successful, the source code authorization service in the (2) source code authorization service is automatically called. The (2) source code authorization service It is the core component of the entire system and also a middleware. It realizes the connection between (1) the process approval system and (3) the source code version control software, provides source code directory structure service and source code authorization service, and unifies the API interface of various version control software of (3) source code version control software; realizes the connection between (1) the process approval system and (3) the source code version control software; the (3) source code version control software is a professional source code version control software, which adopts commonly used third-party systems such as TFS, SVN, GitLab, etc. The source code version control software will provide the source code directory structure API interface, but all need to perform identity authentication. Therefore, a function is designed in (2) source code authorization service to set a certain account and password of (3) source code version control software and store it in encryption. This account has the ability to query all source code directories and authorize all directories. In principle, this account is set by the source code supervisor during system initialization.
[0030] Figure 2 The source code authorization method based on approval flow includes the following steps:
[0031] Step 1: Fill out the authorization application form. The developer fills out the source code authorization application form in the workflow approval system and obtains the source code directory structure from the source code authorization service to select the authorized source code location in the application form. Once the application form is filled out, the approval process is triggered and the application enters the approval stage.
[0032] Step 2: Approval of the application form. After receiving the source code authorization application form approval task in the workflow approval system, the source code administrator approves the applicant and the content of the requested source code. If the administrator does not approve, the authorization is terminated and the applicant is informed of the reason; if the administrator approves, the source code authorization service is triggered to initiate a request for source code authorization.
[0033] Step 3: Request source code authorization. After receiving the request for source code authorization message, the source code authorization service automatically calls the authorization API interface of the source code version control software.
[0034] Step 4: Perform source code authorization. After the source code version control software receives the API interface call request, it authorizes the source code to complete the entire authorization process.
[0035] Example 1:
[0036] S1. Workflow Approval System: Using DingTalk, it provides flexible and customizable OA approval functions and highly open API interfaces. Approval customization includes two parts: workflow customization and form customization. It can realize complex approval processes through its powerful workflow customization function. However, the approval forms required by this invention need to obtain the source code directory structure from the source code version control software. Its form customization function cannot meet the requirements. Therefore, form customization needs to be developed and implemented in the source code licensing service.
[0037] S2, Source Code Licensing Service: The core middleware developed by the developer, providing approval form service, source code directory service, and source code licensing service.
[0038] S3. Source code version control software: It adopts TFS (Microsoft Team Foundation Server), which provides powerful source code management capabilities and is the first choice for the .NET technology system.
[0039] Example 2:
[0040] S1. Source code version control software provides API interfaces for source code directory structure, but all of them require identity authentication. Therefore, a function is designed in the source code authorization service to set an account and password for the source code version control software and store them in encryption. This account has the ability to query all source code directories and authorize all directories. In principle, this account is set by the source code manager during system initialization.
[0041] S2. Initiate source code authorization application: The workflow approval system in the workflow approval system adopts DingTalk OA workflow approval. The application form is provided by the source code authorization service. The application form should at least include the applicant, application time, source code directory to be authorized (obtain source code directory for selection), and reason for application. Once the developer has filled in the form, the approval process can be initiated.
[0042] S3. Approve source code authorization applications: The source code administrator or approver approves the application in the DingTalk workflow approval system. If the approval fails, the authorization is terminated and the approval comments are fed back to the developer who applied. If the approval is successful, the source code authorization service in the source code authorization service is automatically invoked.
[0043] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A source code licensing method based on approval flow, characterized in that: The system includes (1) a workflow approval system, (2) a source code authorization service, and (3) a source code version control software. The (1) workflow approval system is the main user interface, available on PC and APP. The (2) source code authorization service is the core component of the entire system and also a middleware that enables the connection between the (1) workflow approval system and the (3) source code version control software. The (3) source code version control software is a professional source code version control software that provides an API interface for the source code directory structure. It requires identity authentication. The source code authorization service is designed with a function to set a certain account and password for the source code version control software and stores it in encryption. This account has the ability to query all source code directories and authorize all directories. This account is set by the source code manager during system initialization. The method includes the following steps: Step 1: Fill out the authorization application form. Developers fill out the source code authorization application form in the (1) workflow approval system and obtain the source code directory structure from the (2) source code authorization service for the application form to select the authorized source code location. Once the application form is filled out, the approval process is triggered and the approval process begins. Step 2: Approval of application form. After receiving the source code authorization application form approval task in the (1) process approval system, the source code administrator approves the applicant and the content of the applied source code. Step 3: Request source code authorization. After receiving the request for source code authorization message, the source code authorization service automatically calls the authorization API interface of the source code version control software. Step 4: Perform source code authorization. After the source code version control software receives the API interface call request, it authorizes the source code to complete the entire authorization process.
Citation Information
Patent Citations
On-line code inspection system and method
CN103677831A
Code management control method and system
CN107463371A