Application management method, system, device and storage medium
Patent Information
- Application Number
- CN202310118685.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-31
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-01-31
AI Technical Summary
由于业务相近,可能会出现建设功能相近的应用系统,造成资源的浪费
[0014]根据本公开提供的应用管理方法、系统、设备、介质和程序产品,基于安全框架技术对用户的登录请求以及用户角色权限进行验证,并且基于多租户技术对集成后的来自不同机构的应用系统进行统一管理,在保障了各机构应用安全性和内在逻辑隔离的同时实现了机构间的资源共享。因此,至少部分的解决了不同机构应用重复建设,用户反复登录的问题,实现了保证不同机构应用安全性的同时提升用户体验的技术效果。
Smart Images

Figure CN116028907B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of information security technology, and in particular to an application management method, system, device, medium, and program product. Background Technology
[0002] Large enterprises typically have numerous branch offices in addition to their headquarters. Both headquarters and branches usually have their own application systems, which are provided to users through a portal. Due to similar business operations, this can lead to the development of application systems with similar functions, resulting in wasted resources. Furthermore, users often need to repeatedly log in and authenticate before accessing the required application resources, leading to a poor user experience. Summary of the Invention
[0003] In view of the above problems, embodiments of this disclosure provide an application management method, system, device, medium, and program product that unifies the management of application resources of headquarters and branches, and improves user experience while ensuring application security.
[0004] According to a first aspect of this disclosure, an application management method is provided, comprising: acquiring user login verification information; determining whether the user login verification information matches pre-stored user login information based on a security framework technology; when the user login verification information matches the pre-stored user login information, querying user role and permission resources; verifying whether a user login request matches the user role and permission resources; and when the user login request matches the user role and permission resources, returning an authentication token and entering a portal page, wherein the portal page includes at least one application entry matching the user role and permissions, the application entry being set by an application deployment organization, and the application deployment organization being the same as or different from the user's organization. The user login verification information includes a user tenant identifier, the user tenant identifier having a mapping relationship with the user's organization, and the user's organization including either a branch or a head office.
[0005] According to embodiments of this disclosure, the application entry is displayed based on application attribute information, which is mapped to the application deployment organization. The application deployment organization includes the user's affiliated organization and other organizations, wherein the other organizations are branch organizations or headquarters.
[0006] According to embodiments of this disclosure, the application attribute information includes at least application launch information and application sharing information, which are set by the application deployment organization that has a mapping relationship with the application attribute information.
[0007] According to embodiments of this disclosure, the application attribute information further includes user settings information, which includes application display settings information.
[0008] According to embodiments of this disclosure, the method further includes: obtaining a user application access request, wherein the user application access request includes a user authentication token; parsing the authentication token based on a general call interface to generate user role information, wherein the user role information is used by the application to be accessed to verify the user's identity; and obtaining the access page of the application to be accessed when the application to be accessed successfully verifies the user's identity.
[0009] According to embodiments of this disclosure, the method further includes: storing frequently used information based on caching technology, wherein the frequently used information includes at least one of user login information, authentication tokens, user tenant identifiers, and user organization identifiers.
[0010] A second aspect of this disclosure provides an application management system, comprising: an acquisition module configured to acquire user login verification information; a first judgment module configured to determine whether the user login verification information matches pre-stored user login information based on a security framework technology; a query module configured to query user role and permission resources when the user login verification information matches the pre-stored user login information; a second judgment module configured to verify whether a user login request matches the user role and permission resources; and a response module configured to return an authentication token and enter a portal page when the user login request matches the user role and permission resources. The portal page includes at least one application entry matching the user role and permissions, the application entry being set by an application deployment organization, which may be the same as or different from the user's organization. The user login verification information includes a user tenant identifier, which is mapped to the user's organization, and the user's organization may be a branch or a head office.
[0011] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the methods described above.
[0012] A fourth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods described above.
[0013] The fifth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0014] Based on the application management methods, systems, devices, media, and program products provided in this disclosure, user login requests and user role permissions are verified using security framework technology. Furthermore, multi-tenancy technology enables unified management of integrated application systems from different organizations. This ensures the security and internal logical isolation of applications across organizations while achieving resource sharing between them. Therefore, it at least partially solves the problems of redundant application development and repeated user logins across different organizations, achieving the technical effect of improving user experience while ensuring the security of applications from different organizations. Attached Figure Description
[0015] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0016] Figure 1 The illustration shows an application scenario diagram of the application management method according to an embodiment of the present disclosure.
[0017] Figure 2 A flowchart illustrating an application management method according to an embodiment of this disclosure is shown schematically.
[0018] Figure 3 The flowchart illustrates a method for authentication and authorization based on a specific example of a security framework technology according to this disclosure.
[0019] Figure 4 This illustration shows a schematic diagram of how multi-tenant technology is used to implement logical management of various organizations in a specific example.
[0020] Figure 5 The flowchart illustrates a method for user permission authentication when accessing an application using a general API according to an embodiment of the present disclosure.
[0021] Figure 6 A flowchart illustrating a method for storing frequently used information based on caching technology according to an embodiment of the present disclosure is shown.
[0022] Figure 7 A schematic block diagram of an application management system according to an embodiment of the present disclosure is shown.
[0023] Figure 8 A schematic diagram illustrating the structure of an application management system according to other embodiments of the present disclosure is shown.
[0024] Figure 9 A schematic diagram illustrating the structure of an application management system according to some embodiments of the present disclosure is shown.
[0025] Figure 10A block diagram of an electronic device suitable for implementing an application management method according to an embodiment of the present disclosure is shown schematically. Detailed Implementation
[0026] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0029] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).
[0030] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision, disclosure, and application of data (including but not limited to user personal information) comply with the provisions of relevant laws and regulations, necessary confidentiality measures have been taken, and they do not violate public order and good morals.
[0031] Large enterprises typically have numerous branch offices in addition to their headquarters. Generally, both headquarters and branches have their own application systems, provided to users through portals. Typically, staff within each branch can access internal resources via the portal. Due to similar business operations, different branches may develop application systems with similar functions, leading to resource waste. Furthermore, for organizations with high information security requirements, such as banks, internal resources may belong to different systems. Users often need to repeatedly authenticate to access the required application resources, resulting in a poor user experience.
[0032] This disclosure provides an application management method, comprising: acquiring user login verification information; determining whether the user login verification information matches pre-stored user login information based on security framework technology; querying user role and permission resources when the user login verification information matches the pre-stored user login information; verifying whether a user login request matches the user role and permission resources; and returning an authentication token and entering a portal page when the user login request matches the user role and permission resources. The portal page includes at least one application entry point matching the user role and permissions, the application entry point being set by an application deployment organization, which may be the same as or different from the user's organization. The user login verification information includes a user tenant identifier, which is mapped to the user's organization, and the user's organization may be a branch or a head office.
[0033] The application management method provided in this disclosure verifies user login requests and user role permissions based on a security framework technology. Only after verification are resources matching the user's role permissions provided. These application resources can originate from multiple organizations. Multi-tenancy technology is used to uniformly manage integrated applications from different organizations, ensuring application security and internal logical isolation across organizations while achieving resource sharing between organizations and improving user experience.
[0034] Figure 1 The illustration shows an application scenario diagram of the application management method according to an embodiment of the present disclosure.
[0035] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0036] Users can interact with server 105 via network 104 using at least one of the first terminal device 101, second terminal device 102, and third terminal device 103 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, second terminal device 102, and third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0037] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0038] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0039] It should be noted that the application management method provided in this embodiment can generally be executed by server 105. Correspondingly, the application management device provided in this embodiment can generally be located in server 105. The application management method provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the application management device provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0040] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0041] The following will be based on Figure 1 The described scene, through Figures 2-6 The application management method of the disclosed embodiments will be described in detail.
[0042] Figure 2 A flowchart illustrating an application management method according to an embodiment of this disclosure is shown schematically.
[0043] like Figure 2 As shown, the application management method of this embodiment may include at least operations S210 to S230.
[0044] In operation S210, obtain user login verification information.
[0045] In operation S220, the security framework technology is used to determine whether the user login verification information matches the pre-stored user login information.
[0046] When the user login verification information matches the pre-stored user login information, operation S230 is executed.
[0047] In operation S230, query user role permissions resources.
[0048] In operation S240, verify whether the user login request matches the user role permission resource.
[0049] When the user login request matches the user role permission resource, operation S250 is executed.
[0050] When operating the S250, return to the authentication token and enter the portal page.
[0051] According to embodiments of this disclosure, user login verification information and user login information can be verification information such as username, account, and password. It is understood that user login information is pre-stored in the system and has already been verified. When the login verification information entered by the user matches the user login information, the two are successfully matched. In embodiments of this disclosure, security framework technology can be used to determine whether the user login verification information matches the pre-stored user login information. Typical security framework technologies may include the Spring Security security management framework, the Shiro security framework, etc. In embodiments of this disclosure, the Spring Security framework is preferably used to suit portal systems of large, multi-level enterprises. In embodiments of this disclosure, verification based on security framework technology includes authentication and authorization. Specifically, determining whether the user login verification information matches the pre-stored user login information authenticates the user, and verifying whether the user login request matches the user role and permission resources authorizes resource access permissions.
[0052] It should be understood that after operation S220, if the user login verification information does not match the pre-stored user login information, operation S260 can be executed.
[0053] In the S260 operation, an error message is sent, indicating that the user's login information verification failed.
[0054] Similarly, after operation S240, if the user login request does not match the user role permission resources, operation S270 can be executed.
[0055] In the S270 operation, an error message is sent, prompting the user that they do not have access rights.
[0056] Figure 3 The flowchart illustrates a method for authentication and authorization based on a specific example of a security framework technology according to this disclosure.
[0057] like Figure 3 As shown, this specific example uses Spring Security + JWT technology for its security framework. When a user logs into the organization's portal, they need to enter their username and password. The server can query the pre-built user database to check if the user exists based on the entered username and password. If the user exists, the entered username and password are compared with the user information in the database to determine if they are correct. If the user does not exist, an error interface is returned, indicating that the login information verification failed and the user needs to re-enter their username and password. To improve security, the username and password entered by the user can be encrypted, and then compared with the information pre-stored in the user database. Existing encryption algorithms can be used for encryption. When the user login verification information matches the pre-stored user login information, the user login verification is successful, and the user's role and permission resources can be queried. In this embodiment, the user login information includes the user login request. The user request can be further authorized and verified based on the security framework. Specifically, it can be queried whether the resources requested by the user match the permissions resources possessed by the user's role. If they match, an authentication token is returned to complete the authorization, and the user enters the portal page. If they do not match, an authorization failure message is displayed, indicating that the user does not have access rights. A typical authentication token is a JWT token. When a user makes other requests, they need to include the JWT-generated token in the request header. The server parses the token carried in the request to obtain the user identifier. The server looks up the user information based on the user identifier, and if the user has the necessary permissions, allows them to access the requested resource. In the embodiments of this disclosure, the portal page includes at least one application entry point that matches the user's role and permissions. It is understood that the types and number of applications displayed on the portal page will vary depending on the user's level, role, and permissions.
[0058] In the embodiments of this disclosure, multi-tenant technology is used to implement the logical management of each organization. Specifically, the user login verification information includes a user tenant identifier, which is mapped to the organization to which the user belongs. The organization to which the user belongs can be either a branch or a head office. Figure 4This illustration demonstrates a specific example of using multi-tenancy technology to implement logical management of various organizations. For example... Figure 4 As shown, taking the banking industry as an example, the user's affiliated institution can be a branch, such as branches in various regions. Each user's login verification information includes a tenant ID field. Tenants with the same tenant ID are identical within the same institution, and all information displayed is filtered based on the tenant ID. Therefore, when a user is an employee of the Beijing branch, their login verification information contains a Beijing branch tenant identifier, allowing them to access Shanghai branch data. Similarly, employees of the Shanghai branch have a Shanghai branch tenant identifier in their login verification information, enabling them to access Shanghai branch data; employees of the Guangdong branch have a Guangdong branch tenant identifier in their login verification information, allowing them to access Guangdong branch data, and so on. Furthermore, the portal page shown in the embodiments of this disclosure is integrated. The portal page includes at least one application entry point matching the user's role permissions. This application entry point is set by the application deployment organization, which may be the same as or different from the user's affiliated institution. That is, the user can access applications from their own institution and / or other institutions based on their role permissions.
[0059] The embodiments of this disclosure use multi-tenant technology to manage users from different organizations in a unified manner, displaying one or more applications from different organizations that match user roles and permissions on the same portal page. This allows for unified management of applications from different organizations while ensuring information security, avoiding resource waste and improving user experience.
[0060] In some embodiments, the application entry is displayed based on application attribute information, which is mapped to the application deployment organization. The application deployment organization includes the user's affiliated organization and other organizations, where the other organizations are branch offices or headquarters. It should be understood that the application attribute information is primarily set by the application deployment organization. In some embodiments of this disclosure, the displayed application entry includes the user's affiliated organization and other organizations, allowing users to log in through a unified login portal and access application resources from different organizations. The application entry may include a link address of the application; when a user clicks on an application, they can access the corresponding application through the link address configured in the application.
[0061] In some embodiments, the application attribute information includes at least application deployment information and application sharing information, which are set by the application deployment organization that has a mapping relationship with the application attribute information. Specifically, administrators of each branch office and the head office can set whether an application is online, whether it is shared, and which organizations can share it with, to achieve application resource sharing within the enterprise and avoid resource waste caused by redundant construction. Furthermore, information such as the application deployment organization, application launch and delaunch times, and application version information can also be set in the application attribute information to facilitate subsequent maintenance.
[0062] In some embodiments, the application attribute information further includes user settings information, which includes application display settings information. According to embodiments of this disclosure, users can customize the display of applications. For example, infrequently used applications can be set not to be displayed, thereby making the page more concise. Furthermore, users can also customize the display order and position of applications for ease of use and to improve the user experience.
[0063] In the embodiments of this disclosure, when a user's login portal page contains applications from different organizations or applications from different systems within the same organization, user authorization authentication by the corresponding organization or system is typically required when accessing the application to ensure application security. To reduce system modification costs, the embodiments of this disclosure employ a general-purpose call interface combined with security framework technology for user authorization authentication. The general-purpose call interface can be a dedicated authentication token parsing and verification interface. This general-purpose call interface can parse the authentication token contained in the user's application access request and then return the interfaces of the various organizations or systems providing the application connected to the general-purpose call interface. Therefore, this interface can be called when a user accesses various applications through the portal page to obtain the current user's identity and role information, while other permission judgment information within the application provider remains unchanged using its own logic.
[0064] Figure 5 The flowchart illustrates a method for user permission authentication when accessing an application using a general API according to an embodiment of the present disclosure.
[0065] like Figure 5 As shown, the method for user permission authentication when accessing an application using a general call interface in this embodiment includes operations S510 to S530.
[0066] In operation S510, a user application access request is obtained, wherein the user application access request includes a user authentication token.
[0067] In operation S520, the authentication token is parsed based on the general call interface to generate user role information, wherein the user role information is used by the application to be accessed to verify the user's identity.
[0068] When operating the S530, if the application to be accessed successfully verifies the user's identity, the access page of the application to be accessed is obtained.
[0069] According to embodiments of this disclosure, to alleviate database processing pressure and improve response speed, frequently used information such as dictionary data and user-used data can be stored in a cache. This frequently used information includes at least one of user login information, authentication tokens, user tenant identifiers, and user organization identifiers. Therefore, when this information is needed, it can be retrieved by querying the cache instead of the database. A typical caching technology includes Redis caching. Redis is a high-speed in-memory cache; when using Redis caching, frequently accessed content is cached in memory and retrieved directly from memory when needed. Redis supports complex data structures and is suitable for the high-concurrency scenarios of large enterprise portals in embodiments of this disclosure.
[0070] Specifically, Figure 6 A flowchart illustrating a method for storing frequently used information based on caching technology according to an embodiment of the present disclosure is shown.
[0071] like Figure 6 As shown, the method for storing frequently used information based on caching technology in this embodiment may include at least operations S610 to S620.
[0072] In operation S610, when querying the commonly used information, it is determined whether the commonly used information is stored in the cache.
[0073] When the frequently used information is not stored in the cache, operation S620 can be performed.
[0074] In operation S620, the commonly used information is queried from the database, and the commonly used information obtained from the database query is stored in the cache.
[0075] It is understood that when the frequently used information is stored in the cache, operation S630 can be performed.
[0076] In operation S630, the commonly used information is invoked.
[0077] In some specific implementations, when the system starts, basic data such as the tenant IDs of each branch are placed in a Redis cache. After a user successfully logs in, the user's basic information and token information are placed in the Redis cache. When a user operation requires the user ID or token, the corresponding information is retrieved directly from Redis.
[0078] Based on the above application management methods, this disclosure also provides an application management system. The following will combine... Figure 7 The device is described in detail.
[0079] Figure 7A schematic block diagram of an application management system according to an embodiment of the present disclosure is shown.
[0080] like Figure 7 As shown, the application management system 700 of this embodiment includes an acquisition module 710, a first judgment module 720, a query module 730, a second judgment module 740, and a response module 750.
[0081] The acquisition module 710 is configured to acquire user login verification information.
[0082] The first judgment module 720 is configured to determine whether the user login verification information matches the pre-stored user login information based on security framework technology.
[0083] The query module 730 is configured to query user role and permission resources when the user login verification information matches the pre-stored user login information. The user login verification information includes a user tenant identifier, which is mapped to the user's organization. The user's organization may be a branch or a head office.
[0084] The second judgment module 740 is configured to verify whether the user login request matches the user role permission resource.
[0085] The response module 750 is configured to return an authentication token and enter a portal page when the user login request matches the user role permission resource. The portal page includes at least one application entry that matches the user role permission. The application entry is set by the application deployment organization, which may be the same as or different from the organization to which the user belongs.
[0086] According to other embodiments of this disclosure, the application management system may further include a request receiving module, a token parsing module, and a result receiving module.
[0087] Figure 8 A schematic diagram illustrating the structure of an application management system according to other embodiments of the present disclosure is shown.
[0088] like Figure 8 As shown, in addition to the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740 and the response module 750, the application management system 700 of some other embodiments may also include a request receiving module 760, a token parsing module 770 and a result receiving module 780.
[0089] The functions of the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740, and the response module 750 can be combined with those of the other modules. Figure 7 The same applies here, so I will not repeat it further.
[0090] The request receiving module 760 is configured to obtain a user application access request, wherein the user application access request includes a user authentication token.
[0091] The token parsing module 770 is configured to parse the authentication token based on a general call interface to generate user role information, wherein the user role information is used by the application to be accessed to verify the user's identity.
[0092] The result receiving module 780 is configured to obtain the access page of the application to be accessed when the application to be accessed successfully verifies the user's identity.
[0093] According to some embodiments of this disclosure, the application management system may further include a caching module.
[0094] Figure 9 A schematic diagram illustrating the structure of an application management system according to some embodiments of the present disclosure is shown.
[0095] like Figure 9 As shown, in addition to the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740, the response module 750, the request receiving module 760, the token parsing module 770 and the result receiving module 780, the application management system 700 in some embodiments may also include a cache module 790.
[0096] The functions of the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740, the response module 750, the request receiving module 760, the token parsing module 770, and the result receiving module 780 can be combined with those of the other modules. Figure 8 The same applies here, so I will not repeat it further.
[0097] The caching module 790 is configured to store frequently used information based on caching technology. The frequently used information includes at least one of user login information, authentication token, user tenant identifier, and user's affiliated organization identifier.
[0098] According to embodiments of this disclosure, any and multiple modules among the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740, the response module 750, the request receiving module 760, the token parsing module 770, the result receiving module 780, and the caching module 790 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functionality of one or more of these modules can be combined with at least some of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740, the response module 750, the request receiving module 760, the token parsing module 770, the result receiving module 780, and the cache module 790 can be at least partially implemented as hardware circuits, such as field-programmable gate arrays (FPGAs), programmable logic arrays (PLAs), systems-on-a-chip, systems-on-a-substrate, systems-on-package, application-specific integrated circuits (ASICs), or any other reasonable means of integrating or packaging circuits, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the acquisition module 710, the first judgment module 720, the query module 730, the second judgment module 740, the response module 750, the request receiving module 760, the token parsing module 770, the result receiving module 780, and the cache module 790 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.
[0099] Figure 10 A block diagram of an electronic device suitable for implementing an application management method according to an embodiment of the present disclosure is shown schematically.
[0100] like Figure 10 As shown, an electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage portion 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0101] RAM 903 stores various programs and data required for the operation of electronic device 900. Processor 901, ROM 902, and RAM 903 are interconnected via bus 904. Processor 901 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.
[0102] According to embodiments of this disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to a bus 904. The electronic device 900 may also include one or more of the following components connected to the I / O interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 910 as needed so that computer programs read from it can be installed into the storage section 908 as needed.
[0103] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0104] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903 described above.
[0105] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the item recommendation method provided in the embodiments of this disclosure.
[0106] When the computer program is executed by the processor 901, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0107] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 909, and / or installed from a removable medium 911. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0108] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0109] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0110] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0111] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0112] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.
Claims
1. An application management method, characterized in that, include: Obtain user login verification information; Based on security framework technology, it is determined whether the user login verification information matches the pre-stored user login information; When the user login verification information matches the pre-stored user login information, query the user role and permission resources; Verify whether the user login request matches the user role and permission resources; as well as When the user login request matches the user's role and permission resources, an authentication token is returned, and the user is directed to a portal page. This portal page includes at least one application entry point that matches the user's role and permissions. This application entry point is set by the application deployment organization, which may be the same as or different from the user's organization. The application entry point is displayed based on application attribute information, which is mapped to the application deployment organization. The application deployment organization includes the user's organization and other organizations, where the other organizations are branches or headquarters. This allows the user to log in through a unified login portal and access application resources from different organizations. The user login verification information includes a user tenant identifier, which is mapped to the user's organization, including branch offices or head offices. The application attribute information includes at least application launch information and application sharing information, which are set by the application deployment organization that has a mapping relationship with the application attribute information. The method further includes: obtaining a user application access request, wherein the user application access request contains a user authentication token; parsing the authentication token based on a general call interface to generate user role information, wherein the user role information is used by the application to be accessed to verify the user's identity; and obtaining the access page of the application to be accessed when the application to be accessed successfully verifies the user's identity.
2. The method according to claim 1, wherein, The application attribute information also includes user settings information, which includes application display settings information.
3. The method according to claim 1, wherein, The method further includes: Frequently used information is stored using caching technology, including at least one of user login information, authentication tokens, user tenant identifiers, and user organization identifiers.
4. The method according to claim 3, wherein, The storage of frequently used information based on caching technology also includes: When querying the frequently used information, determine whether the frequently used information is stored in the cache; and When the frequently used information is not stored in the cache, the frequently used information is queried from the database, and the frequently used information obtained from the database query is stored in the cache.
5. An application management system, characterized in that, include: The module is configured to retrieve user login verification information. The first judgment module is configured to determine whether the user login verification information matches the pre-stored user login information based on security framework technology. The query module is configured to query user role and permission resources when the user login verification information matches the pre-stored user login information. The second judgment module is configured to verify whether the user login request matches the user role permission resource. as well as The response module is configured to return an authentication token and redirect to a portal page when a user login request matches the user's role and permission resources. The portal page includes at least one application entry point matching the user's role and permissions. This application entry point is set by an application deployment organization, which may be the same as or different from the user's organization. The application entry point is displayed based on application attribute information, which is mapped to the application deployment organization. The application deployment organization includes the user's organization and other organizations, where the other organizations are branches or headquarters. This allows users to log in through a unified login portal and access application resources from different organizations. The user login verification information includes a user tenant identifier, which is mapped to the user's organization. The user's organization can be either a branch or a head office. The application attribute information includes at least application launch information and application sharing information, which are set by the application deployment organization that has a mapping relationship with the application attribute information. The request receiving module is configured to acquire a user application access request, wherein the user application access request includes a user authentication token; the token parsing module is configured to parse the authentication token based on a general call interface to generate user role information, wherein the user role information is used by the application to be accessed to verify the user's identity; and the result receiving module is configured to acquire the access page of the application to be accessed when the application to be accessed successfully verifies the user's identity.
6. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 4.
7. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 4.
8. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Multi-tenant application integrated framework system based on micro-service architecture
CN114928460A