A method, device, equipment and readable storage medium for docking system services
By obtaining the authentication permission configuration file configured in advance, directly connecting to the target system business, the problem of low system docking efficiency in the existing technology is solved, and efficient system docking without additional code is achieved.
Patent Information
- Application Number
- CN202211476368.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-11-23
AI Technical Summary
The existing system docking method requires a lot of permission adaptation work, which leads to a lot of configuration code being written in each microservice, which reduces the efficiency of system docking.
By confirming whether the user information to be authenticated meets the authentication permissions, and obtaining the configuration file corresponding to the authentication permissions configured in advance when it is met, directly connect to the target system services through the configuration file to avoid writing additional code.
It improves the efficiency of system docking, reduces the need to write configuration code, and realizes the docking of system services through unified authentication.
Smart Images

Figure CN116132094B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of system docking, and in particular, to a method, apparatus, device and readable storage medium for docking system services. Background Art
[0002] At present, the separation mode of service network permissions and system business modules is often physical separation. In use, it is necessary to add additional code to connect the system. The service calls for connecting between various microservices generally use the same authentication and authorization scheme.
[0003] The above system docking method requires a lot of permission adaptation work and requires all parties to coordinate specific development work, resulting in a large amount of configuration code to be written in each microservice, which reduces the efficiency of system docking.
[0004] Therefore, how to improve the efficiency of system docking is a technical problem that needs to be solved. Summary of the invention
[0005] The purpose of the embodiments of the present application is to provide a method for docking system services. The technical solution of the embodiments of the present application can achieve the effect of improving the efficiency of system docking.
[0006] In a first aspect, an embodiment of the present application provides a method for docking system services, including confirming whether the user information to be authenticated satisfies the authentication authority; when it is determined that the user information to be authenticated satisfies the authentication authority, obtaining a configuration file corresponding to the authentication authority, wherein the configuration file is configured in advance according to the authentication authority; and docking the target system services through the configuration file.
[0007] In the above embodiment of the present application, the user information is used to authenticate the authority, and when the authentication is passed, the configuration file required for the system service connection can be directly obtained to complete the system service connection, without writing additional code like the traditional technology, and the system service connection is performed through a unified authentication method. Therefore, the solution of the present application can achieve the effect of improving the efficiency of the system connection.
[0008] In some embodiments, after obtaining the configuration file corresponding to the authentication authority, the method further includes:
[0009] If it is determined that the user information to be authenticated does not satisfy the authentication authority, converting the user information to be authenticated into authority information that satisfies the authentication authority;
[0010] Obtaining a second configuration file corresponding to the permission information;
[0011] Connect to the target system services through the configuration file, including:
[0012] Connect to the target system service through the second configuration file.
[0013] In the above embodiments of the present application, when the user information to be authenticated does not meet the authentication authority, permission information that can meet the authentication authority can be obtained by converting the user information, and then the docking of the target system business can be completed through the permission information, thereby ensuring the accuracy of the system business docking.
[0014] In some embodiments, connecting to the target system service through the configuration file includes:
[0015] Confirm the interface parameters of the target system business from the configuration file;
[0016] Connect to the target system business through interface parameters.
[0017] In the above-mentioned embodiments of the present application, the docking of system services can be completed through the interface parameters in the configuration file, and there is no need to rewrite or change the code, thereby improving the efficiency of the system service docking.
[0018] In some embodiments, confirming whether the to-be-authenticated user information of the to-be-authenticated user satisfies the authentication authority includes:
[0019] The user information to be authenticated is authenticated through the encapsulation program to confirm whether the user information to be authenticated satisfies the authentication authority. When the user information to be authenticated is matched in the system through the encapsulation program, the user information to be authenticated satisfies the authentication authority; when the user information to be authenticated is not matched in the system through the encapsulation program, the user information to be authenticated does not satisfy the authentication authority.
[0020] In the above-mentioned embodiments of the present application, the user information to be authenticated can be accurately authenticated through the encapsulation program.
[0021] In some embodiments, confirming whether the to-be-authenticated user information of the to-be-authenticated user satisfies the authentication authority includes:
[0022] Determine whether the user information to be authenticated satisfies the authentication authority through basic information authentication, cross-domain mechanism authentication or custom authentication. If at least one of the basic information authentication, cross-domain mechanism authentication and custom authentication methods passes the authentication, the user information to be authenticated satisfies the authentication authority. If no authentication is passed in the basic information authentication, cross-domain mechanism authentication or custom authentication methods, the user information to be authenticated does not meet the authentication authority.
[0023] In the above embodiments of the present application, authentication of the user information to be authenticated can be achieved through basic information authentication, cross-domain mechanism authentication or custom authentication, thereby avoiding the failure rate of authentication and improving the efficiency of system business docking.
[0024] In some embodiments, before confirming whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority, the method further includes:
[0025] The user information to be authenticated and the authentication authority corresponding to the user information to be authenticated are stored in the system;
[0026] Configure the configuration file corresponding to the authentication authority;
[0027] The configuration files corresponding to the authentication permissions include:
[0028] Obtain the correspondence between the user information to be authenticated and the authentication authority from the system;
[0029] According to the corresponding relationship, obtain the configuration file.
[0030] In the above embodiment of the present application, the configuration file corresponding to the user information to be authenticated can be configured in advance, so that when obtaining the configuration file corresponding to the authentication authority, the configuration file can be directly obtained from the system, thereby improving the efficiency of system business docking.
[0031] In some embodiments, obtaining a configuration file corresponding to the authentication authority includes:
[0032] Obtain a custom configuration file customized by the user end or obtain a third-party configuration file corresponding to the authentication authority from a third-party packaging program.
[0033] In the above embodiments of the present application, a user-defined configuration file or a configuration file called from other encapsulation programs can be used as a target configuration file to achieve docking with the target business system, ensuring that the corresponding configuration file can be obtained when the system business is docked.
[0034] In some embodiments, connecting to the target system service through the configuration file includes:
[0035] Jump from the source system business to the target system business through the configuration file, or directly enter the target system business through the configuration file.
[0036] In the above-mentioned embodiments, the present application can realize the jump between different system services, and can also directly log in to the target business system through the interface, which is more multifunctional.
[0037] In a second aspect, an embodiment of the present application provides a device for connecting to system services, including:
[0038] A confirmation module is used to confirm whether the user information to be authenticated satisfies the authentication authority;
[0039] An acquisition module, used to acquire a configuration file corresponding to the authentication authority when it is determined that the information of the user to be authenticated meets the authentication authority, wherein the configuration file is configured in advance according to the authentication authority;
[0040] The docking module is used to dock with the target system business through the configuration file.
[0041] Optionally, the device further comprises:
[0042] A second acquisition module, configured to convert the user information to be authenticated into authority information satisfying the authentication authority after the acquisition module acquires the configuration file corresponding to the authentication authority and, if it is determined that the user information to be authenticated does not satisfy the authentication authority, the user information to be authenticated is converted into authority information satisfying the authentication authority;
[0043] Obtaining a second configuration file corresponding to the permission information;
[0044] The docking module is specifically used for:
[0045] Connect to the target system service through the second configuration file.
[0046] Optionally, the docking module is specifically used for:
[0047] Confirm the interface parameters of the target system business from the configuration file;
[0048] Connect to the target system business through interface parameters.
[0049] Optionally, the confirmation module is specifically used to:
[0050] The user information to be authenticated is authenticated through the encapsulation program to confirm whether the user information to be authenticated satisfies the authentication authority. When the user information to be authenticated is matched in the system through the encapsulation program, the user information to be authenticated satisfies the authentication authority; when the user information to be authenticated is not matched in the system through the encapsulation program, the user information to be authenticated does not satisfy the authentication authority.
[0051] Optionally, the confirmation module is specifically used to:
[0052] Determine whether the user information to be authenticated satisfies the authentication authority through basic information authentication, cross-domain mechanism authentication or custom authentication. If at least one of the basic information authentication, cross-domain mechanism authentication and custom authentication methods passes the authentication, the user information to be authenticated satisfies the authentication authority. If no authentication is passed in the basic information authentication, cross-domain mechanism authentication or custom authentication methods, the user information to be authenticated does not meet the authentication authority.
[0053] Optionally, the device further comprises:
[0054] A configuration module, used for the confirmation module to store the user information to be authenticated and the authentication authority corresponding to the user information to be authenticated in the system before confirming whether the user information to be authenticated satisfies the authentication authority;
[0055] Configure the configuration file corresponding to the authentication authority;
[0056] Wherein, the acquisition module is specifically used for:
[0057] Obtain the correspondence between the user information to be authenticated and the authentication authority from the system;
[0058] According to the corresponding relationship, obtain the configuration file.
[0059] Optionally, the acquisition module is specifically used to:
[0060] Obtain a custom configuration file customized by the user end or obtain a third-party configuration file corresponding to the authentication authority from a third-party packaging program.
[0061] Optionally, the docking module is specifically used for:
[0062] Jump from the source system business to the target system business through the configuration file, or directly enter the target system business through the configuration file.
[0063] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect are performed.
[0064] In a fourth aspect, an embodiment of the present application provides a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in the method provided in the first aspect are performed.
[0065] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the embodiments of the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0067] Figure 1 A flowchart of a method for docking system services provided in an embodiment of the present application;
[0068] Figure 2 A flowchart of a detailed method for docking system services provided in an embodiment of the present application;
[0069] Figure 3 A schematic diagram of the structure of a system for docking system services provided in an embodiment of the present application;
[0070] Figure 4 A schematic block diagram of a device for docking system services provided in an embodiment of the present application;
[0071] Figure 5 A schematic block diagram of the structure of an apparatus for docking system services provided in an embodiment of the present application. DETAILED DESCRIPTION
[0072] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0073] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0074] First, some terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0075] Sidecar: A wrapper that deploys components of an application into a separate process or container to provide isolation and encapsulation.
[0076] Istio: An open source project developed by Google, IBM, and Lyft that aims to provide a unified way to connect, secure, manage, and monitor microservices.
[0077] Jwt: (JSON Web Token) is currently the most popular cross-domain authentication solution and a Token-based authentication and authorization mechanism.
[0078] token: In computer authentication, it means a token (temporary); in lexical analysis, it means a tag.
[0079] Basic: A basic identity authentication method implemented through username and password.
[0080] Helm: is a command line tool used for local development and management of charts, chart repository management, etc.
[0081] This application is applied to the scenario of system docking, and the specific scenario is to authenticate the user's authority and directly jump to the target system business through the client or other system business.
[0082] However, the current separation mode of service network permissions and system business modules is often physically separated. In use, additional code needs to be added to connect the system. The service calls for connecting between various microservices generally use the same authentication and authorization scheme. The above system connection method requires a lot of permission adaptation work and requires all parties to coordinate specific development work, resulting in a large amount of configuration code to be written in each microservice, reducing the efficiency of system connection.
[0083] To this end, this application confirms whether the user information to be authenticated satisfies the authentication authority; when it is determined that the user information to be authenticated satisfies the authentication authority, obtains the configuration file corresponding to the authentication authority, wherein the configuration file is configured in advance according to the authentication authority; and connects the target system business through the configuration file. The authority is authenticated through user information, and when the authentication is passed, the configuration file required for the system business connection can be directly obtained to complete the system business connection, without writing additional code like traditional technology, and the system business is connected through a unified authentication method. Therefore, the solution of this application can achieve the effect of improving the efficiency of system connection.
[0084] In the embodiment of the present application, the execution entity may be a docking system business device in the docking system business system. In actual applications, the docking system business device may be electronic devices such as terminal devices and servers, which are not limited here.
[0085] Combine the following Figure 1 The method for docking system services in an embodiment of the present application is described in detail.
[0086] Please see Figure 1 , Figure 1 A flowchart of a method for docking system services provided in an embodiment of the present application, such as Figure 1 The method for docking system services shown includes:
[0087] Step 110: Confirm whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority.
[0088] Among them, the user to be authenticated can be a new user or an old user. Any user who can use the system of this application can be a user to be authenticated. The user information to be authenticated can be the user's identity information, such as name, ID number, identity number or system code. The authentication authority can be a rule for authentication to pass, including the keywords of the user information to be authenticated hitting the words in the authentication text in the authentication authority. The authentication authority can also be an instruction. When the user information to be authenticated matches some information in the system, the system will provide this instruction, indicating that the user information to be authenticated meets the authentication authority.
[0089] In some embodiments of the present application, before confirming whether the user information to be authenticated satisfies the authentication authority, Figure 1 The method shown also includes: storing the user information to be authenticated and the authentication authority corresponding to the user information to be authenticated in the system; configuring a configuration file corresponding to the authentication authority; wherein obtaining the configuration file corresponding to the authentication authority includes: obtaining the corresponding relationship between the user information to be authenticated and the authentication authority from the system; and obtaining the configuration file based on the corresponding relationship.
[0090] In the above process, the present application can configure the configuration file corresponding to the user information to be authenticated in advance, so that when obtaining the configuration file corresponding to the authentication authority, the configuration file can be directly obtained from the system, thereby improving the efficiency of system business docking.
[0091] The configuration file includes interface parameters and docking codes of multiple system services, including interface parameters of the target system service that the user to be authenticated needs to dock. Each user's user information that passes the authentication authority can correspond to a configuration file for docking different system services. The correspondence between the user information to be authenticated and the authentication authority can be a corresponding or non-corresponding relationship. If it is a corresponding relationship, the corresponding configuration file can be directly obtained.
[0092] In some embodiments of the present application, confirming whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority includes: authenticating the user information to be authenticated of the user to be authenticated through an encapsulation program, and confirming whether the user information to be authenticated satisfies the authentication authority, wherein, when the user information to be authenticated is matched in the system through the encapsulation program, the user information to be authenticated satisfies the authentication authority, and when the user information to be authenticated is not matched in the system through the encapsulation program, the user information to be authenticated does not satisfy the authentication authority.
[0093] In the above process, the present application can accurately authenticate the user information to be authenticated of the user to be authenticated through the encapsulation program.
[0094] Among them, the encapsulation program can be a sidecar program, which is used to deploy the components of the application into a separate process or container to provide isolation and encapsulation. This application encapsulates the authentication module through the encapsulation program to complete the authentication of the user information to be authenticated. The sidecar that extracts permissions has standardized definitions and parameter specifications for the authentication and authorization interface, mainly to standardize the calls and communications between different sidecars. For business processing, the sidecar will intercept the request for the proxy to process the business service and parse the user information for the request, that is, authentication.
[0095] In some embodiments of the present application, confirming whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority includes: determining whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority through basic information authentication, cross-domain mechanism authentication or custom authentication, wherein, if at least one of the basic information authentication, cross-domain mechanism authentication and custom authentication methods is authenticated successfully, the user information to be authenticated satisfies the authentication authority, and if no authentication is passed in the basic information authentication, cross-domain mechanism authentication or custom authentication methods, the user information to be authenticated does not satisfy the authentication authority.
[0096] In the above process, the present application can realize the authentication of the user information to be authenticated through basic information authentication, cross-domain mechanism authentication or custom authentication, thereby avoiding the error rate of authentication and improving the efficiency of system business docking.
[0097] Among them, basic authentication information (basic authentication) can be achieved by authenticating the user's identity information, cross-domain mechanism authentication (jwt authentication) can be achieved by authenticating the identity through other programs or third-party plug-ins, and custom authentication can be achieved by the user himself or through a custom program to authenticate the identity information.
[0098] Step 120: When it is determined that the to-be-authenticated user information satisfies the authentication authority, a configuration file corresponding to the authentication authority is obtained.
[0099] Among them, the configuration file is configured in advance according to the authentication authority.
[0100] In some embodiments of the present application, obtaining a configuration file corresponding to the authentication authority includes: obtaining a custom configuration file customized by the user end or obtaining a third-party configuration file corresponding to the authentication authority from a third-party packaging program.
[0101] In the above process, the user-defined configuration file or the configuration file called from other encapsulation programs can be used as the target configuration file to achieve the docking of the target business system, ensuring that the corresponding configuration file can be obtained when the system business is docked.
[0102] When the third-party encapsulation program authenticates the user information to be authenticated, the corresponding configuration file can be obtained. When the user information to be authenticated is authenticated again through the encapsulation program, the configuration file can be directly obtained from the third-party encapsulation program.
[0103] In some embodiments of the present application, after obtaining the configuration file corresponding to the authentication authority, Figure 1 The method shown also includes: when it is determined that the user information to be authenticated does not meet the authentication authority, converting the user information to be authenticated into authority information that meets the authentication authority; obtaining a second configuration file corresponding to the authority information; and connecting to the target system business through the configuration file, including: connecting to the target system business through the second configuration file.
[0104] In the above process, when the user information to be authenticated does not meet the authentication authority, the user information can be converted to obtain permission information that meets the authentication authority, and then the target system business can be connected through the permission information, thereby ensuring the accuracy of the system business connection.
[0105] Among them, converting the user information to be authenticated into permission information that satisfies the authentication authority includes extracting key information such as keywords and key words in the user information to be authenticated, matching the key information with the permission information stored in the system until the relevant permission information is matched, and each permission information corresponds to a configuration file, and the configuration file can be matched through the matched permission information.
[0106] Step 130: Connect to the target system service through the configuration file.
[0107] In some embodiments of the present application, connecting to the target system service through the configuration file includes: confirming interface parameters of the target system service from the configuration file; and connecting to the target system service through the interface parameters.
[0108] In the above process, the present application can complete the docking of system services through the interface parameters in the configuration file, and there is no need to rewrite or change the code, thereby improving the efficiency of system service docking.
[0109] In some embodiments of the present application, connecting to the target system service through the configuration file includes: jumping from the source system service to the target system service through the configuration file or directly entering the target system service through the configuration file.
[0110] In the above process, the present application can realize the jump between different system businesses, and can also directly log in to the target business system through the interface, which is more multifunctional.
[0111] The direct access to the target system service through the configuration file may be that the user directly accesses the target system service through a login interface of the user terminal.
[0112] In the above Figure 1 In the process shown, the present application confirms whether the user information to be authenticated satisfies the authentication authority; when it is determined that the user information to be authenticated satisfies the authentication authority, obtains the configuration file corresponding to the authentication authority, wherein the configuration file is configured in advance according to the authentication authority; and connects the target system business through the configuration file. The authority is authenticated through user information, and when the authentication is passed, the configuration file required for the system business connection can be directly obtained to complete the system business connection, without writing additional code like the traditional technology, and the system business is connected through a unified authentication method. Therefore, the solution of the present application can achieve the effect of improving the efficiency of system connection.
[0113] Combine the following Figure 2 The detailed method of docking system services in the embodiment of the present application is described in detail.
[0114] Please see Figure 2 , Figure 2 A flowchart of a detailed method for docking system services provided in an embodiment of the present application, such as Figure 2 The detailed method of docking system services shown includes:
[0115] Step 210: Input a docking request for the user system.
[0116] Specifically, the user to be authenticated inputs a connection request for the target system service through a login interface of the client.
[0117] Step 211: The load balancer forwards the connection request to the encapsulation program.
[0118] Specifically, the load balancer sends the connection request to the encapsulation program.
[0119] Step 212: The encapsulation program hijacks the traffic.
[0120] Specifically, the encapsulation program receives the connection request data sent by the load balancer.
[0121] Step 213: Encapsulate program authentication service processing.
[0122] Specifically, the encapsulation program confirms the service requested by the user.
[0123] Step 214: Obtain user information from the user center.
[0124] Specifically, the encapsulation program obtains the corresponding user information to be authenticated from the user center according to the requested service.
[0125] Step 215: Verify whether the user information is passed.
[0126] Specifically, the authentication of the user information to be authenticated is performed. If it is passed, the process proceeds to step 217 . If it is not passed, the process proceeds to step 216 .
[0127] Step 216: Return error information.
[0128] Specifically, the process proceeds to step 211 while returning an error message.
[0129] The error message may be an error in user information matching or an error in the business system requested by the user.
[0130] Step 217: Obtain authentication authority from the user center.
[0131] Specifically, obtain the authentication authority corresponding to the user information to be authenticated.
[0132] Step 218: The encapsulation program accesses the target system service.
[0133] Specifically, the encapsulation program obtains the corresponding configuration file through authentication authority and accesses the target system business through the configuration file.
[0134] Step 219: Output the result of system business connection.
[0135] Specifically, the result of whether the docking is successful is output, and the reason for the docking failure is output if the docking fails.
[0136] also, Figure 2 The specific methods and steps shown can be found in Figure 1 The methods and steps shown are not described in detail here.
[0137] Previous article Figure 1-Figure 2 Describes the method of docking system services. Figure 3 Describes the system that connects to the system business.
[0138] Combine the following Figure 3 The system for docking system services in an embodiment of the present application is described in detail.
[0139] Please see Figure 3 , Figure 3 A schematic diagram of the structure of a system for docking system services provided in an embodiment of the present application, such as Figure 3 The system for docking system services shown includes:
[0140] One or more clients send a client request. When the load balancer forwards the client request to the sidecar (encapsulation program), it needs to perform jwt authentication on the client request. After the authentication is passed, the client request enters the sidecar authentication modules in the three pods (business containers) respectively. The sidecar authentication module performs jwt authentication, basic authentication and custom authentication on the client request respectively. When the authentication is passed, the corresponding configuration file can be obtained through the sidecar authentication module linked to the istio management module, or the corresponding main business application can be connected from the configuration file stored in the system.
[0141] For example, the first step is to define the interface of the permission interface and permission adapter in sidecar. The permission interface is mainly divided into two parts: authentication and authorization. The external client calls the project through jwt authentication. In the re-authentication interface, it is necessary to obtain the target business system token and parse the user information to be authenticated according to the key and encryption algorithm configured by the system. Then determine whether the user is legal. After verifying that the user is legal, the user information needs to be packaged one step further. That is, through the call of the adapter, adapt the following service call to smoothly access the resources of the business service. The adapter interface is customized by the user. If the permission authentication scheme of the third-party business service and the system is consistent, the implementation in the adapter can use the default jwt to generate a token that can be parsed by the third-party service. For business services that use other methods to grant permissions, permission conversion can be implemented in the adapter to convert user information into authentication information that can be recognized and parsed by the service. In order to facilitate the integration of third-party services and deploy and call them more quickly, we have encapsulated common permission authentication schemes, such as jwt authentication and basic authentication. Users only need to modify the configuration information of the project in the sidecar package to make it the same as the permission configuration in the service to access it. The prerequisite for deploying a new service is to synchronize relevant user information. Generally, different business service projects will have their own user information for maintenance, so it is necessary to synchronize users to the project's users to ensure that permission conversion information is correct. The service provider needs to prepare custom implementations of relevant interfaces in the business service package and permission package. And provide relevant configuration documents. Finally, it can be deployed to the service grid system. Finally, the communication and management between sidecars is based on the customized deployment service of istio.
[0142] also, Figure 3 The specific methods and steps shown can be found in Figure 1 The methods and steps shown are not described in detail here.
[0143] Combine the following Figure 4-Figure 5 Describes the device for docking system services.
[0144] Please refer to Figure 4 , is a schematic block diagram of a device 400 for docking system services provided in an embodiment of the present application. The device 400 may be a module, program segment or code on an electronic device. The device 400 is similar to the above Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the device 400 can be found in the description below. To avoid repetition, the detailed description is appropriately omitted here.
[0145] Optionally, the device 400 includes:
[0146] Confirmation module 410, used to confirm whether the user information to be authenticated of the user to be authenticated meets the authentication authority;
[0147] The acquisition module 420 is used to acquire a configuration file corresponding to the authentication authority when it is determined that the user information to be authenticated meets the authentication authority, wherein the configuration file is configured in advance according to the authentication authority;
[0148] The docking module 430 is used to dock with the target system service through the configuration file.
[0149] Optionally, the device further comprises:
[0150] A second acquisition module, which is used for, after the acquisition module acquires the configuration file corresponding to the authentication authority, if it is determined that the user information to be authenticated does not meet the authentication authority, to convert the user information to be authenticated into authority information that meets the authentication authority; and to acquire a second configuration file corresponding to the authority information;
[0151] The docking module is specifically used for:
[0152] Connect to the target system service through the second configuration file.
[0153] Optionally, the docking module is specifically used for:
[0154] Confirm the interface parameters of the target system service from the configuration file; connect to the target system service through the interface parameters.
[0155] Optionally, the confirmation module is specifically used to:
[0156] The user information to be authenticated is authenticated through the encapsulation program to confirm whether the user information to be authenticated satisfies the authentication authority. When the user information to be authenticated is matched in the system through the encapsulation program, the user information to be authenticated satisfies the authentication authority; when the user information to be authenticated is not matched in the system through the encapsulation program, the user information to be authenticated does not satisfy the authentication authority.
[0157] Optionally, the confirmation module is specifically used to:
[0158] Determine whether the user information to be authenticated satisfies the authentication authority through basic information authentication, cross-domain mechanism authentication or custom authentication. If at least one of the basic information authentication, cross-domain mechanism authentication and custom authentication methods passes the authentication, the user information to be authenticated satisfies the authentication authority. If no authentication is passed in the basic information authentication, cross-domain mechanism authentication or custom authentication methods, the user information to be authenticated does not meet the authentication authority.
[0159] Optionally, the device further comprises:
[0160] A configuration module, used for the confirmation module to store the user information to be authenticated and the authentication authority corresponding to the user information to be authenticated in the system before confirming whether the user information to be authenticated satisfies the authentication authority; and configure a configuration file corresponding to the authentication authority;
[0161] Wherein, the acquisition module is specifically used for:
[0162] Obtain the correspondence between the user information to be authenticated and the authentication authority from the system; and obtain the configuration file based on the correspondence.
[0163] Optionally, the acquisition module is specifically used to:
[0164] Obtain a custom configuration file customized by the user end or obtain a third-party configuration file corresponding to the authentication authority from a third-party packaging program.
[0165] Optionally, the docking module is specifically used for:
[0166] Jump from the source system business to the target system business through the configuration file, or directly enter the target system business through the configuration file.
[0167] Please refer to Figure 5 5 is a schematic block diagram of a device for docking system services provided in an embodiment of the present application. The device may include a memory 510 and a processor 520. Optionally, the device may also include: a communication interface 530 and a communication bus 540. The device is similar to the above Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the device can be found in the description below.
[0168] Specifically, the memory 510 is used to store computer-readable instructions.
[0169] Processor 520 is used to process the readable instructions stored in the memory and can execute Figure 1 The steps in the method.
[0170] The communication interface 530 is used for signaling or data communication with other node devices, for example, for communication with a server or a terminal, or for communication with other device nodes, but the embodiments of the present application are not limited thereto.
[0171] The communication bus 540 is used to realize direct connection and communication among the above components.
[0172] The communication interface 530 of the device in the embodiment of the present application is used to communicate signals or data with other node devices. The memory 510 can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The memory 510 can also be at least one storage device located away from the aforementioned processor. The memory 510 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 520, the electronic device executes the aforementioned Figure 1 The method process shown. The processor 520 can be used on the device 400 and used to perform the functions in the present application. Exemplarily, the above-mentioned processor 520 can be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and the embodiments of the present application are not limited thereto.
[0173] The embodiment of the present application also provides a readable storage medium, when the computer program is executed by a processor, Figure 1 The method process in the method embodiment shown is executed by the electronic device.
[0174] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.
[0175] In summary, the embodiments of the present application provide a method, device, electronic device and readable storage medium for docking system services, the method comprising: confirming whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority; if it is determined that the user information to be authenticated satisfies the authentication authority, obtaining a configuration file corresponding to the authentication authority, wherein the configuration file is pre-configured according to the authentication authority; and docking the target system service through the configuration file. This method can achieve the effect of improving the efficiency of system docking.
[0176] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0177] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0178] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0179] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0180] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0181] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A method for connecting to system services, It is characterized in that include: Confirm whether the user information to be authenticated satisfies the authentication authority; In the case where it is determined that the information of the user to be authenticated satisfies the authentication authority, a configuration file corresponding to the authentication authority is obtained, wherein the configuration file is configured in advance according to the authentication authority, the configuration file includes interface parameters and docking codes of multiple system services, the interface parameters of the multiple system services include interface parameters of target system services that the user to be authenticated needs to dock, the authentication authority passed by the user information of each user corresponds to a configuration file, different configuration files are used to dock different system services, the correspondence between the information of the user to be authenticated and the authentication authority is a correspondence and a non-correspondence, and when the correspondence between the information of the user to be authenticated and the authentication authority is a correspondence, the configuration file is used to obtain the corresponding configuration file; Connecting to the target system service through the configuration file; After obtaining the configuration file corresponding to the authentication authority, the method further includes: if it is determined that the user information to be authenticated does not satisfy the authentication authority, converting the user information to be authenticated into authority information satisfying the authentication authority; obtaining a second configuration file corresponding to the authority information, wherein one authority information corresponds to one configuration file; The connecting to the target system service through the configuration file includes: connecting to the target system service through the second configuration file.
2. The method according to claim 1, It is characterized in that The connecting to the target system service through the configuration file includes: Confirming interface parameters of the target system service from the configuration file; The target system service is connected through the interface parameters.
3. The method according to claim 1 or 2, It is characterized in that The step of confirming whether the user information to be authenticated satisfies the authentication authority includes: The user information to be authenticated of the user to be authenticated is authenticated through an encapsulation program to confirm whether the user information to be authenticated satisfies the authentication authority, wherein, when the user information to be authenticated is matched in the system through the encapsulation program, the user information to be authenticated satisfies the authentication authority, and when the user information to be authenticated is not matched in the system through the encapsulation program, the user information to be authenticated does not satisfy the authentication authority.
4. The method according to claim 1 or 2, It is characterized in that The step of confirming whether the user information to be authenticated satisfies the authentication authority includes: Determine whether the user information of the user to be authenticated satisfies the authentication authority through basic information authentication, cross-domain mechanism authentication or custom authentication, wherein, if at least one of the basic information authentication, the cross-domain mechanism authentication and the custom authentication is authenticated, the user information to be authenticated satisfies the authentication authority, and if no authentication is passed in the basic information authentication, the cross-domain mechanism authentication or the custom authentication, the user information to be authenticated does not satisfy the authentication authority.
5. The method according to claim 1 or 2, It is characterized in that Before confirming whether the user information to be authenticated of the user to be authenticated satisfies the authentication authority, the method further includes: storing the user information to be authenticated and the authentication authority corresponding to the user information to be authenticated in a system; Configuring the configuration file corresponding to the authentication authority; Wherein, obtaining the configuration file corresponding to the authentication authority includes: Acquire the correspondence between the to-be-authenticated user information and the authentication authority from the system; According to the corresponding relationship, the configuration file is obtained.
6. The method according to claim 1 or 2, It is characterized in that The obtaining of the configuration file corresponding to the authentication authority includes: Obtain a custom configuration file customized by the user end or obtain a third-party configuration file corresponding to the authentication authority from a third-party packaging program.
7. The method according to claim 1 or 2, It is characterized in that The connecting to the target system service through the configuration file includes: The source system service is jumped to the target system service through the configuration file, or the target system service is directly entered through the configuration file.
8. A device for connecting to system services, It is characterized in that include: A confirmation module is used to confirm whether the user information to be authenticated satisfies the authentication authority; an acquisition module, configured to acquire a configuration file corresponding to the authentication authority when it is determined that the information of the user to be authenticated satisfies the authentication authority, wherein the configuration file is pre-configured according to the authentication authority, the configuration file includes interface parameters and docking codes of multiple system services, the interface parameters of the multiple system services include interface parameters of target system services that the user to be authenticated needs to dock, the authentication authority passed by the user information of each user corresponds to a configuration file, different configuration files are used to dock different system services, the correspondence between the information of the user to be authenticated and the authentication authority is a correspondence and a non-correspondence, and when the correspondence between the information of the user to be authenticated and the authentication authority is a correspondence, the module is configured to acquire the corresponding configuration file; A docking module, used for docking the target system service through the configuration file; After the acquisition module acquires the configuration file corresponding to the authentication authority, the module is further configured to: if it is determined that the user information to be authenticated does not satisfy the authentication authority, convert the user information to be authenticated into authority information satisfying the authentication authority; acquire a second configuration file corresponding to the authority information, wherein one authority information corresponds to one configuration file; The docking module is specifically used to: dock with the target system service through the second configuration file.
9. An electronic device, It is characterized in that include: A memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method according to any one of claims 1 to 7 are executed.
10. A computer-readable storage medium, It is characterized in that include: A computer program, when the computer program is run on a computer, causes the computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Micro-service interface authentication system, method and device based on Evnoy framework
CN112788031A
Data query method and device, computer equipment and storage medium
CN113961600A