A smooth upgrade method for IPPBX authorization mode, terminal device and medium
By constructing reauthorization flag parameters and authorization type parameters in the IPPBX third-party docking module, the user data and binding relationship are retained when the authorization method is replaced, the problem of data loss caused by the replacement of the authorization method in the prior art is solved, and the smooth upgrade capability of the IPPBX third-party docking module is realized.
Patent Information
- Application Number
- CN202310384273.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-11
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2043-04-11
AI Technical Summary
When the existing IPPBX third-party docking module is replaced with authorization mode, the user data and binding relationship are lost, and the smooth upgrade cannot be achieved, and the smooth upgrade of different authorization modes cannot be dealt with.
By constructing reauthorization flag parameters and authorization type parameters, the third-party docking module retains the original data and binding relationship after the user enters the reauthorization instruction, and operates normally under the new authorization mode. The specific steps include constructing the reauthorization flag parameters and authorization type parameters, receiving the reauthorization instructions entered by the user, sending the authorization code request instruction to the third-party server, obtaining the refresh token and refreshing the access token, verifying the reauthorization flag parameters, retaining the data and binding relationship, updating the authorization type parameters, and notifying the front-end to complete the authorization method switching.
It realizes that the original docking data required by the user is retained after the user is re-authorized, avoids the loss of data and binding relationships, ensures the normal operation of the IPPBX third-party docking module under the new authorization method, and provides the ability to smoothly upgrade.
Smart Images

Figure CN116405291B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and particularly to a method for smooth upgrade of IPPBX authorization mode, a terminal device, and a medium. Background Art
[0002] IPPBX is an enterprise telephone system based on Internet protocol, which can integrate multiple communication methods and has new working methods such as remote work and mobile work. The third-party docking module is a module on Yeastar IPPBX specifically for docking with third-party services (such as docking with Microsoft, docking with ZOHO, etc.). OAuth2 is an authorization protocol used to allow an application to access third-party services in the name of a user, improving the security and user experience of the application.
[0003] Client credential authorization is an authorization method in the OAuth2 protocol, which is applicable to applications that need to access their own resources without user authentication. In client credential authorization, the client sends a request to the authorization server using its own authentication information (client ID and client password) to obtain an access token. Client credential authorization is usually used for authentication and authorization between applications. For example, protecting the API of an application so that only other specific applications can access it. This method can avoid direct user participation in the authorization process, simplify the authorization process, and improve security. In client credential authorization, the client first registers with the authorization server and obtains a client ID and a client password. Then, the client uses this information to send a request to the authorization server to request an access token. If the authorization server validates the client's identity information as valid, it will return an access token. In subsequent API requests, the client passes this access token as an authentication credential to the API server to obtain access to protected resources.
[0004] The Authorization Code Grant is another authorization method in the OAuth2 protocol, which is applicable to scenarios where OAuth2 needs to be used in applications with higher security requirements. In the Authorization Code Grant, the user clicks the login button in the client application, and the client application redirects the user to the authorization server to obtain an authorization code. After obtaining the authorization code, the client application sends a request to the authorization server using the authorization code to obtain an access token. The authorization server verifies the validity of the authorization code and returns the access token to the client application. The advantage of the Authorization Code Grant method is that it requires the user to authenticate on the authorization server to obtain the authorization code. This can ensure that the user's credentials (such as username and password) will not be leaked in the client application. At the same time, the authorization code can only be used once and has a short validity period, so the security is higher. The Authorization Code Grant method requires the support of the authorization server and requires multiple HTTP requests, so the authorization process is relatively complex. However, for applications with security requirements, this method is one of the most commonly used authorization methods.
[0005] The current third-party docking module of the IPPBX has the following technical defects:
[0006] (1) Incomplete functions after docking, unable to meet specific user needs: Most of the third-party docking modules of IPPBX on the market currently only support one authorization method, either using client credential authorization or using authorization code authorization. However, due to security considerations of the third-party server, the permissions of client credential authorization and authorization code authorization are different. Some data is only supported for applications that obtain it through client credential authorization, while some data is only supported for users who obtain it through authorization code authorization. This causes IPPBX manufacturers to have to make a choice between the two, and some data cannot be obtained, resulting in the inability to realize functions normally.
[0007] (2) After changing the authorization method, it is necessary to re-dock, and the user's old data and binding relationships are lost, resulting in a poor experience: Even if some IPPBX manufacturers support authorization changes, they must first cancel the docking and then re-authorize and dock. This will cause the data or binding relationships that the user originally synchronized from the third party to be cleared, and the user needs to re-synchronize, unable to achieve smooth upgrade.
[0008] (3) Insufficient scalability: Unable to handle the smooth upgrade of different authorization modes. Smooth upgrade means retaining the original docking data required by IPPBX users and not affecting the normal operation of the functions of the IPPBX third-party docking module under the new authorization method. Summary of the Invention
[0009] In order to solve the above problems, the present invention proposes a method, a terminal device and a medium for smooth upgrade of IPPBX authorization methods.
[0010] The specific solution is as follows:
[0011] A method for smooth upgrade of IPPBX authorization mode, comprising the following steps:
[0012] S1: Construct a re-authorization flag parameter and an authorization type parameter;
[0013] S2: When the third-party docking module receives the re-authorization instruction input by the user, set the re-authorization flag parameter to true;
[0014] S3: Based on the authorization information required in the re-authorization instruction, the third-party docking module sends an authorization code request instruction to the third-party server;
[0015] S4: After receiving the authorization code sent by the third-party server, the third-party docking module obtains a refresh token based on the authorization code, refreshes the access token based on the refresh token, and stores the refreshed access token in the database;
[0016] S5: The third-party docking module verifies the value of the re-authorization flag parameter. If it is true, after retaining the data and binding relationship during the previous authorization, it is initialized. After the initialization is completed, the re-authorization flag parameter is set to false;
[0017] S6: After the third-party docking module updates the authorization type parameter, it notifies the front end that the authorization mode switch is completed;
[0018] S7: After receiving the notification that the authorization mode switch is completed, the front end enables or disables the corresponding function according to the authorization type parameter.
[0019] Furthermore, the way for the user to input the re-authorization instruction is to construct a button for sending the re-authorization instruction on the Web interface of the third-party docking module of the IPPBX. After clicking the button, an interface for inputting the authorization information required appears. After the user inputs the authorization information required in the pop-up interface and clicks the button to confirm re-authorization, the sending of the re-authorization instruction is completed.
[0020] Furthermore, the interface for inputting the authorization information required also includes a button for canceling re-authorization. When the user clicks the button for canceling re-authorization, the third-party docking module sets the re-authorization flag parameter to false.
[0021] Furthermore, the authorization information required includes the client ID and the client password.
[0022] An IPPBX authorization method for smoothly upgrading terminal devices, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method described above in the embodiments of the present invention are implemented.
[0023] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the method described above in the embodiments of the present invention are implemented.
[0024] With the above technical solution, the present invention can still retain the original docking data required by the user and does not affect the normal operation of the IPPBX third-party docking module under the new authorization method after the user re-authorizes. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 The flowchart of Embodiment 1 of the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] To further illustrate the embodiments, the present invention provides drawings. These drawings are part of the disclosure of the present invention, mainly used to illustrate the embodiments, and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention.
[0027] The present invention will be further described below in conjunction with the drawings and specific embodiments.
[0028] Embodiment 1:
[0029] The embodiment of the present invention provides an IPPBX authorization method for smooth upgrade, as Figure 1 shown, the method includes the following steps:
[0030] S1: Construct a re-authorization flag parameter reoauth2_flag and an authorization type parameter oauth2_type.
[0031] S2: When the third-party docking module receives a re-authorization instruction input by the user, set the re-authorization flag parameter reoauth2_flag to true.
[0032] The way for the user to input the re-authorization instruction can be to construct a button for sending a re-authorization instruction (the re-authorization instruction is used to change the current authorization method, such as changing from client credential authorization to authorization code authorization) on the Web interface of the third-party docking module of the IPPBX. After clicking the button, an interface for inputting the information required for authorization pops up. After the user inputs the information required for authorization in the popped-up interface and clicks the button to confirm re-authorization, the sending of the re-authorization instruction is completed.
[0033] When the reauthorization flag parameter reoauth2_flag is true (true), it indicates reauthorization, and when it is false (false), it indicates no reauthorization.
[0034] Furthermore, the interface for inputting authorization information also includes a button for canceling reauthorization. The user can cancel reauthorization in this pop-up interface. That is, when the user clicks the button for canceling reauthorization, at this time, the third-party docking module sets the reauthorization flag parameter reoauth2_flag to false.
[0035] S3: The third-party docking module sends an authorization code request instruction to the third-party server based on the authorization information included in the reauthorization instruction.
[0036] In this embodiment, it is set that the authorization information includes the client ID and the client password. After the third-party server verifies the authorization information, it sends an authorization code to the third-party docking module of the IPPBX.
[0037] S4: After the third-party docking module receives the authorization code sent by the third-party server (such as Microsoft, Zoho, etc.), it obtains the refresh token refresh_token based on the authorization code (the refresh token refresh_token is used to periodically refresh the access token access_token), and refreshes the access token access_token based on the refresh token refresh_token, and stores the refreshed access token access_token in the database.
[0038] S5: The third-party docking module checks the value of the reauthorization flag parameter reoauth2_flag. If it is true, it initializes after retaining the data and binding relationship during the previous authorization. After the initialization is completed, the reauthorization flag parameter reoauth2_flag is set to false.
[0039] In this embodiment, there are two types of binding relationships: (1) the binding relationship between the extension and the user; (2) the binding relationship between the enterprise contact group and the shared mailbox of the third party. Since the binding relationship will be unbound during reauthorization, in this embodiment, the binding relationship is retained when the reauthorization flag parameter reoauth2_flag is true.
[0040] Initialization is to update the basic data required for re-binding.
[0041] S6: After the third-party docking module updates the authorization type parameter oauth2_type, it notifies the front end that the authorization method switching is completed.
[0042] The authorization type parameter oauth2_type needs to be updated to the authorization type at the time of reauthorization.
[0043] S7: After the front end receives the notification that the authorization method switch is completed, it enables or disables the corresponding function according to the authorization type parameter oauth2_type.
[0044] Based on the standard oauth2 protocol, the embodiment of the present invention provides a solution for the smooth upgrade of the client credential flow to the authorization code flow through a third-party docking module on the IPPBX, which not only meets the new functional requirements of users but also retains the original data.
[0045] The embodiment of the present invention has the following technical effects:
[0046] 1. The authorization method can be switched according to user needs: When the user initially uses the client credential authorization and now wants to switch to the authorization code authorization mode, there is no need to cancel the docking. The IPPBX front end will provide a switch button, and only the data required for authorization such as the client ID and client password need to be input.
[0047] 2. The original data is retained and there is no need for re-synchronization: After the user reauthorizes, the original data and binding relationships will not be cleared, and the user does not need to spend a lot of time re-synchronizing the data.
[0048] 3. Strong versatility: According to this framework, any future authorization upgrade based on oauth2 such as implicit authorization or password authorization for users can be smoothly upgraded, reducing the workload of IPPBX developers.
[0049] Embodiment 2:
[0050] The present invention also provides an IPPBX authorization method smooth upgrade terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above method embodiment of Embodiment 1 of the present invention are implemented.
[0051] Further, as an executable solution, the terminal device for smooth upgrade of the IPPBX authorization method may be a computing device such as a desktop computer, a notebook, or a palm computer. The terminal device for smooth upgrade of the IPPBX authorization method may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the composition structure of the above terminal device for smooth upgrade of the IPPBX authorization method is only an example of the terminal device for smooth upgrade of the IPPBX authorization method, and does not constitute a limitation on the terminal device for smooth upgrade of the IPPBX authorization method. It may include more or fewer components than the above, or combine some components, or different components. For example, the terminal device for smooth upgrade of the IPPBX authorization method may further include input / output devices, network access devices, a bus, etc. The embodiments of the present invention do not make any limitations thereto.
[0052] Further, as an executable solution, the so-called processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device for smooth upgrade of the IPPBX authorization method, and connects various parts of the entire terminal device for smooth upgrade of the IPPBX authorization method through various interfaces and lines.
[0053] The memory can be used to store the computer programs and / or modules. The processor realizes various functions of the terminal device for smooth upgrade of the IPPBX authorization method by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0054] The present invention also provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements the steps of the above-mentioned method of the embodiments of the present invention.
[0055] If the module / unit integrated in the terminal device for the smooth upgrade of the IPPBX authorization method is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned method embodiments of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), and software distribution medium, etc.
[0056] Although the present invention has been specifically shown and described in conjunction with the preferred embodiments, those skilled in the art should understand that various changes can be made to the present invention in terms of form and details without departing from the spirit and scope of the present invention defined by the appended claims, and all such changes are within the protection scope of the present invention.
Claims
1. A smooth upgrade method for IPPBX authorization mode, Characterized in that: It includes the following steps: S1: Construct a re-authorization flag parameter and an authorization type parameter; S2: When the third-party docking module receives the re-authorization instruction input by the user, set the re-authorization flag parameter to true; S3: The third-party docking module sends an authorization code request instruction to the third-party server based on the authorization required information included in the re-authorization instruction; S4: After the third-party docking module receives the authorization code sent by the third-party server, obtain a refresh token based on the authorization code, and refresh the access token based on the refresh token, and store the refreshed access token in the database; S5: The third-party docking module verifies the value of the re-authorization flag parameter. If it is true, initialize after retaining the data and binding relationship during the previous authorization. After the initialization is completed, set the re-authorization flag parameter to false; S6: After the third-party docking module updates the authorization type parameter, notify the front end that the authorization mode switch is completed; S7: After receiving the notification that the authorization mode switch is completed, the front end enables or disables the function corresponding to the third-party docking module according to the authorization type parameter.
2. The smooth upgrade method for IPPBX authorization mode according to claim 1, Characterized in that: The way for the user to input the re-authorization instruction is: construct a button for sending the re-authorization instruction on the Web interface of the third-party docking module of the IPPBX. After clicking the button, a interface for inputting the authorization required information pops up. After the user inputs the authorization required information in the popped-up interface and clicks the button to confirm re-authorization, the sending of the re-authorization instruction is completed.
3. The smooth upgrade method for IPPBX authorization mode according to claim 2, Characterized in that: The interface for inputting the authorization required information further includes a button for canceling re-authorization. When the user clicks the button for canceling re-authorization, the third-party docking module sets the re-authorization flag parameter to false.
4. The smooth upgrade method for IPPBX authorization mode according to claim 1, Characterized in that: The authorization required information includes a client ID and a client password.
5. An IPPBX authorization mode smooth upgrade terminal device, Characterized in that: It includes a processor, a memory, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
6. A computer-readable storage medium, the computer-readable storage medium stores a computer program, Characterized in that: When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Method for establishing dynamic authorization code based on identity authentication
CN104104672A
Token protection method, authorization system, device, and program recording medium
WO2020166066A1