Front-end code publishing, resource access method, device, equipment and application system

CN119182556BActive Publication Date: 2026-09-29PEOPLE'S INSURANCE COMPANY OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411108228.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-13
Publication Date
2026-09-29
Estimated Expiration
2044-08-13

AI Technical Summary

Technical Problem

[0007]本申请实施例提供一种前端代码发布、资源访问方法、装置、设备及应用系统,用以解决现有技术中存在的如何避免应用系统数据泄露的问题

Benefits of technology

本申请将实现第一路由项的第一前端代码拆分出来,且将第一前端代码部署在隔离区。由于第一路由项对应为外网客户端访问资源的访问路径,对应的,第一前端代码仅为实现外网客户端资源访问的实现代码,因此,从外网客户端仅能获取到自身资源访问所需的前端代码,避免了仅内网客户端用户能够获知的数据的泄露,提高了应用系统数据的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119182556B_ABST
    Figure CN119182556B_ABST
Patent Text Reader

Abstract

The application discloses a front-end code publishing, resource accessing method, device, equipment and application system, and aims at solving the problem of how to avoid data leakage of the application system in the prior art. The publishing method comprises the following steps: acquiring a first routing item used for indicating an access path of a first resource; acquiring a first front-end code used for implementing the first routing item; and deploying the first front-end code to an isolated area. The first front-end code implementing the first routing item is split out and deployed in the isolated area. Since the first front-end code is only an implementation code for realizing resource access of an external network client, the external network client can only acquire the front-end code required for resource access, so that the leakage of data that can be acquired only by the internal network client user is avoided, and the security of the data of the application system is improved. For an interface calling request sent by a client, a request source identifier is added, and the access authority of the client is limited based on the identifier, so that the security of the data is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of software development, and in particular to a front-end code publishing, resource access method, apparatus, device, and application system. Background Technology

[0002] An application system refers to a software system that can meet specific business and user needs. It completes predefined tasks by interacting with hardware devices.

[0003] The front-end code of an application system refers to the code that runs on the user's device (e.g., the application system client) and is used to create or render the display page of the application system front-end and to implement user interaction.

[0004] In the existing technology, for the same application system that supports access from both intranet clients and extranet clients, the two types of clients use the same set of front-end code. That is, the same set of front-end code contains both the implementation code for rendering and presenting the display pages of extranet clients and the implementation code for rendering and presenting the display pages of intranet clients.

[0005] To improve the loading efficiency of the application system's front-end display page, the front-end code is usually stored in the client cache. However, this makes it easy to retrieve the front-end code: for example, the front-end code can be easily retrieved from the client cache.

[0006] Given easy access to the front-end code, if high-level privileges are obtained through illegal means such as attacks or eavesdropping (e.g., obtaining the username and login password of an intranet client user), the front-end code can be run on an external client to display the intranet client's page. Furthermore, the external client can obtain the routing information contained in the front-end code and access the resources at the URL corresponding to the page component (such as a button) based on the mapping between the page component (such as a button) and the URL (Uniform Resource Locator) specified in the routing information. This results in the leakage of important / sensitive data in the resource that only intranet client users have the right to access. Summary of the Invention

[0007] This application provides a front-end code publishing and resource access method, apparatus, device, and application system to solve the problem of how to avoid application system data leakage in the prior art.

[0008] The embodiments of this application adopt the following technical solutions: A method for deploying front-end code, comprising: Obtain a first routing entry that specifies the access path to the first resource; the first resource is a resource in the application system that can be accessed by external network clients. Obtain the first front-end code used to implement the first route item; The first front-end code is deployed to an isolation zone so that the external network client can obtain the first front-end code from the isolation zone; the isolation zone is a network area located between the internal network and the external network; the internal network is the local area network where the application system's server and back-end database are located; the external network is any network other than the local area network.

[0009] A resource access method based on the aforementioned front-end code publishing method, the resource access method comprising: Send a resource access request to the application system, the resource access request including interface call requests and static resource requests; causing the application system to execute: A request source identifier is added to the interface call request, and the interface call request with the added request source identifier is forwarded to the gateway device; the static resource request is forwarded to the front-end server; wherein the interface call request contains the target interface information to be called; the gateway device obtains the request source identifier from the interface call request with the added request source identifier; generates an authentication request containing the request source identifier; and sends the authentication request and the interface call request received by the gateway device to the user center device; the user center device determines whether the client has the permission to call the target interface based on the target interface information contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied the right to call the target interface; Display the return result of the resource access request.

[0010] An application system includes a reverse proxy server, a gateway device, and a user center device. The reverse proxy server is used to receive interface call requests and static resource requests sent by the client of the application system; add a request source identifier to the interface call request and forward the interface call request with the added request source identifier to the gateway device; and forward the static resource request to the front-end server; wherein, the interface call request contains information about the target interface to be called; A gateway device is used to obtain a request source identifier from an interface call request with an added request source identifier; generate an authentication request containing the request source identifier; and send the authentication request and the interface call request received by the gateway device to the user center device. The user center device is used to determine whether the client has permission to call the target interface based on the information of the target interface contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied from calling the target interface.

[0011] A front-end code deployment device, comprising: The first routing item information acquisition unit is used to acquire a first routing item that indicates the access path of the first resource; the first resource is a resource in the application system that can be opened to external network clients for access. The first front-end code acquisition unit is used to acquire the first front-end code used to implement the first routing item; A deployment unit is configured to deploy the first front-end code to an isolation zone, so that the external network client can obtain the first front-end code from the isolation zone; the isolation zone is a network area located between an internal network and an external network; the internal network is the local area network where the application system's server and back-end database are located; the external network is any network other than the local area network.

[0012] A resource access device based on the aforementioned front-end code publishing method includes: The request sending unit is used to send interface call requests and static resource requests to the application system, causing the application system to execute: A request source identifier is added to the interface call request, and the interface call request with the added request source identifier is forwarded to the gateway device; the static resource request is forwarded to the front-end server; wherein the interface call request contains the target interface information to be called; the gateway device obtains the request source identifier from the interface call request with the added request source identifier; generates an authentication request containing the request source identifier; and sends the authentication request and the interface call request received by the gateway device to the user center device; the user center device determines whether the client has the permission to call the target interface based on the target interface information contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied the right to call the target interface; The results display unit is used to display the return results of call requests and static resource requests.

[0013] A computing device includes: a memory and a processor, wherein, The memory is used to store computer programs; The processor, coupled to the memory, is used to execute the computer program stored in the memory for performing the methods described above.

[0014] A computer-readable storage medium storing a computer program that, when executed by a computer, enables the implementation of the above-described method.

[0015] A computer program product includes a computer program that, when executed by a processor, implements the above-described method.

[0016] The above-described technical solutions adopted in the embodiments of this application can achieve the following beneficial effects: This application separates the first front-end code that implements the first routing item and deploys it in an isolated area. Since the first routing item corresponds to the access path for external clients to access resources, the corresponding first front-end code is only the implementation code for external clients to access resources. Therefore, external clients can only obtain the front-end code required for their own resource access, avoiding the leakage of data that only internal client users can access, and improving the security of application system data. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 A flowchart illustrating the specific implementation of a front-end code deployment method provided in this application embodiment; Figure 2 This is a schematic diagram of the front-end code deployment framework provided in the embodiments of this application; Figure 3 A flowchart illustrating a specific implementation of a resource access method provided in this application embodiment; Figure 4 This application provides a schematic diagram of the structure of an application system according to an embodiment of the present application. Figure 5 A specific schematic diagram of a front-end code publishing device provided in an embodiment of this application; Figure 6 This is a schematic diagram of the specific structure of a resource access device provided in an embodiment of this application; Figure 7 This is a schematic diagram of the specific structure of a computing device provided in an embodiment of this application. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0019] As will be known to those skilled in the art, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0020] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.

[0021] To address the problem of preventing application system data leakage in existing technologies, one embodiment of this application provides a front-end code deployment method.

[0022] The subject executing this method can be any computing device capable of implementing the method, such as a server, mobile phone, personal computer, smart wearable device, smart robot, etc.

[0023] Furthermore, the embodiments of this application do not limit the execution order of different steps. When using the method provided in the embodiments of this application, the execution order of different steps can be adjusted according to actual needs.

[0024] For ease of description, the following uses a front-end code publishing device as the execution subject of this method to provide a detailed description of the method provided in the embodiments of this application.

[0025] like Figure 1 The diagram shown is a flowchart illustrating the specific implementation of a front-end code deployment method provided in this application embodiment, including the following steps 11 to 13: Step 11: Obtain the first routing entry that specifies the access path to the first resource.

[0026] The first resource refers to the resources in the application system that can be accessed by external network clients. Routing entries are navigation links for pages or components within an application system, defining the access paths to resources that users can access. These access paths include URL paths, as well as the page content and components associated with each URL path. The implementation of routing entries typically relies on front-end frameworks or libraries, such as Vue.js and React (two front-end JavaScript frameworks). These frameworks provide routing management functionality, allowing developers to easily manage page navigation within their application systems.

[0027] The first routing entry defines the access paths for resources that the application system can expose to external network clients.

[0028] It should be noted that the two types of clients mentioned in this application—"internal network client" and "external network client"—are determined based on the network environment in which the client is located; specifically: a client installed in an external network environment is an external network client, and a client installed in an internal network environment is an internal network client.

[0029] The network environment involved in this application includes internal network environment and external network environment. Among them, the internal network is the local area network where the application system's server and backend database are located; the external network is any network other than the local area network.

[0030] In step 11, the first routing entry used to specify the access path of the first resource is obtained, specifically including the following steps 111 to 112: Step 111: Depending on the deployment environment, split all route items into first route items and second route items, and write them into two route manifest sub-files for reference by the core route file index.js.

[0031] The routing manifest file for the first route is internetRouter.js, and the routing manifest file for the second route is intranetRouter.js.

[0032] Step 112: The routing core file imports the routing manifest subfile corresponding to the environment variable VUE_APP_ENV.

[0033] Environment variables represent the network environment. For example, when the environment variable represents the external network environment, the routing manifest file internetRouter.js is introduced as the first routing entry; when the environment variable represents the internal network environment, the routing manifest sub-file intranetRouter.js is introduced as the second routing entry.

[0034] Step 12: Obtain the first front-end code used to implement the first route item.

[0035] The front-end code includes HTML (HyperText Markup Language) files that define the page structure and content, CSS (Cascading Style Sheets) files that define the page layout (such as appearance and style), JavaScript files that implement page interaction and dynamic functions, and routing information that determines the page response when a user visits different URLs, etc.

[0036] The front-end code implements the specific functions of this route information. This includes handling user interactions with the page, such as page navigation after clicking navigation links, data retrieval and display, etc. The front-end code uses the route management module to identify and process different route requests, load the corresponding pages or components according to the route definition, and update the user interface to reflect the current page state.

[0037] The first front-end code is used to implement the pages corresponding to the access paths that can be opened to external network clients to access resources.

[0038] In step 12, the first front-end code used to implement the first route item is obtained, including: Retrieve the code containing the first route information and use it as the first front-end code.

[0039] Step 13: Deploy the first front-end code to the isolation zone so that the external network client can obtain the first front-end code from the isolation zone.

[0040] The DMZ (demilitarized zone) is a buffer zone between secure and insecure systems established to prevent external network users from accessing internal network servers after a firewall is installed.

[0041] An isolation zone is a network area located between the internal and external networks. This area can house publicly accessible server facilities, such as enterprise web servers. Furthermore, such an isolation zone provides more effective protection for the internal network. This network deployment adds an extra layer of protection against attackers from the external network compared to a typical firewall solution.

[0042] To ensure the successful release of the first front-end code and to facilitate the deployment and maintenance of the application system, the deployment process of the first front-end code also includes packaging the first front-end code.

[0043] Deploying the first front-end code in the isolation zone specifically includes the following steps 131 to 134: Step 131: Determine the type of the target deployment environment for the first front-end code.

[0044] The types of deployment environments include external network environments and internal network environments. The first front-end code is determined based on the external network environment, therefore the target deployment environment for the first front-end code is the external network environment.

[0045] Step 132: When the type is external network type, obtain the configuration parameters that match the external network type.

[0046] To meet the different bundling requirements of front-end code in different network environments, and to facilitate the maintenance of webpack (a code bundling tool) configuration parameters for different network environments, bundling configuration files for different network environments are added to the webpackConfig directory to control webpack configuration parameters (such as file size, file name format, hash value length, etc.) under different network environments. For example, add bundling configuration files internet.js (to control webpack configuration parameters in the external network environment) and intranet.js (to control webpack configuration parameters in the internal network environment).

[0047] Therefore, when packaging the front-end code, obtain the configuration parameters that match the network environment.

[0048] Step 133: Based on the configuration parameters, package the first front-end code into a front-end code package.

[0049] Based on the webpack configuration parameters, webpack is used to bundle the first-level front-end code. The webpack bundling process includes the following steps 1 to 3: Step 1: During the build phase, the front-end framework first creates module objects based on the dependencies imported in the entry file main.js.

[0050] During the webpack bundling process, the entry file main.js is the starting point for bundling. webpack reads the entry file main.js and identifies specific statements (import, require, etc.) in the entry file. After identifying the specific statements, it creates a module object for each imported module. This module object represents the module itself and contains the module's identifier (such as the path), content, and other modules that it may depend on.

[0051] Step 2: Call Webpack's loader to translate the module into standard JS (JavaScript), and call the JS interpreter to convert the standard JS into an abstract syntax tree object to find the modules that the module depends on.

[0052] Loaders are the system in Webpack used to process non-JavaScript files (such as CSS, images, etc.) and convert them into JavaScript modules.

[0053] After the loader finishes processing, webpack calls the JS interpreter to parse the JavaScript into an abstract syntax tree (Abstract Syntax Tree). An Abstract Syntax Tree is a tree-like data structure that represents the syntactic structure of the code, enabling webpack to understand and manipulate it.

[0054] Step 3: After processing all the dependent files imported in main.js, a package file is generated.

[0055] After all modules in the entry file have undergone step 2 processing, webpack will generate one or more bundle files (usually called bundles or chunks), which are the front-end code packages.

[0056] Step 134: Deploy the front-end code package to the isolation zone.

[0057] To further strengthen the restriction on external network client access to resources, one implementation of this embodiment includes the following steps 14-15: Step 14: Obtain the third routing entry provided by the application system's backend.

[0058] The third routing entry is used to specify the access path of resources that can be opened to external network clients after the external network client logs into the application system.

[0059] In one specific implementation, the specific information in the third routing entry can differ depending on the user; that is, the third routing entry can be based on the resource access permissions set by the user.

[0060] Step 15: When it is found that the first routing entry and the third routing entry are inconsistent, the routing entry common to the third routing entry and the first routing entry is used to control the external client's access to the application system's resources.

[0061] When the first and third routing entries are inconsistent, the routing information shared by both can be used to control external client users' access to resources, thereby further strengthening resource protection.

[0062] To further enhance the security of resources accessed by application systems to intranet clients, one specific implementation of this application includes the following steps 16 to 18: Step 16: Obtain the second routing entry used to specify the access path to the second resource.

[0063] The second resource refers to the resources in the application system that can be accessed by intranet clients. Intranet clients refer to the clients of the application system installed in an internal network environment.

[0064] The second routing entry defines the access paths for resources that the application system can expose to intranet clients.

[0065] In step 16, a second routing entry is obtained to specify the access path of the second resource, referring to the process of steps 111 to 112 above.

[0066] Step 17: Obtain the second front-end code used to implement the second route item.

[0067] The second front-end code is used to implement the pages corresponding to the access paths that can be opened to intranet clients to access resources.

[0068] Obtain the second front-end code used to implement the second route item, including: Retrieve the code containing the second route information and use it as the second front-end code.

[0069] Step 18: Deploy the second front-end code to the internal network so that the internal network client can obtain the second front-end code from the internal network.

[0070] To ensure the successful deployment of the second front-end code and facilitate the deployment and maintenance of the application system, the deployment process also includes packaging the second front-end code. The specific packaging process is the same as steps 131-134 above, except that the object to be packaged differs. In this implementation, the second front-end code can be packaged using the methods described in steps 131-134, and the corresponding network deployment environment is an internal network environment.

[0071] At this point, the separation and separate deployment of the first and second front-end code have been completed.

[0072] like Figure 2 As shown, the first front-end code corresponding to the external network client 21 is deployed in the isolation zone 22, and the second front-end code corresponding to the internal network client 23 is deployed in the internal network zone 24. Therefore, the external network client only obtains the first front-end code determined by the application system for its own resource access, and the second front-end code determined for the internal network client access is deployed in the internal network zone with multiple security safeguards, making it difficult for external network client users to obtain it through illegal means. This further avoids the leakage of data used by the application system solely for internal network access, enhancing the security of the application system's data.

[0073] In this implementation, it is also necessary to obtain the fourth routing entry, which is used to specify the access path of the resources that can be opened to intranet client users after the intranet client user logs into the application system.

[0074] When the second and fourth route items are inconsistent, data not in the fourth route item is removed from the second route item, thus enabling effective backend control over route permissions. The filtered route information is added to the route manager (vue-router) as a whitelist for frontend route permissions, used for subsequent access control.

[0075] The above description describes the protection of application system data at the front end. To further protect the application system data, this application embodiment also considers the back end of the application system and provides a method for protecting application system data, specifically including: A first request forwarder is deployed in the isolation zone to add a first request source identifier to requests sent by external network clients; and a second request forwarder is deployed in the internal network to add a second request source identifier to requests sent by internal network clients.

[0076] Specifically, the first and second request forwarders can be implemented using a reverse proxy server. The first request source identifier is used to identify that the request originates from an external network client; the first request source identifier can be netflag=internet. Correspondingly, the second request source identifier is used to identify that the request originates from an internal network client; the second request source identifier can be netflag=intranet.

[0077] After adding request source identifiers to requests from different types of clients (essentially different network environments), the requests with added request source identifiers are sent to the application system backend via request forwarders (first request forwarder or second request forwarder), enabling the backend to further authenticate client requests to prevent data leakage.

[0078] In the above embodiments of this application, the first front-end code implementing the first routing item is separated and deployed in an isolated area. Since the first routing item corresponds to the access path for external network clients to access resources, the corresponding first front-end code is only the implementation code for external network clients to access resources. Therefore, external network clients can only obtain the front-end code for accessing their own resources, avoiding the leakage of data that only internal network client users can know, and improving the security of application system data.

[0079] Based on the above embodiments, in order to further solve the problem of how to avoid application system data leakage in the prior art, Embodiment 2 of this application provides a data access method based on the front-end code publishing method.

[0080] The execution subject of this method is the client of the application system. The specific implementation can be any computing device that can install the client and implement this method, such as a server, mobile phone, personal computer, smart wearable device, smart robot, etc.

[0081] Furthermore, the embodiments of this application do not limit the execution order of different steps. When using the method provided in the embodiments of this application, the execution order of different steps can be adjusted according to actual needs.

[0082] For ease of description, the following uses a data access device as the execution subject of this method as an example to provide a detailed description of the method provided in the embodiments of this application.

[0083] like Figure 3 The diagram shown illustrates a specific implementation flow of a data access method based on a front-end code publishing method provided in this application embodiment, including the following steps 31-32: Step 31: Send a resource access request to the application system, the resource access request including an interface call request and a static resource request; causing the application system to execute: A request source identifier is added to the interface resource request, and the interface call request with the added request source identifier is forwarded to the gateway device; the static resource request is forwarded to the front-end server; wherein the interface call request contains the target interface information to be called; the gateway device obtains the request source identifier from the interface call request with the added request source identifier; generates an authentication request containing the request source identifier; and sends the authentication request and the interface call request received by the gateway device to the user center device; the user center device determines whether the client has the permission to call the target interface based on the target interface information contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied the right to call the target interface.

[0084] An interface call request can be an API (Application Programming Interface) request. When a client needs to interact with resources or functions on a server, it typically sends an HTTP (Hypertext Transfer Protocol) request to call the API interface provided on the server. The API request contains information about the target interface to be called, and usually also includes a request header and a request body to provide additional information and data.

[0085] Static resources refer to fixed files stored on a server. The content of these files does not change upon request; each request retrieves the same copy of the file. Static resources mainly include HTML, CSS, JavaScript, images, and video files. These resources are pre-stored on the server and are not dynamically generated based on user requests or interactions. To quickly respond to user requests for static resources, they are typically stored on a front-end server.

[0086] For requests to access static resources, the requests are forwarded to the front-end server via the application system's reverse server. It should be noted that static resource requests from different client types are typically sent to the front-end server corresponding to their network origin—that is, static resource requests sent from external network clients are forwarded to the front-end server in the isolated zone; static resource requests sent from internal network clients are forwarded to the front-end server in the internal network zone.

[0087] For API call requests, the reverse proxy server forwards them to the user API gateway cluster (gateway device) at the intranet application layer. When forwarding API call requests, a request origin identifier is added to the request header. For requests from external clients, the identifier `netflag=internet` is added; for requests from intranet clients, the identifier `netflag=intranet` is added.

[0088] After receiving an interface call request with an added request source identifier, the intranet application layer user API gateway cluster (gateway device) extracts the request source identifier from the request header. When calling the user center for authentication, it passes the request source identifier as a parameter to the user center as an authentication request.

[0089] After receiving an authentication request, the user center determines whether the client has permission to call the target interface; if the determination result is no, the client's call to the target interface is denied. Specifically, this includes: The user center stores API permission data, which includes a field for allowed network sources. For example, 000000 means that access is allowed in any network environment, 000001 means that intranet access is supported only, 000010 means that external network access is supported only, 000100 means that dedicated line access is supported only, and so on.

[0090] The user center, based on stored API permission data and the source identifier parameter and target interface information in the authentication request, determines whether the current API call request has permission to access the target interface. For example, if the source identifier of the API call request is netflag=intranet and the target interface corresponds to the 000000 network segment, then the intranet client user has permission to access the target interface, and authentication is successful. Conversely, if the source identifier of the API call request is netflag=internet and the target interface corresponds to the 000001 network segment, then the extranet client user does not have permission to access the target interface, and authentication fails. If the determination result is yes (authentication successful), the data corresponding to the API interface is returned to the client; if the determination result is no (authentication failed), the client's call to the target interface is denied.

[0091] Step 32: Display the return result of the resource access request.

[0092] The returned results can include those from static resource requests and those from API call requests. Specifically, the returned results from API call requests can be the data corresponding to the API interface or a result indicating that the access failed.

[0093] Building upon Embodiment 1, which avoids the leakage of data accessible only to intranet client users and improves the security of application system data, the embodiments of this application further include request source marking for interface call requests to intranet data issued by the client. This marks the network source of the request. For requests from different network sources, the target interface to be accessed is identified to further determine whether the current request has permission to access the corresponding target interface. For requests without access rights, the client's call to the target interface is rejected, further preventing the leakage of intranet data and enhancing the data security of the application system.

[0094] Based on the above embodiments, in order to further solve the problem of how to avoid application system data leakage in the prior art, this application embodiment 3 provides an application system.

[0095] The specific structural diagram of the application system is shown below. Figure 4 As shown, it includes a client 41, a reverse proxy server 42, a gateway device 43, and a user center device 44.

[0096] Client 41 enables interaction with the user, sending API call requests and static resource requests, and displaying the return results of the requests.

[0097] Reverse proxy server 42 is used to receive interface call requests and static resource requests sent by clients of the application system; add a request source identifier to the interface call request and forward the interface call request with the added request source identifier to the gateway device; and forward static resource requests to the front-end server; wherein, the interface call request contains information about the target interface to be called.

[0098] For requests to access static resources, the requests are forwarded to the front-end server via the application system's reverse server 42. It should be noted that static resource requests from different client types are typically sent to the front-end server corresponding to their network origin—that is, static resource requests sent from external network clients are forwarded to the front-end server in the isolated zone; static resource requests sent from internal network clients are forwarded to the front-end server in the internal network zone.

[0099] For API call requests, the reverse proxy server 42 forwards them to the gateway device. When forwarding the API call request, a request origin identifier is added to the request header. For requests from external network clients, the identifier netflag=internet is added; for requests from internal network clients, the identifier netflag=intranet is added.

[0100] Gateway device 43 is used to obtain the request source identifier from the interface call request with the request source identifier added; generate an authentication request containing the request source identifier; and send the authentication request and the interface call request received by the gateway device to the user center device.

[0101] After receiving an interface call request with an added request source identifier, the gateway device 43 extracts the request source identifier from the request header and passes it as a parameter to the user center when calling the user center for authentication, as an authentication request.

[0102] User center device 44 is used to determine whether the client has permission to call the target interface based on the information of the target interface contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied from calling the target interface.

[0103] User Center 44 stores API permission data, which includes allowed network source fields. For example, 000000 means that access is allowed in any network environment, 000001 means that intranet access is supported only, 000010 means that internet access is supported only, 000100 means that dedicated line access is supported only, and so on.

[0104] User Center 44, based on stored API permission data and the source flag parameters and target interface information in the authentication request, determines whether the current API call request has permission to access the target interface. For example, if the source flag of the API call request is netflag=intranet and the target interface corresponds to the 000000 network segment, then the intranet client user has permission to access the target interface, and authentication is successful. Conversely, if the source flag of the API call request is netflag=internet and the target interface corresponds to the 000001 network segment, then the extranet client user does not have permission to access the target interface, and authentication fails. If the determination result is yes (authentication successful), the data corresponding to the API interface is returned to the client; if the determination result is no (authentication failed), the client's call to the target interface is denied.

[0105] Building upon Embodiment 1, which avoids the leakage of data accessible only to intranet client users and improves the security of application system data, the application system provided in the above embodiments of this application marks the request source of interface call requests for intranet data issued by the client to identify the network source of the request. For requests from different network sources, the target interface to be accessed is identified to further determine whether the current request has permission to access the corresponding target interface. For requests without access permissions, the client's call to the target interface is rejected, further preventing the leakage of intranet data and enhancing the data security of the application system.

[0106] To address the problem of how to prevent application system data leakage in the prior art, based on the same inventive concept as Embodiment 1 above, Embodiment 4 of this application also provides a front-end code publishing device.

[0107] The front-end code deployment device includes, for example: Figure 5 The following functional units are shown: The first routing entry information acquisition unit 51 is used to acquire a first routing entry that indicates the access path of the first resource; the first resource is a resource in the application system that can be opened to external network clients for access.

[0108] The first front-end code acquisition unit 52 is used to acquire the first front-end code used to implement the first routing item.

[0109] Deployment unit 53 is used to deploy the first front-end code to an isolation zone, so that the external network client can obtain the first front-end code from the isolation zone; the isolation zone is a network area located between the internal network and the external network; the internal network is the local area network where the application system's server and back-end database are located; the external network is any network other than the local area network.

[0110] Deployment unit 53 specifically includes a release environment type determination subunit, a configuration parameter acquisition subunit, a code packaging subunit, and a code deployment subunit.

[0111] in, The deployment environment type determination subunit is used to determine the type of the target deployment environment for the first front-end code; The configuration parameter acquisition subunit is used to acquire configuration parameters that match the external network type when the type is external network type. The code packaging subunit packages the first front-end code into a front-end code package based on the configuration parameters. The code deployment subunit is used to deploy the front-end code package to the isolation zone.

[0112] To further strengthen the restrictions on external network client access to resources, the publishing device in this embodiment also includes a third routing entry acquisition unit and a resource access control unit.

[0113] in, The third routing entry acquisition unit is used to acquire the third routing entry provided by the backend of the application system.

[0114] The resource access control unit is used to control the external client's access to the application system's resources based on the common routing entries of the third routing entry and the first routing entry when the first routing entry and the third routing entry are found to be inconsistent.

[0115] To further enhance the security of the application system's access to resources by intranet clients, the publishing device in this embodiment also includes a second routing item information acquisition unit and a second front-end code acquisition unit.

[0116] in, The second routing entry information acquisition unit is used to acquire a second routing entry that specifies the access path of the second resource; the second resource is a resource in the application system that can be accessed by intranet clients. The second front-end code acquisition unit is used to acquire the second front-end code used to implement the second route item; Furthermore, the second front-end code is deployed to the internal network through the deployment unit 53, so that the internal network client can obtain the second front-end code from the internal network.

[0117] In the front-end code publishing device provided in the above embodiments of this application, the first front-end code implementing the first routing item is separated and deployed in an isolated area. Since the first routing item corresponds to the access path for external network clients to access resources, the corresponding first front-end code is only the implementation code for external network clients to access resources. Therefore, external network clients can only obtain the front-end code required for their own resource access, avoiding the leakage of data that only internal network client users can know, and improving the security of application system data.

[0118] To address the problem of how to prevent application system data leakage in the prior art, based on the same inventive concept as Embodiment 2 above, Embodiment 5 of this application also provides a resource access device.

[0119] The resource access device includes, for example: Figure 6 The following functional units 61-62 are shown: Request sending unit 61 is used to send interface call requests and static resource requests to the application system, causing the application system to execute: A request source identifier is added to the interface resource request, and the interface call request with the added request source identifier is forwarded to the gateway device; the static resource request is forwarded to the front-end server; wherein the interface call request contains the target interface information to be called; the gateway device obtains the request source identifier from the interface call request with the added request source identifier; generates an authentication request containing the request source identifier; and sends the authentication request and the interface call request received by the gateway device to the user center device; the user center device determines whether the client has the permission to call the target interface based on the target interface information contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied the right to call the target interface; The result display unit 62 is used to display the return results of the call request and the static resource request.

[0120] The resource access device provided in the above embodiments of this application, based on Embodiment 1 which avoids the leakage of data that only intranet client users can know and improves the security of application system data, marks the request source of the interface call request for intranet data issued by the client to identify the network source of the request. For requests from different network sources, the target interface to be accessed is identified to further determine whether the current request has permission to access the corresponding target interface. For requests without permission, the client's call to the target interface is rejected, further avoiding the leakage of intranet data and enhancing the data security of the application system.

[0121] Based on the same inventive concept as the foregoing embodiments of this application, this application also provides a computing device.

[0122] like Figure 7 As shown, the computing device includes a memory 71 and a processor 72. The memory 71 can be configured to store various other data to support operation on the electronic device. Examples of this data include instructions for any application or method used to operate on the electronic device. The memory 71 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0123] The processor 72, coupled to the memory 71, is used to execute the computer program stored in the memory 71 to perform the front-end code publishing method described in Embodiment 1 above, or the resource access method based on the front-end code publishing method described in Embodiment 2 of this application.

[0124] When processor 72 executes the computer program for performing the front-end code deployment method, the first front-end code implementing the first routing item is separated and deployed in an isolated area. Since the first routing item corresponds to the access path for external network clients to access resources, and the corresponding first front-end code is only the implementation code for external network clients to access resources, external network clients can only obtain the front-end code required for their own resource access. This avoids the leakage of data that only internal network client users can access, thus improving the security of application system data.

[0125] When processor 72 executes the computer program to perform the resource access method based on the front-end code publishing method, it avoids the leakage of data that only intranet client users can access, thus improving the security of application system data. Furthermore, it marks the request source of interface call requests sent by clients targeting intranet data to identify the network origin of the request. For requests from different network sources, it identifies the target interface to be accessed to further determine whether the current request has permission to access the corresponding target interface. For requests without permission, the client's call to the target interface is rejected, further preventing the leakage of intranet data and enhancing the data security of the application system.

[0126] When the processor 72 executes the computer program in the memory 71, in addition to the functions described above, it can also perform other functions, as detailed in the descriptions of the preceding embodiments.

[0127] Furthermore, such as Figure 7As shown, the computing device also includes other components such as a display 74, a communication component 73, a power supply component 75, and an audio component 76. Figure 7 The diagram only shows some components and does not mean that the computing device includes only these components. Figure 7 The components shown.

[0128] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a computer, can implement the methods provided in the above embodiments.

[0129] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the methods provided in the above embodiments.

[0130] The computer program product includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a processor, implement the methods provided in the above embodiments.

[0131] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0132] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0133] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for deploying front-end code, characterized in that, include: Retrieve the first routing entry that specifies the access path to the first resource; The first resource refers to the resource in the application system that can be accessed by external network clients; Obtain the first front-end code used to implement the first route item; The first front-end code is deployed to an isolation zone so that the external network client can obtain the first front-end code from the isolation zone; the isolation zone is a network area located between the internal network and the external network; the internal network is the local area network where the application system's server and back-end database are located; the external network is any network other than the local area network.

2. The method as described in claim 1, characterized in that, Deploying the first front-end code to the isolation zone includes: Determine the type of the target deployment environment for the first front-end code; When the type is external network type, obtain the configuration parameters that match the external network type; Based on the configuration parameters, the first front-end code is packaged into a front-end code package; Deploy the front-end code package to the isolation zone.

3. The method as described in claim 1, characterized in that, The method further includes: Obtain a second routing entry that specifies the access path to the second resource; the second resource is a resource in the application system that can be accessed by intranet clients. Obtain the second front-end code used to implement the second route item; The second front-end code is deployed to the internal network so that the internal network client can obtain the second front-end code from the internal network.

4. The method as described in claim 1, characterized in that, The method further includes: Obtain the third routing entry provided by the backend of the application system; the third routing entry is used to indicate the access path of the resources that can be opened to the external network client after the external network client logs into the application system. When the first routing entry and the third routing entry are found to be inconsistent, the routing entry common to both the third routing entry and the first routing entry is used to control the external client's access to the application system's resources.

5. The method as described in claim 1, characterized in that, The method further includes: The isolation zone is also equipped with a first request forwarder; the first request forwarder is used to add a first request source identifier to requests sent by external network clients.

6. A resource access method based on the front-end code publishing method of claim 1, characterized in that, Applied to the client, the resource access method includes: Send resource access requests to the reverse proxy server in the application system. These resource access requests include interface call requests and static resource requests. This causes the reverse proxy server, gateway device, and user center device in the application system to execute: The reverse proxy server adds a request source identifier to the interface call request and forwards the interface call request with the added request source identifier to the gateway device; it also forwards the static resource request to the front-end server; wherein the interface call request contains the target interface information to be called; the gateway device obtains the request source identifier from the interface call request with the added request source identifier; it generates an authentication request containing the request source identifier; and sends the authentication request and the interface call request received by the gateway device to the user center device; the user center device determines whether the client has the permission to call the target interface based on the target interface information contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied the right to call the target interface; Display the return result of the resource access request.

7. An application system, characterized in that, This includes client devices, reverse proxy servers, gateway devices, and user center devices. The client is used to send API call requests and static resource requests; A reverse proxy server is used to receive interface call requests and static resource requests sent by the clients of the application system. A request source identifier is added to the interface call request, and the interface call request with the added request source identifier is forwarded to the gateway device; static resource requests are forwarded to the front-end server; wherein, the interface call request contains information about the target interface to be called; the reverse proxy server is deployed in the isolation zone described in claim 1; A gateway device is used to obtain a request source identifier from an interface call request with an added request source identifier; generate an authentication request containing the request source identifier; and send the authentication request and the interface call request received by the gateway device to the user center device. The user center device is used to determine whether the client has permission to call the target interface based on the information of the target interface contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied from calling the target interface.

8. A front-end code deployment device, characterized in that, include: The first routing entry information acquisition unit is used to acquire the first routing entry that specifies the access path of the first resource; The first resource refers to the resource in the application system that can be accessed by external network clients; The first front-end code acquisition unit is used to acquire the first front-end code used to implement the first routing item; A deployment unit is configured to deploy the first front-end code to an isolation zone, so that the external network client can obtain the first front-end code from the isolation zone; The isolation zone is a network area located between the internal network and the external network; the internal network is the local area network where the application system's server and backend database are located; the external network is any network other than the local area network.

9. A resource access device based on the front-end code publishing method of claim 1, characterized in that, Applied to the client side, including: The request sending unit is used to send interface call requests and static resource requests to the reverse proxy server in the application system; causing the reverse proxy server, gateway device, and user center device in the application system to execute: The reverse proxy server adds a request source identifier to the interface call request and forwards the interface call request with the added request source identifier to the gateway device; it also forwards the static resource request to the front-end server; wherein the interface call request contains the target interface information to be called; the gateway device obtains the request source identifier from the interface call request with the added request source identifier; it generates an authentication request containing the request source identifier; and sends the authentication request and the interface call request received by the gateway device to the user center device; the user center device determines whether the client has the permission to call the target interface based on the target interface information contained in the interface call request sent by the gateway device and the request source identifier contained in the authentication request sent by the gateway device; if the determination result is no, the client is denied the right to call the target interface; The results display unit is used to display the return results of call requests and static resource requests.

10. A computing device, characterized in that, include: Memory and processor, among which, The memory is used to store computer programs; The processor, coupled to the memory, is configured to execute the computer program stored in the memory for performing the method according to any one of claims 1 to 6.

11. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a computer, it can implement the method described in any one of claims 1 to 6.

12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Common platform of sports competition information release system

    CN107451169A

  • Data access method and device, terminal and storage medium

    CN110851823A