Application calling method and device, equipment, medium and product

By generating exclusive user sub-application containers for each system users in the application system, the problem of user data leakage in multi-user systems is solved, and data security is improved.

CN120296723AActive Publication Date: 2025-07-11HANGZHOU NEWGRAND TECHNOLOGY CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510765174.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-11
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

In existing application systems, the process of multiple system users calling applications cannot be isolated from each other, resulting in user data leakage.

Method used

The corresponding user sub-application container is generated for each candidate system user in the target application system, and the call is made through the exclusive user sub-application container to ensure the isolation of the call process.

Benefits of technology

It realizes mutual isolation of the process of system users calling applications, reduces the risk of user data leakage, and improves the data security of the application system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296723A_ABST
    Figure CN120296723A_ABST
Patent Text Reader

Abstract

The invention discloses an application program calling method and device, equipment, a medium and a product, and relates to the technical field of computers.The method comprises the steps that if it is determined that the number of system users is at least two, candidate data source information associated with candidate system users and first application container port information independently distributed for the candidate system users are obtained; according to the candidate data source information and the first application container port information, performing parameter updating on the current container context parameter, and generating a first container context parameter corresponding to the candidate system user; according to the current container context type and the first container context parameter, generating a corresponding user sub-application container for the candidate system user; wherein the candidate system users call the application programs through the corresponding user sub-application containers. According to the method and the device, the effect of mutually isolating the process of calling the application program by the system user is realized, the risk of user data leakage when the system user calls the application program is reduced, and the data security of the application system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method, apparatus, device, medium, and product for invoking an application program. Background Art

[0002] In the digital age, all walks of life have started digital transformation, and the demand for digitalization has exploded. Application systems are a typical digital system in the digital age. An application system is an integrated solution composed of software, hardware, and data resources, aiming to solve specific business problems or meet specific functional requirements.

[0003] There are usually multiple system users in an application system. In the prior art, multiple system users all invoke application programs through the application containers of the application system, and the application system uses permission verification to control the invocation of application programs by different system users.

[0004] However, this method cannot isolate the processes of different system users invoking application programs from each other, and there is still a problem of leakage of user data of system users, resulting in insufficient data security of the application system. Summary of the Invention

[0005] The present invention provides a method, apparatus, device, medium, and product for invoking an application program to solve the problem that the existing application system has insufficient data security, resulting in easy leakage of user data.

[0006] According to an aspect of the present invention, there is provided a method for invoking an application program, the method comprising:

[0007] Determining whether the number of system users of candidate system users of a target application system is at least two;

[0008] If it is determined that the number of system users is at least two, obtaining candidate data source information of candidate system data sources associated with each of the candidate system users, and obtaining first application container port information separately allocated to each of the candidate system users;

[0009] Updating parameters of current container context parameters according to the candidate data source information and the first application container port information to generate first container context parameters respectively corresponding to each of the candidate system users; wherein, the current container context parameters are container context parameters of a main application container of the target application system, and the main application container provides an application program that can be invoked.

[0010] Based on the current container context type of the main application container and the first container context parameter, corresponding user sub-application containers are respectively generated for each of the candidate system users in the target application system; wherein, each of the candidate system users calls the application program through the corresponding user sub-application container.

[0011] According to another aspect of the present invention, there is provided a calling device for an application program, the device includes:

[0012] A system user quantity recognition module, configured to determine whether the quantity of candidate system users in the target application system is at least two;

[0013] An information acquisition module, configured to, if it is determined that the quantity of system users is at least two, acquire the candidate data source information of the candidate system data sources associated with each of the candidate system users, and acquire the first application container port information separately allocated for each of the candidate system users;

[0014] A first context parameter generation module, configured to update the parameters of the current container context parameter according to the candidate data source information and the first application container port information, and generate the first container context parameters respectively corresponding to each of the candidate system users; wherein, the current container context parameter is the container context parameter of the main application container of the target application system, and the main application container provides an application program that can be called.

[0015] A user sub-application container generation module, configured to generate corresponding user sub-application containers for each of the candidate system users in the target application system according to the current container context type of the main application container and the first container context parameter; wherein, each of the candidate system users calls the application program through the corresponding user sub-application container.

[0016] According to another aspect of the present invention, there is provided an electronic device, the electronic device includes:

[0017] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the calling method of the application program according to any one of the present invention.

[0018] According to another aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the calling method of the application program according to any one of the present invention when executed by a processor.

[0019] According to another aspect of the present invention, there is provided a computer program product including a computer program which, when executed by a processor, implements the method for invoking an application program according to any one of the present invention.

[0020] In the present invention, corresponding user sub-application containers are respectively generated for each candidate system user in the target application system, and each candidate system user invokes the application program through the corresponding user sub-application container, thereby achieving the effect of isolating the processes of system users invoking the application program from each other, reducing the risk of user data leakage when the system users invoke the application program, and enhancing the data security of the application system.

[0021] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0023] Figure 1 It is a flowchart of a method for invoking an application program provided in Embodiment 1 of the present invention;

[0024] Figure 2 It is a flowchart of a method for invoking an application program provided in Embodiment 2 of the present invention;

[0025] Figure 3 It is a flowchart of a method for invoking an application program provided in Embodiment 3 of the present invention;

[0026] Figure 4 It is a schematic structural diagram of an apparatus for invoking an application program provided in Embodiment 4 of the present invention;

[0027] Figure 5 It is a schematic structural diagram of an electronic device for implementing the method for invoking an application program in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.

[0029] It should be noted that the terms "first", "second", "candidate", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0030] Embodiment 1

[0031] Figure 1 FIG. 10 is a flowchart of a method for calling an application program provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation where a system user calls an application program through an exclusive user sub-application container. This method can be executed by a calling device for an application program. The calling device for an application program can be implemented in the form of hardware and / or software, such as being implemented by an application system, etc. As Figure 1 shown, the method includes:

[0032] S101. Determine whether the number of system users of candidate system users that the target application system has is at least two.

[0033] Among them, candidate system users refer to system users that the target application system has. System users are also called system tenants, and refer to users who have specific permissions and function access rights and directly operate or manage the application system. It can be understood that the number of system users of candidate system users that the target application system has can be one or more.

[0034] When the number of system users is one, it means that the type of the target application system is a single-user system. Since there is only one system user accessing the application container to call the application program in a single-user system, and there is no situation where other system users access the application container to call the application program, there is no risk of system user data leakage.

[0035] When the number of system users is multiple, that is, at least two, it means that the target application system is a multi-user system. At this time, different system users access the application container to call the application, so there is a risk of system user data leakage. Therefore, it is necessary to identify the number of system users of the target application system to determine whether the target application system has the risk of system user data leakage.

[0036] In one embodiment, the system management backend of the target application system is accessed, and the user management module in the system management backend is further accessed, the system user list is viewed through the user management module, and further, it is determined whether the number of system users is at least two based on the system user list.

[0037] In another embodiment, a system access log of the target application system is obtained, and system access users of the target application system in a historical time period are determined according to the system access log, and whether the number of system users is at least two is determined according to the system access users.

[0038] In another embodiment, the number of databases of the candidate databases configured for the target application system is determined. If the number of databases is at least two, the candidate table metadata information of each candidate database is further compared. If the metadata information of each candidate table is the same, it is identified whether the database scheduling mechanism of the target application system is a scheduling mechanism for switching databases based on user identifiers. If so, it is determined whether the number of system users is at least two.

[0039] S102: If it is determined that the number of system users is at least two, obtain candidate data source information of a candidate system data source associated with each candidate system user, and obtain first application container port information individually allocated to each candidate system user.

[0040] Among them, the candidate system data source represents the system data source connected to each candidate database configured by the target application system. The system data source is the source of data required by the target application system, that is, the core channel for the target application system to interact with the outside of the system. The candidate data source information represents the data source parameters corresponding to the candidate system data source, which is the core attribute parameter for configuring the data source connection.

[0041] In this embodiment, there is an association relationship between the candidate system user and the candidate data source, that is, any candidate system user corresponds to a candidate data source alone, and the candidate system user initiates a request to the target application system through the associated candidate data source, such as initiating an application call request, thereby realizing data interaction with the target application system. For example, assuming that candidate system user 1 is associated with candidate data source A, candidate system user 1 initiates a request to the target application system through candidate data source A, thereby realizing data interaction with the target application system.

[0042] In this embodiment, exclusive application container port information is separately allocated to each candidate system user as the first application container port information, and the first application container port information corresponding to each candidate system user is different. The application container port information is a logical concept in containerization technology used to identify the communication endpoints of processes inside the application container, and is exposed to the application system through port mapping for accessing the application container. In other words, based on any application container port information, the application container corresponding to the application container port information can be accessed. It can be understood that separately allocating exclusive application container port information to each candidate system user lays a parameter foundation for generating user sub-application containers corresponding to each candidate system user subsequently.

[0043] For example, assume that the target application system has candidate system user 1, candidate system user 2, and candidate system user 3. Exclusive application container port information "81" is separately allocated to candidate system user 1; exclusive application container port information "82" is separately allocated to candidate system user 2; and exclusive application container port information "83" is separately allocated to candidate system user 3.

[0044] In one implementation manner, access the system configuration file of the target application system, and obtain the candidate data source information of the candidate system data sources associated with each candidate system user according to the system configuration file, and also obtain the first application container port information separately allocated to each candidate system user.

[0045] S103. Update the parameters of the current container context parameters according to the candidate data source information and the first application container port information, and generate the first container context parameters corresponding to each candidate system user respectively.

[0046] Among them, the current container context parameters are the container context parameters of the main application container of the target application system. The main application container provides callable application programs and is a pre-created application container in the target application system. The application container is a lightweight virtualization technology used to package the application program and its dependent environment into an independent and portable running unit. The container context parameters are key configuration items for initializing and managing the running environment of the application container, usually storing globally shared information, that is, the application container can be generated using the container context parameters.

[0047] In one implementation, determine the container interface corresponding to the main application container, such as the ServletContext interface, and extract the current container context parameters of the main application container through the container interface. Further, determine the first position in the current container context parameters for describing data source information and the second position for describing application container port information. Then, update the candidate data source information corresponding to any candidate system user to the first position, and update the first application container port information corresponding to the candidate system user to the second position, and use the current container context parameters with updated parameters as the first container context parameters corresponding to the candidate system user.

[0048] S104. According to the current container context type of the main application container and the first container context parameters, generate corresponding user sub - application containers for each candidate system user in the target application system.

[0049] Among them, the current container context type refers to the container context type corresponding to the main application container. The container context type refers to the container implementation class used to manage the application container Bean definition and life cycle in different application scenarios. Each candidate system user calls the application program through the corresponding user sub - application container.

[0050] In one implementation, determine the container interface corresponding to the main application container, such as the ServletContext interface, and extract the current container context type of the main application container through the container interface. Further, input the current container context type and the first container context parameters into the container generation tool, so that the container generation tool generates corresponding user sub - application containers for each candidate system user in the target application system based on the current container context type and the first container context parameters. For example, assume that the first container context parameters corresponding to candidate system user 1 are container context parameter A. Then, input the current container context type and container context parameter A into the container generation tool, so that the container generation tool generates the corresponding user sub - application container for candidate system user 1 in the target application system based on the current container context type and container context parameter A.

[0051] Further, construct a target routing container according to the candidate user identifier and the first application container port information corresponding to each candidate system user. Through the target routing container, parse the candidate user identifier from the application program call request sent by any candidate system data source, and determine the associated first application container port information according to the candidate user identifier. Then, route the application program call request to the user sub - application container corresponding to the first application container port information according to the first application container port information, so that the candidate system user calls the application program through the user sub - application container.

[0052] In the embodiment of the present invention, user sub - application containers are respectively generated for each candidate system user in the target application system, and each candidate system user calls the application program through the corresponding user sub - application container, thereby achieving the effect of isolating the process of system users calling the application program from each other, reducing the risk of user data leakage when system users call the application program, and enhancing the data security of the application system.

[0053] Embodiment 2

[0054] Figure 2 FIG. is a flowchart of a method for calling an application program provided in Embodiment 2 of the present invention. This embodiment further optimizes and expands the above - mentioned embodiment and can be combined with each of the above - mentioned optional implementation manners. As Figure 2 shown, the method includes:

[0055] S201. Determine the number of databases of the candidate databases configured in the target application system. If the number of databases is at least two, obtain the candidate table metadata information corresponding to each candidate database, and compare the candidate table metadata information of each candidate database to determine whether the candidate table metadata information of each candidate database is the same.

[0056] Among them, the candidate database refers to at least one database configured in the target application system. The candidate database is the core data storage and management module that supports the operation of the business logic of the target application system. Its essence is a collection that structurally stores, securely manages, and efficiently accesses the business data of the target application system through database technology. The candidate table metadata information of the candidate database is the core data used to describe the database table structure, attributes, and relationships, which is equivalent to the "data dictionary" of the candidate database.

[0057] In one implementation manner, obtain the system configuration file of the target application system, identify the database identifier in the system configuration file, and determine the number of databases of the candidate databases according to the number of identified database identifiers. If the number of databases is at least two, further call the metadata interface of each candidate database, and use the metadata interface to obtain the candidate table metadata information corresponding to each candidate database.

[0058] Furthermore, compare the candidate table metadata information corresponding to each candidate database to determine whether all the candidate table metadata information contains the same metadata information.

[0059] S202. If the candidate table metadata information of each candidate database is the same, determine whether the database scheduling mechanism of the target application system is the target scheduling mechanism; if the database scheduling mechanism of the target application system is the target scheduling mechanism, determine that the number of system users is at least two.

[0060] Among them, the database scheduling mechanism refers to the core component of the target application system for coordinating task execution and database allocation. Its core goal is to ensure data consistency, optimize performance, and efficiently handle concurrent operations. The target scheduling mechanism is a scheduling mechanism for switching databases based on user identification. The scheduling mechanism for switching databases based on user identification is mainly used in multi-user systems to automatically select the corresponding database for access according to the user identity identification (such as ID, tenant code, etc.).

[0061] In one implementation, if the candidate table metadata information corresponding to each candidate database is the same, obtain the slow query log of the target application system, and further analyze the database scheduling mechanism of the target application system according to the slow query log. If it is determined that the database scheduling mechanism of the target application system is the "scheduling mechanism based on SQL statement execution", it means that the target application system is in a read-write separation state and no processing is performed; if it is determined that the database scheduling mechanism of the target application system is the target scheduling mechanism, that is, the scheduling mechanism for switching databases based on user identification, then determine that the number of system users is at least two.

[0062] By determining the number of databases of the candidate databases configured in the target application system, if the number of databases is at least two, obtain the candidate table metadata information corresponding to each candidate database; compare the candidate table metadata information to determine whether the candidate table metadata information is the same; if the candidate table metadata information is the same, determine whether the database scheduling mechanism of the target application system is the target scheduling mechanism; if the database scheduling mechanism of the target application system is the target scheduling mechanism, then determine that the number of system users is at least two. The beneficial effects are as follows:

[0063] First, it realizes the effect of automatically identifying the number of system users, reduces the manual inspection cost, and improves the efficiency of identifying the number of system users.

[0064] Second, through the comparison of the table metadata information and the identification of the database scheduling mechanism, the time-consuming for identifying the number of system users is shortened, and the accuracy of identifying the number of system users can also be guaranteed.

[0065] S203. If it is determined that the number of system users is at least two, obtain the candidate data source information of the candidate system data sources associated with each candidate system user, and obtain the first application container port information separately allocated for each candidate system user.

[0066] S204. Determine the current data source information and the current application container port information included in the current container context parameter; update the current data source information to the candidate data source information corresponding to any candidate system user, and update the current application container port information to the first application container port information corresponding to the candidate system user.

[0067] Among them, the current data source information represents the data source information supported by the main application container currently. The current application container port information represents the application container port information of the main application container currently.

[0068] In one implementation, the current container context parameters are parsed to determine the current data source information and the current application container port information therefrom.

[0069] Furthermore, all the current data source information is deleted, and the candidate data source information corresponding to any candidate system user is used as the new current data source information. For example, assume that the current data source information includes the data source information of data source 1, the data source information of data source 2, and the data source information of data source 3, and the candidate data source information X corresponding to candidate system user 1. Then all these data source information are deleted, and the candidate data source information X is used as the new current data source information.

[0070] At the same time, the current application container port information is deleted, and the first application container port information corresponding to this candidate system user is used as the new current application container port information. For example, assume that the current application container port information is "80", and the first application container port information corresponding to this candidate system user is "81". Then the current application container port information "80" is deleted, and the first application container port information "81" is used as the new current data source information.

[0071] By determining the current data source information and the current application container port information included in the current container context parameters; updating the current data source information to the candidate data source information corresponding to any candidate system user, and updating the current application container port information to the first application container port information corresponding to this candidate system user, the beneficial effects are as follows:

[0072] Firstly, since there are only differences in "candidate data source information" and "first application container port information" among different candidate system users, only updating the current container context parameters according to "candidate data source information" and "first application container port information" without changing other information in the current container context parameters can not only ensure the efficiency of generating the first container context parameters, but also ensure that the user sub-application containers generated according to the first container context parameters can still provide application programs normally.

[0073] Secondly, it can ensure that different candidate system users operate independent user sub-application containers, avoid data mixing or unauthorized access, and further ensure the data security of each candidate system user.

[0074] S205. Determine the first container context parameters corresponding to this candidate system user according to the updated current container context parameters.

[0075] S206. Generate corresponding user sub-application containers for each candidate system user in the target application system according to the current container context type of the main application container and the first container context parameter.

[0076] Among them, each candidate system user calls the application program through the corresponding user sub-application container.

[0077] In one implementation, after generating the user sub-application containers corresponding to each candidate system user, all the application layer beans of the main application container are removed to ensure the isolation between the main application container and each user sub-application container, so that the main application container no longer provides callable application programs, but each user sub-application container provides callable application programs to the corresponding candidate system users.

[0078] Optionally, the method further includes:

[0079] A1. Determine the candidate user identifiers corresponding to each candidate system user respectively, and generate the first routing rule for the target routing container in the target application system according to the candidate user identifiers corresponding to each candidate system user respectively and the first application container port information.

[0080] Among them, the candidate user identifier refers to the naming symbol used to uniquely identify the candidate user identity or candidate user-defined element. The target routing container refers to the routing container set in the target application system. The routing container is the core component for managing network communication paths in the containerized environment, and its function is similar to that of a router in the traditional network, but it is designed specifically for the container architecture.

[0081] In one implementation, put the candidate user identifiers corresponding to each candidate system user respectively and the first application container port information into the target routing container for port orchestration, so as to construct the first routing rule between each candidate user identifier and each first application container port information.

[0082] For example, if candidate system user 1 corresponds to candidate user identifier "V" and the first application container port information "85", then put the candidate user identifier "V" and the first application container port information "85" into the target routing container for port orchestration, and construct the first routing rule between the candidate user identifier "V" and the first application container port information "85".

[0083] B1. Control each candidate system user to access the corresponding user sub-application container respectively through the target routing container for calling the application program.

[0084] In one embodiment, the target application system obtains a first application program call request sent by any candidate system data source, determines the candidate user identifier of the candidate system user associated with the candidate system data source, and then controls the candidate system user to access its corresponding user sub-application container according to the first routing rule through the target routing container for calling the application program.

[0085] By determining the candidate user identifiers respectively corresponding to each candidate system user, and according to the candidate user identifiers respectively corresponding to each candidate system user and the first application container port information, generating a first routing rule for the target routing container in the target application system; by controlling each candidate system user to access the corresponding user sub-application container respectively according to the first routing rule through the target routing container for calling the application program, the beneficial effects are as follows:

[0086] First, through the binding of the candidate user identifier and the application container port information, it is ensured that the candidate system user can only access the authorized user sub-application container, preventing unauthorized operations and enhancing the data security of the candidate system user.

[0087] Second, when adding a new candidate system user or user sub-application container, only the routing rule needs to be updated, without reconstructing the overall architecture, to meet the requirements of rapid iteration.

[0088] Optionally, the controlling each candidate system user to access the corresponding user sub-application container respectively according to the first routing rule through the target routing container includes:

[0089] B11. Through the target routing container, according to a first application program call request sent by any candidate system data source, determining the candidate user identifier of the candidate system user associated with the candidate system data source as the first user identifier.

[0090] In one embodiment, any candidate system user sends a first application program call request containing its candidate user identifier to the target application system through its associated candidate system data source. The target application system parses the first application program call request through the target routing container to obtain the candidate user identifier of the candidate system user as the first user identifier.

[0091] B12. Through the target routing container, according to the first user identifier and the first routing rule, determining the first application container port information associated with the first user identifier as the first port information to be accessed.

[0092] Exemplarily, assuming that there is an association between the first user identifier "xxyy" and the first application container port information "83" in the first routing rule, the target routing container determines the first application container port information "83" associated with the first user identifier "xxyy" according to the first user identifier "xxyy" and the first routing rule, as the first port information to be accessed.

[0093] B13. The target routing container forwards the first application program call request according to the first port information to be accessed, for controlling the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

[0094] In one implementation manner, the target application system determines the user sub-application container corresponding to the candidate system user according to the first port information to be accessed through the target routing container, and then forwards the first application program call request to the user sub-application container corresponding to the candidate system user, so that the candidate system user can access the user sub-application container corresponding to the candidate system user for application program calls.

[0095] The target routing container determines the candidate user identifier of the candidate system user associated with the candidate system data source according to the first application program call request sent by any candidate system data source as the first user identifier; the target routing container determines the first application container port information associated with the first user identifier according to the first user identifier and the first routing rule as the first port information to be accessed; the target routing container forwards the first application program call request according to the first port information to be accessed, for controlling the candidate system user associated with the candidate system data source to access the corresponding user sub-application container. The beneficial effects are as follows:

[0096] In the first aspect, based on the dynamic matching mechanism between the user identifier and the first routing rule, the automatic mapping of port resources and system users is realized, avoiding manual maintenance of the port mapping table.

[0097] In the second aspect, multiple isolated user sub-application containers can be deployed in the target application system, and traffic isolation is achieved through the first routing rule, ensuring precise control of data access rights and resource allocation.

[0098] Embodiment III

[0099] Figure 3 The flowchart of a method for calling an application program provided in Embodiment III of the present invention further optimizes and expands the above embodiments and can be combined with the above various optional implementation manners. This embodiment is applicable to the situation where different system roles call application programs through exclusive role sub-application containers. As Figure 3 shown, the method includes:

[0100] S301. Determine whether the number of system roles of the candidate system roles of the target application system is at least two.

[0101] Among them, the candidate system role represents the system role of the target application system. The system role is a set of predefined permission sets used to identify the responsibilities and operation scopes of system users in the application system. That is, one system user corresponds to one system role.

[0102] It can be understood that the number of system roles of the candidate system roles of the target application system can be one or more. When the number of system roles is one, it means that the type of the target application system is a single-role system. Since there is only one system role accessing the application container to call the application program in the single-role system and there is no situation where other system roles access the application container to call the application program, there is no risk of system role data leakage.

[0103] When the number of system roles is multiple, that is, at least two, it means that the type of the target application system is a multi-role system. At this time, there is a situation where different system roles access the application container to call the application program, so there is a risk of system role data leakage. Therefore, it is necessary to identify the number of system roles of the target application system to determine whether there is a risk of system role data leakage in the target application system.

[0104] In one implementation, obtain the user detail pages of each candidate system user in the target application system, and determine the candidate system roles to which each candidate system user belongs according to each user detail page. Then, count all the candidate system roles to determine whether the number of system roles of the candidate system roles is at least two.

[0105] In another implementation, through the REST API of the target application system, obtain the role list of the target application system, and then determine whether the number of system roles of the candidate system roles is at least two according to the role list.

[0106] In another implementation, determine the number of databases of the candidate databases configured in the target application system. If the number of databases is one, determine whether the target user type field in the target system user table is used for user classification. If so, determine that the number of system roles is at least two; if the number of databases is at least two, determine whether the target interceptor of the target application system has performed a data source switching operation for the main application container. If so, determine that the number of system roles is at least two.

[0107] Optionally, determining whether the number of system roles of the candidate system roles of the target application system is at least two includes:

[0108] S3011. Determine the number of databases of the candidate databases configured for the target application system. If the number of databases is one, obtain the candidate table metadata information corresponding to the candidate database as the target table metadata information.

[0109] Exemplarily, assume that only candidate database A is configured for the target application system. Then, use the candidate table metadata information corresponding to candidate database A as the target table metadata information.

[0110] S3012. Determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification.

[0111] Among them, the target system user table is a structured data table in the target application system for storing the core information of system users. The target user type field is the core field in the target system user table for distinguishing user roles or permission levels, and usually realizes the differential control of user groups through coding, identifiers or classification names.

[0112] In one implementation, determine whether the table name of each system table in the target application system includes a target keyword according to the target table metadata information. The target keyword includes but is not limited to an account keyword, a password keyword or a "USER" keyword, etc. Then, use the system table including the target keyword as the target system user table. Further, detect the target user type field included in the target system user table to determine whether the target user type field is used for user classification.

[0113] S3013. If the target user type field is used for user classification, determine whether the target user type field contains target user characteristics; otherwise, determine that the number of system roles is at least two.

[0114] Among them, the target user characteristic is a user characteristic irrelevant to role characteristics, such as a position characteristic, etc.

[0115] In one implementation, determine whether the target user type field is used for user classification. If the target user type field is used for user classification, further determine whether the target user type field contains a user characteristic irrelevant to role characteristics; otherwise, determine that the number of system roles is at least two.

[0116] By determining the number of databases of the candidate databases configured for the target application system, if the number of databases is one, obtain the candidate table metadata information corresponding to the candidate database as the target table metadata information; determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification; if the target user type field is used for user classification, determine whether the target user type field contains target user characteristics, otherwise determine that the number of system roles is at least two, ensuring the accuracy and efficiency of determining the number of system roles.

[0117] S302. If it is determined that the number of system roles is at least two, obtain the target common code of the target application system, the candidate role codes respectively corresponding to the candidate system roles, and the second application container port information separately allocated for each candidate system role.

[0118] Among them, the target common code refers to the system common code set in the target application system, and the system common code is a standardized code segment reused in the target application system. The candidate role code is the role code exclusive to each candidate system role, and the role code is a coding system used to uniquely identify the permissions of different candidate system roles, and its meaning is usually closely related to system function modules, operation permissions or business responsibilities.

[0119] In this embodiment, exclusive application container port information is separately allocated for each candidate system role as the second application container port information, and the second application container port information corresponding to each candidate system role is different. It can be understood that separately allocating exclusive application container port information for each candidate system role lays a parameter foundation for generating role sub-application containers respectively corresponding to each candidate system role in the future.

[0120] In one implementation manner, perform code analysis on the target application system to obtain the target common code of the target application system and the candidate role codes respectively corresponding to the candidate system roles. And, access the system configuration file of the target application system, and obtain the second application container port information separately allocated for each candidate system role according to the system configuration file.

[0121] Optionally, obtaining the target common code of the target application system includes:

[0122] Construct a first scanning expression according to the first package name of the target code package in the target application system; use the first scanning expression to scan the system code of the target application system, and determine the target common code of the target application system according to the scanning result.

[0123] Among them, the target code package is the system code package and / or the tool code package. The system code package is a collection of codes used to encapsulate functional modules in the development of the target application system, usually including resources such as program source codes, dependent libraries, and configuration files. The tool code package is a modular functional collection used to improve efficiency in the development of the target application system, usually existing in the form of function libraries, SDKs, or framework plugins. It can be understood that both the system code package and the tool code package contain the target common codes of the target application system. The first package name is used to uniquely identify the target code package within the global scope of the target application system. The first scanning expression is constructed based on the first package name and is used to match and filter the package paths of the target code package.

[0124] In one implementation, code package identification is performed on the target application system to determine the system code package and the tool code package included in the target application system as the target code package. Further, the package names of each target code package are extracted as the first package name, and the first scanning expression is constructed based on the first package name. The system code of the target application system is scanned using the first scanning expression, and the system code obtained by scanning based on the first scanning expression is used as the target common code.

[0125] By constructing the first scanning expression according to the first package name of the target code package in the target application system; scanning the system code of the target application system using the first scanning expression, and determining the target common code of the target application system according to the scanning result, the beneficial effects are as follows:

[0126] First, by constructing the first scanning expression through the first package name, the target common codes across modules such as basic tool classes and general configurations in the target application system can be quickly located, improving the efficiency of determining the target common code.

[0127] Second, by scanning the system code of the target application system using the first scanning expression to determine the target common code, the accuracy of determining the target common code can be guaranteed.

[0128] Optionally, obtaining the candidate role codes corresponding to each candidate system role includes:

[0129] S3021. According to the candidate role identifier corresponding to any candidate system role, determine the role routing rule corresponding to the candidate system role, and determine the system routing address corresponding to the candidate system role according to the role routing rule.

[0130] Among them, the candidate role identifier is a key field used to uniquely identify and distinguish different candidate system roles. The role routing rule refers to a mechanism for dynamically controlling the access permissions of the target application system interface based on the candidate system roles. The role routing rule can be a routing rule of vue, etc. The system routing address refers to the routing address corresponding to the candidate system role in the target application system, which can be a URL address, etc.

[0131] In one implementation, according to the candidate role identifier corresponding to any candidate system role, scan the code routing of vue to determine the routing rule of vue for this candidate system role as the role routing rule. Determine the URL address corresponding to this candidate system role in the target application system according to the role routing rule, and use it as the system routing address corresponding to this candidate system role.

[0132] S3022. Match the system routing address with the control class address of the candidate control class in the main application container, and determine the target control class from the candidate control classes according to the matching result.

[0133] Among them, the candidate control class refers to the class in the main application container that models the control behavior of specific use cases or business logics. The control class address is also the address information of each candidate control class in the target application system.

[0134] In one implementation, match the system routing address corresponding to this candidate system role with the control class address of the candidate control class in the main application container, and use the candidate control class whose control class address matches the system routing address as the target control class.

[0135] S3023. Construct a second scan expression according to the second package name of the class code package corresponding to the target control class, and use the second scan expression to scan the system code of the target application system. Determine the candidate role code corresponding to this candidate system role according to the scan result.

[0136] Among them, the second package name is used to uniquely identify the class code package corresponding to the target control class within the global scope of the target application system. The second scan expression is constructed based on the second package name and is used to match and filter the package path of the class code package corresponding to the target control class.

[0137] In one implementation, determine the class code package corresponding to the target control class, extract the package name of the class code package as the second package name, and construct a second scan expression according to the second package name. Use the second scan expression to scan the system code of the target application system, and use the system code scanned based on the second scan expression as the candidate role code corresponding to this candidate system role.

[0138] By determining the role routing rule corresponding to any candidate system role according to the candidate role identifier corresponding to the candidate system role, and determining the system routing address corresponding to the candidate system role according to the role routing rule; matching the system routing address with the control class address of the candidate control class in the main application container, and determining the target control class from the candidate control classes according to the matching result; constructing a second scanning expression according to the second package name of the class code package corresponding to the target control class, and scanning the system code of the target application system by using the second scanning expression, and determining the candidate role code corresponding to the candidate system role according to the scanning result, the beneficial effects are as follows:

[0139] First, the second scanning expression can quickly identify the candidate role code related to the candidate system role in the system code, ensuring the efficiency of candidate role code identification.

[0140] Second, by scanning the system code of the target application system with the second scanning expression to determine the candidate role code, the accuracy of determining the candidate role code can be ensured.

[0141] Optionally, the method further includes:

[0142] A2. Determine the candidate role identifier corresponding to each candidate system role respectively, and generate a second routing rule for the target routing container in the target application system according to the candidate role identifier corresponding to each candidate system role respectively and the second application container port information.

[0143] In one implementation, the candidate role identifier corresponding to each candidate system role respectively and the second application container port information are put into the target routing container for port orchestration, so as to construct a second routing rule between each candidate role identifier and each second application container port information.

[0144] For example, if the candidate system role 1 corresponds to the candidate role identifier "Y" and the second application container port information "90", then the candidate role identifier "Y" and the second application container port information "90" are put into the target routing container for port orchestration, and a second routing rule between the candidate role identifier "Y" and the second application container port information "90" is constructed.

[0145] B2. The target routing container controls each candidate system role to access the corresponding role sub-application container respectively according to the second routing rule, for calling the application program.

[0146] In one embodiment, the target application system obtains a second application call request sent by any candidate system data source, determines the candidate role identifier of the candidate system role associated with the candidate system data source, and then controls the candidate system role to access its corresponding role sub-application container according to the second routing rule through the target routing container for calling the application program.

[0147] By determining the candidate role identifiers corresponding to each candidate system role respectively, and according to the candidate role identifiers corresponding to each candidate system role respectively and the second application container port information, generate a second routing rule for the target routing container in the target application system; through the target routing container, control each candidate system role to access the corresponding role sub-application container respectively for calling the application program. The beneficial effects are as follows:

[0148] First, through the binding of the candidate role identifier and the application container port information, it is ensured that the candidate system role can only access the authorized role sub-application container, preventing unauthorized operations and enhancing the data security of the candidate system role.

[0149] Second, when adding a new candidate system role or role sub-application container, only the routing rule needs to be updated, without reconstructing the overall architecture, to meet the requirements of rapid iteration.

[0150] Optionally, controlling each candidate system role to access the corresponding role sub-application container respectively through the target routing container according to the second routing rule includes:

[0151] B21. Through the target routing container, determine the candidate role identifier of the candidate system role associated with the candidate system data source according to the second application call request sent by any candidate system data source as the first role identifier.

[0152] In one embodiment, any candidate system user sends a second application call request containing its candidate role identifier to the target application system through its associated candidate system data source. The target application system parses the second application call request through the target routing container and obtains the candidate role identifier of the candidate system user as the first role identifier.

[0153] B22. Through the target routing container, determine the second application container port information associated with the first role identifier according to the first role identifier and the second routing rule as the second port information to be accessed.

[0154] Exemplarily, assume that there is an association between the first role identifier "aabb" and the second application container port information "90" in the second routing rule. Then, the target routing container determines the second application container port information "90" associated with the first role identifier "aabb" based on the first role identifier "aabb" and the second routing rule, and uses it as the second port information to be accessed.

[0155] B23. The target routing container forwards the second application program call request based on the second port information to be accessed, to control the candidate system role associated with the candidate system data source to access the corresponding role sub-application container.

[0156] In one implementation, the target application system determines the role sub-application container corresponding to the candidate system role through the target routing container based on the second port information to be accessed, and then forwards the second application program call request to the role sub-application container corresponding to the candidate system role, so that the candidate system role can access the role sub-application container corresponding to the candidate system role for application program calls.

[0157] The target routing container determines the candidate role identifier of the candidate system role associated with the candidate system data source based on the second application program call request sent by any candidate system data source, and uses it as the first role identifier; the target routing container determines the second application container port information associated with the first role identifier based on the first role identifier and the second routing rule, and uses it as the second port information to be accessed; the target routing container forwards the second application program call request based on the second port information to be accessed, to control the candidate system role associated with the candidate system data source to access the corresponding role sub-application container. The beneficial effects are as follows:

[0158] First, based on the dynamic matching mechanism of the role identifier and the second routing rule, it realizes the automatic mapping of port resources and system roles, avoiding manual maintenance of the port mapping table.

[0159] Second, the target application system can deploy multiple isolated role sub-application containers, and realizes traffic isolation through the second routing rule, ensuring precise control of data access permissions and resource allocation.

[0160] S303. Update the current container context parameters according to the target public code, candidate role code, and second application container port information, and generate second container context parameters corresponding to each candidate system role.

[0161] In one embodiment, determine the container interface corresponding to the main application container, such as the ServletContext interface, and extract the current container context parameters of the main application container through the container interface. Further, determine the third position in the current container context parameters for describing the system code, and the second position for describing the application container port information. Then, update the second application container port information corresponding to any candidate system role to the second position, and update the target common code and the candidate role code corresponding to the candidate system role to the third position, and use the current container context parameters with updated parameters as the second container context parameters corresponding to the candidate system role.

[0162] S304. According to the current container context type of the main application container and the second container context parameters, generate corresponding role sub-application containers for each candidate system role in the target application system.

[0163] Among them, each candidate system role calls the application program through its corresponding role sub-application container.

[0164] In one embodiment, determine the container interface corresponding to the main application container, such as the ServletContext interface, and extract the current container context type of the main application container through the container interface. Further, input the current container context type and the second container context parameters into the container generation tool, so that the container generation tool generates corresponding role sub-application containers for each candidate system role in the target application system based on the current container context type and the second container context parameters. For example, assume that the second container context parameters corresponding to candidate system role 1 are container context parameter B. Then, input the current container context type and container context parameter B into the container generation tool, so that the container generation tool generates the corresponding role sub-application container for candidate system role 1 in the target application system based on the current container context type and container context parameter B.

[0165] Further, construct a target routing container according to the candidate role identifiers and the second application container port information corresponding to each candidate system role respectively. Through the target routing container, parse the candidate role identifier according to the application program call request sent by any candidate data source, and determine the associated second application container port information according to the candidate role identifier. Then, route the application program call request to the role sub-application container corresponding to the second application container port information according to the second application container port information, so that the candidate system role calls the application program through the role sub-application container.

[0166] In the embodiment of the present invention, corresponding role sub-application containers are generated for each candidate system role in the target application system, and each candidate system role calls the application program through the corresponding role sub-application container, thereby achieving the effect of isolating the process of system role calling the application program from each other, reducing the risk of role data leakage when the system role calls the application program, and improving the data security of the application system.

[0167] Optionally, after determining the number of databases of the candidate databases configured in the target application system, it further includes:

[0168] A3. If the number of databases is at least two, obtain the candidate table metadata information corresponding to each candidate database, and compare the candidate table metadata information to determine whether the candidate table metadata information is the same.

[0169] B3. If any two pieces of candidate table metadata information are different, obtain at least one target interceptor included in the target application system.

[0170] Wherein, the target interceptor is a programming mechanism for dynamically intercepting requests or method calls, mainly used to insert additional processing logic before and after the execution of the core business logic of the target application system.

[0171] In one implementation manner, if any two pieces of candidate table metadata information are different, obtain at least one target interceptor included in the target application system according to the interceptor registry of the target application system.

[0172] C3. According to the decompilation result of the code of each target interceptor, determine whether each target interceptor has performed a data source switching operation for the main application container.

[0173] In one implementation manner, decompile the code of each target interceptor, and according to the decompilation result of the code of each target interceptor, identify whether each target interceptor has performed a data source switching operation for the main application container.

[0174] D3. If any one of the target interceptors has performed a data source switching operation for the main application container, determine that the number of system roles is at least two.

[0175] If the number of databases is at least two, obtain the candidate table metadata information corresponding to each candidate database, compare the candidate table metadata information, and determine whether the candidate table metadata information is the same; if any two pieces of candidate table metadata information are different, obtain at least one target interceptor included in the target application system; according to the decompiled code results of each target interceptor, determine whether each target interceptor has performed a data source switching operation for the main application container; if any target interceptor has performed a data source switching operation for the main application container, determine that the number of system roles is at least two, achieving the effect of automatically identifying the number of system roles, reducing the manual inspection cost, and improving the efficiency of identifying the number of system roles.

[0176] Optionally, after determining whether each target interceptor has performed a data source switching operation for the main application container, it further includes:

[0177] If none of the target interceptors have performed a data source switching operation for the main application container, determine whether the object-relational mapping framework of the target application system has performed a data source scheduling operation; if it has performed a data source scheduling operation, determine that the number of system roles is at least two.

[0178] Among them, the object-relational mapping framework, also known as the orm framework, is a technical tool for solving the data mapping between object-oriented programming languages and relational databases.

[0179] In one implementation, if none of the target interceptors have performed a data source switching operation for the main application container, determine whether the object-relational mapping framework of the target application system has performed a data source scheduling operation through the where parameter of the SQL statement; if it has performed a data source scheduling operation, determine that the number of system roles is at least two.

[0180] By determining whether the object-relational mapping framework of the target application system has performed a data source scheduling operation if none of the target interceptors have performed a data source switching operation for the main application container; if it has performed a data source scheduling operation, determine that the number of system roles is at least two, the efficiency and accuracy of determining the number of system roles are guaranteed.

[0181] Embodiment 4

[0182] Figure 4 The following is a schematic structural diagram of a calling device for an application program provided in Embodiment 4 of the present invention, which is applicable to the situation where a system user calls an application program through a dedicated user sub-application container. As Figure 4 shown, the device includes:

[0183] A system user number identification module 41, configured to determine whether the number of system users of the candidate system users included in the target application system is at least two;

[0184] An information acquisition module 42, configured to, if it is determined that the number of system users is at least two, acquire candidate data source information of candidate system data sources associated with each of the candidate system users, and acquire first application container port information separately allocated for each of the candidate system users;

[0185] A first context parameter generation module 43, configured to update the current container context parameters according to the candidate data source information and the first application container port information, and generate first container context parameters respectively corresponding to each of the candidate system users; wherein, the current container context parameters are the container context parameters of the main application container of the target application system, and the main application container provides an application program that can be called;

[0186] A user sub-application container generation module 44, configured to generate corresponding user sub-application containers for each of the candidate system users in the target application system according to the current container context type of the main application container and the first container context parameters; wherein, each of the candidate system users calls the application program through the corresponding user sub-application container.

[0187] Optionally, the first context parameter generation module 43 is specifically configured to:

[0188] Determine the current data source information and the current application container port information included in the current container context parameters;

[0189] Update the current data source information to the candidate data source information corresponding to any one of the candidate system users, and update the current application container port information to the first application container port information corresponding to the candidate system user;

[0190] Determine the first container context parameters corresponding to the candidate system user according to the updated current container context parameters.

[0191] Optionally, the device further includes a first routing rule generation module, specifically configured to:

[0192] Determine candidate user identifiers respectively corresponding to each of the candidate system users, and generate a first routing rule for a target routing container in the target application system according to the candidate user identifiers respectively corresponding to each of the candidate system users and the first application container port information;

[0193] Control each of the candidate system users to access the corresponding user sub-application container through the target routing container according to the first routing rule, for calling the application program.

[0194] Optionally, the first routing rule generation module is further specifically configured to:

[0195] Based on the first application call request sent by any one of the candidate system data sources through the target routing container, determine the candidate user identifier of the candidate system user associated with the candidate system data source as the first user identifier;

[0196] Based on the first user identifier and the first routing rule through the target routing container, determine the first application container port information associated with the first user identifier as the first port information to be accessed;

[0197] Forward the first application call request through the target routing container according to the first port information to be accessed, for controlling the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

[0198] Optionally, the system user quantity identification module 41 is specifically configured to:

[0199] Determine the quantity of databases of the candidate databases configured by the target application system. If the quantity of databases is at least two, obtain the candidate table metadata information corresponding to each of the candidate databases;

[0200] Compare the candidate table metadata information to determine whether the candidate table metadata information is the same;

[0201] If the candidate table metadata information is the same, determine whether the database scheduling mechanism of the target application system is the target scheduling mechanism; wherein, the target scheduling mechanism is a scheduling mechanism for switching databases based on user identifiers;

[0202] If the database scheduling mechanism of the target application system is the target scheduling mechanism, determine that the quantity of system users is at least two.

[0203] Optionally, the device further includes a role sub-application container generation module, specifically configured to:

[0204] Determine whether the quantity of system roles of the candidate system roles included in the target application system is at least two;

[0205] If it is determined that the quantity of system roles is at least two, obtain the target common code of the target application system, the candidate role codes corresponding to each of the candidate system roles, and the second application container port information separately allocated for each of the candidate system roles;

[0206] Update the current container context parameters according to the target common code, the candidate role codes, and the second application container port information, and generate second container context parameters corresponding to each of the candidate system roles;

[0207] Generate corresponding role sub - application containers for each of the candidate system roles in the target application system according to the current container context type of the main application container and the second container context parameter; wherein, each of the candidate system roles calls the application program through the corresponding role sub - application container.

[0208] Optionally, the role sub - application container generation module is further specifically configured to:

[0209] Construct a first scanning expression according to the first package name of the target code package in the target application system; wherein, the target code package is a system code package and / or a tool code package.

[0210] Scan the system code of the target application system using the first scanning expression, and determine the target common code of the target application system according to the scanning result.

[0211] Optionally, the role sub - application container generation module is further specifically configured to:

[0212] Determine the role routing rule corresponding to a candidate system role according to the candidate role identifier corresponding to any one of the candidate system roles, and determine the system routing address corresponding to the candidate system role according to the role routing rule.

[0213] Match the system routing address with the control class address of the candidate control class in the main application container, and determine the target control class from the candidate control classes according to the matching result.

[0214] Construct a second scanning expression according to the second package name of the class code package corresponding to the target control class, and scan the system code of the target application system using the second scanning expression, and determine the candidate role code corresponding to the candidate system role according to the scanning result.

[0215] Optionally, the device further includes a second routing rule generation module, which is specifically configured to:

[0216] Determine the candidate role identifiers corresponding to each of the candidate system roles, and generate a second routing rule for the target routing container in the target application system according to the candidate role identifiers corresponding to each of the candidate system roles and the second application container port information.

[0217] Control each of the candidate system roles to access the corresponding role sub - application container through the target routing container according to the second routing rule for calling the application program.

[0218] Optionally, the second routing rule generation module is further specifically configured to:

[0219] Based on the second application call request sent by any one of the candidate system data sources through the target routing container, determine the candidate role identifier of the candidate system role associated with the candidate system data source as the first role identifier;

[0220] Based on the first role identifier and the second routing rule through the target routing container, determine the second application container port information associated with the first role identifier as the second port information to be accessed;

[0221] Forward the second application call request through the target routing container according to the second port information to be accessed, for controlling the candidate system role associated with the candidate system data source to access the corresponding role sub-application container.

[0222] Optionally, the role sub-application container generation module is further specifically configured to:

[0223] Determine the number of databases of the candidate databases configured by the target application system. If the number of databases is one, obtain the candidate table metadata information corresponding to the candidate database as the target table metadata information;

[0224] Determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification;

[0225] If the target user type field is used for user classification, determine whether the target user type field contains target user characteristics, otherwise determine that the number of system roles is at least two; wherein the target user characteristics are user characteristics irrelevant to role characteristics.

[0226] Optionally, the device further includes a target interceptor acquisition module, specifically configured to:

[0227] If the number of databases is at least two, obtain the candidate table metadata information corresponding to each of the candidate databases, and compare the candidate table metadata information to determine whether the candidate table metadata information is the same;

[0228] If any two of the candidate table metadata information are different, obtain at least one target interceptor included in the target application system;

[0229] Based on the decompiled code results of each of the target interceptors, determine whether each of the target interceptors has performed a data source switching operation for the main application container;

[0230] If any of the target interceptors has performed a data source switching operation for the main application container, determine that the number of system roles is at least two.

[0231] Optionally, the device further includes a data source scheduling operation recognition module, specifically configured to:

[0232] If none of the target interceptors has performed a data source switching operation for the main application container, determine whether the object-relational mapping framework of the target application system has performed a data source scheduling operation;

[0233] If the data source scheduling operation has been performed, determine that the number of system roles is at least two.

[0234] The application program calling device provided by the embodiments of the present invention can execute the application program calling method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0235] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0236] Embodiment Five

[0237] Figure 5 FIG. shows a schematic structural diagram of an electronic device 50 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0238] As Figure 5As shown, the electronic device 50 includes at least one processor 51 and a memory communicatively connected to the at least one processor 51, such as a read-only memory (ROM) 52, a random access memory (RAM) 53, etc. The memory stores computer programs executable by the at least one processor. The processor 51 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 52 or the computer programs loaded from the storage unit 58 into the random access memory (RAM) 53. In the RAM 53, various programs and data required for the operation of the electronic device 50 can also be stored. The processor 51, the ROM 52, and the RAM 53 are connected to each other via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.

[0239] Multiple components in the electronic device 50 are connected to the I / O interface 55, including: an input unit 56, such as a keyboard, a mouse, etc.; an output unit 57, such as various types of displays, speakers, etc.; a storage unit 58, such as a disk, an optical disc, etc.; and a communication unit 59, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 59 allows the electronic device 50 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0240] The processor 51 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 51 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 51 executes the various methods and processes described above, such as the method for calling an application program.

[0241] In some embodiments, the method for calling an application program can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 58. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 50 via the ROM 52 and / or the communication unit 59. When the computer program is loaded into the RAM 53 and executed by the processor 51, one or more steps of the method for calling an application program described above can be executed. Alternatively, in other embodiments, the processor 51 can be configured to execute the method for calling an application program by any other appropriate means (e.g., by means of firmware).

[0242] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.

[0243] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.

[0244] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0245] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and the input received from the user can be in any form (including acoustic input, voice input, or tactile input).

[0246] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0247] The computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0248] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0249] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for invoking an application program, characterized in that, The method includes: determining whether the number of system users of candidate system users possessed by a target application system is at least two; if it is determined that the number of system users is at least two, obtaining candidate data source information of candidate system data sources associated with each of the candidate system users, and obtaining first application container port information separately allocated to each of the candidate system users; updating parameters of current container context parameters according to the candidate data source information and the first application container port information, and generating first container context parameters respectively corresponding to each of the candidate system users; wherein the current container context parameters are container context parameters of a main application container of the target application system, and the main application container provides an application program that can be called; generating corresponding user sub-application containers for each of the candidate system users in the target application system according to the current container context type of the main application container and the first container context parameters; wherein each of the candidate system users calls the application program through the corresponding user sub-application container.

2. The method according to claim 1, wherein The updating parameters of current container context parameters according to the candidate data source information and the first application container port information, and generating first container context parameters respectively corresponding to each of the candidate system users includes: determining current data source information and current application container port information included in the current container context parameters; updating the current data source information to the candidate data source information corresponding to any one of the candidate system users, and updating the current application container port information to the first application container port information corresponding to the candidate system user; determining first container context parameters corresponding to the candidate system user according to the updated current container context parameters.

3. The method according to claim 1, characterized in that The method further includes: determining candidate user identifiers respectively corresponding to each of the candidate system users, and generating a first routing rule for a target routing container in the target application system according to the candidate user identifiers respectively corresponding to each of the candidate system users and the first application container port information; controlling each of the candidate system users to access the corresponding user sub-application container respectively through the target routing container according to the first routing rule, for calling the application program.

4. The method according to claim 3, characterized in that, The controlling each of the candidate system users to access the corresponding user sub-application container respectively through the target routing container according to the first routing rule includes: determining, by the target routing container according to a first application program call request sent by any one of the candidate system data sources, the candidate user identifier of the candidate system user associated with the candidate system data source as a first user identifier; determining, by the target routing container according to the first user identifier and the first routing rule, the first application container port information associated with the first user identifier as first port information to be accessed; Forward the first application call request by the target routing container according to the first port information to be accessed, for controlling the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

5. The method according to claim 1, characterized in that, Determining whether the number of system users of the candidate system users of the target application system is at least two includes: Determine the number of databases of the candidate databases configured by the target application system. If the number of databases is at least two, obtain the candidate table metadata information respectively corresponding to each candidate database; Compare the candidate table metadata information, and determine whether the candidate table metadata information is the same; If the candidate table metadata information is the same, determine whether the database scheduling mechanism of the target application system is the target scheduling mechanism; wherein, the target scheduling mechanism is a scheduling mechanism for switching databases based on user identification; If the database scheduling mechanism of the target application system is the target scheduling mechanism, determine that the number of system users is at least two.

6. The method according to claim 1, wherein The method further includes: Determine whether the number of system roles of the candidate system roles of the target application system is at least two; If it is determined that the number of system roles is at least two, obtain the target common code of the target application system, the candidate role codes respectively corresponding to each candidate system role, and the second application container port information separately allocated for each candidate system role; Update the current container context parameters according to the target common code, the candidate role codes, and the second application container port information to generate second container context parameters respectively corresponding to each candidate system role; Generate corresponding role sub-application containers for each candidate system role in the target application system according to the current container context type of the main application container and the second container context parameters; wherein, each candidate system role calls the application through the corresponding role sub-application container.

7. The method according to claim 6, characterized in that, The obtaining the target common code of the target application system includes: Construct a first scanning expression according to the first package name of the target code package in the target application system; wherein, the target code package is a system code package and / or a tool code package; Scan the system code of the target application system with the first scanning expression, and determine the target common code of the target application system according to the scanning result.

8. The method according to claim 6, wherein The obtaining the candidate role codes respectively corresponding to each candidate system role includes: Determine the role routing rule corresponding to the candidate system role according to the candidate role identifier corresponding to any candidate system role, and determine the system routing address corresponding to the candidate system role according to the role routing rule; Match the system routing address with the control class address of the candidate control class in the main application container, and determine the target control class from the candidate control classes according to the matching result; Construct a second scanning expression based on the second package name of the corresponding class code package of the target control class, and use the second scanning expression to scan the system code of the target application system, and determine the candidate role code corresponding to the candidate system role according to the scanning result.

9. The method according to claim 6, characterized in that, The method further includes: Determine the candidate role identifiers corresponding to each of the candidate system roles respectively, and generate a second routing rule for the target routing container in the target application system according to the candidate role identifiers and the second application container port information corresponding to each of the candidate system roles respectively; Control each of the candidate system roles to access the corresponding role sub-application container according to the second routing rule through the target routing container, for invoking the application program.

10. The method according to claim 9, wherein The controlling each of the candidate system roles to access the corresponding role sub-application container according to the second routing rule through the target routing container includes: Determine, by the target routing container according to a second application program call request sent by any one of the candidate system data sources, the candidate role identifier of the candidate system role associated with the candidate system data source as a first role identifier; Determine, by the target routing container according to the first role identifier and the second routing rule, the second application container port information associated with the first role identifier as second port information to be accessed; Forward the second application program call request by the target routing container according to the second port information to be accessed, for controlling the candidate system role associated with the candidate system data source to access the corresponding role sub-application container.

11. The method according to claim 6, characterized in that, The determining whether the number of system roles of the candidate system roles in the target application system is at least two includes: Determine the number of databases of the candidate databases configured in the target application system. If the number of databases is one, obtain the candidate table metadata information corresponding to the candidate database as target table metadata information; Determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification; If the target user type field is used for user classification, determine whether the target user type field contains a target user feature, otherwise determine that the number of system roles is at least two; wherein, the target user feature is a user feature irrelevant to the role feature.

12. The method according to claim 11, wherein, After determining the number of databases of the candidate databases configured in the target application system, it further includes: If the number of databases is at least two, obtain the candidate table metadata information corresponding to each of the candidate databases respectively, and compare the candidate table metadata information to determine whether the candidate table metadata information is the same; If any two of the candidate table metadata information are different, obtain at least one target interceptor included in the target application system; Determine whether each of the target interceptors has performed a data source switching operation on the main application container according to the code decompilation result of each of the target interceptors. If any of the target interceptors has performed a data source switching operation for the main application container, it is determined that the number of system roles is at least two.

13. The method according to claim 12, wherein After determining whether each of the target interceptors has performed a data source switching operation for the main application container, it further includes: If none of the target interceptors has performed a data source switching operation for the main application container, it is determined whether the object-relational mapping framework of the target application system has performed a data source scheduling operation; If the data source scheduling operation has been performed, it is determined that the number of system roles is at least two.

14. A calling device for an application program, characterized in that The device includes: A system user number identification module, configured to determine whether the number of system users of candidate system users in a target application system is at least two; An information acquisition module, configured to, if it is determined that the number of system users is at least two, acquire candidate data source information of candidate system data sources associated with each of the candidate system users, and acquire first application container port information separately allocated to each of the candidate system users; A first context parameter generation module, configured to update the current container context parameters according to the candidate data source information and the first application container port information, and generate first container context parameters corresponding to each of the candidate system users; wherein, the current container context parameters are the container context parameters of the main application container of the target application system, and the main application container provides callable application programs; A user sub-application container generation module, configured to generate corresponding user sub-application containers for each of the candidate system users in the target application system according to the current container context type of the main application container and the first container context parameters; wherein each of the candidate system users calls the application program through the corresponding user sub-application container.

15. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the application program calling method according to any one of claims 1-13.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to execute the application program calling method according to any one of claims 1-13.

17. A computer program product, characterized in that, It includes a computer program which, when executed by a processor, implements the application program calling method according to any one of claims 1-13.

Citation Information

Patent Citations

  • Meeting notice system and method based on context service

    CN101645789A

  • Secure data container for web applications

    CN104603793A

  • Page sharing method, electronic equipment and readable storage medium

    CN115269233A

  • Data isolation protection system, method and equipment and storage medium

    CN117272401A

  • Application execution method and system, electronic equipment and storage medium

    CN117785322A