Application calling method, device, equipment, medium and product

By generating exclusive user sub-application containers for users of each system, the problem of user data leakage in the application system is solved, and the isolation and data security of the application call process are realized.

CN120296723BActive Publication Date: 2025-09-02HANGZHOU NEWGRAND TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510765174.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-09-02
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

In existing application systems, the process of multiple system users calling applications cannot be isolated from each other, resulting in user data leakage.

Method used

The corresponding user sub-application container is generated for each candidate system users in the target application system, and the application is called through the exclusive user sub-application container to ensure the isolation of the call process.

Benefits of technology

It realizes mutual isolation of the process of system users calling applications, reduces the risk of user data leakage, and improves the data security of the application system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296723B_ABST
    Figure CN120296723B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, device, medium, and product for calling an application, relating to the field of computer technology. The method comprises: if it is determined that the number of system users is at least two, obtaining candidate data source information associated with the candidate system user and first application container port information individually allocated for the candidate system user; updating the current container context parameters based on the candidate data source information and the first application container port information to generate first container context parameters corresponding to the candidate system user; generating a corresponding user sub-application container for the candidate system user based on the current container context type and the first container context parameters; wherein the candidate system user calls the application through the corresponding user sub-application container. The present invention achieves the effect of isolating the processes of system users calling applications from each other, reducing the risk of user data leakage when system users call applications, and improving the data security of the application system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method, apparatus, device, medium and product for calling an application program. Background Art

[0002] In the digital age, various industries are undergoing digital transformation, and the demand for digitalization is exploding. Application systems are a typical example of digital systems in this era. Application systems are integrated solutions consisting of software, hardware, and data resources, designed to solve specific business problems or meet specific functional requirements.

[0003] An application system usually has multiple system users. In the prior art, multiple system users call applications through the application container of the application system. The application system uses permission verification to control the calls of different system users to the application.

[0004] However, this method cannot isolate the process of each system user calling the application program from each other, and the problem of user data leakage of system users still exists, resulting in insufficient data security of the application system. Summary of the Invention

[0005] The present invention provides a method, apparatus, device, medium and product for calling an application program to solve the problem that existing application systems have insufficient data security, resulting in easy leakage of user data.

[0006] According to one aspect of the present invention, a method for calling an application is provided, the method comprising:

[0007] determining whether the number of system users of the target application system that are candidate system users is at least two;

[0008] If it is determined that the number of the system users is at least two, then obtaining candidate data source information of the candidate system data source associated with each candidate system user, and obtaining first application container port information individually allocated to each candidate system user;

[0009] updating the current container context parameters based on the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user; wherein the current container context parameters are container context parameters of the primary application container of the target application system, and the primary application container provides a callable application;

[0010] Based on the current container context type of the main application container and the first container context parameter, a corresponding user sub-application container is generated for each candidate system user in the target application system; wherein each candidate system user calls the application through the corresponding user sub-application container.

[0011] According to another aspect of the present invention, a device for calling an application is provided, the device comprising:

[0012] a system user quantity identification module, configured to determine whether the number of candidate system users of the target application system is at least two;

[0013] an information acquisition module, configured to, if it is determined that the number of the system users is at least two, acquire candidate data source information of a candidate system data source associated with each candidate system user, and acquire first application container port information individually allocated to each candidate system user;

[0014] a first context parameter generation module configured to update current container context parameters based on the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user; wherein the current container context parameters are container context parameters of a primary application container of the target application system, and the primary application container provides a callable application;

[0015] A user sub-application container generation module is used to generate a corresponding user sub-application container for each candidate system user in the target application system based on the current container context type of the main application container and the first container context parameter; wherein each candidate system user calls the application through the corresponding user sub-application container.

[0016] According to another aspect of the present invention, an electronic device is provided, comprising:

[0017] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for calling an application program described in any one of the present inventions.

[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement any one of the application calling methods of the present invention when executed.

[0019] According to another aspect of the present invention, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method for calling an application program according to any one of the present inventions.

[0020] The present invention generates a corresponding user sub-application container for each candidate system user in the target application system, and each candidate system user calls the application through the corresponding user sub-application container, thereby isolating the processes of system users calling the application from each other, reducing the risk of user data leakage when the system user calls the application, and improving the data security of the application system.

[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0023] Figure 1 A flowchart of a method for calling an application program provided in the first embodiment of the present invention;

[0024] Figure 2 A flowchart of a method for calling an application program provided in the second embodiment of the present invention;

[0025] Figure 3 A flowchart of a method for calling an application program provided in Embodiment 3 of the present invention;

[0026] Figure 4 A schematic diagram of the structure of a device for calling an application program provided in a fourth embodiment of the present invention;

[0027] Figure 5 The present invention is a schematic diagram of the structure of an electronic device for implementing the method for calling an application program according to an embodiment of the present invention. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first", "second", "candidate", "target", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0030] Example 1

[0031] Figure 1 This is a flow chart of a method for calling an application provided in the first embodiment of the present invention. This embodiment is applicable to the case where a system user calls an application through a dedicated user sub-application container. The method can be executed by an application calling device, which can be implemented in the form of hardware and / or software, such as by an application system. Figure 1 As shown, the method includes:

[0032] S101: Determine whether the number of candidate system users of the target application system is at least two.

[0033] The candidate system users represent system users of the target application system. System users, also known as system tenants, are users with specific permissions and functional access rights who directly operate or manage the application system. It is understood that the target application system can have one or more candidate system users.

[0034] When the number of system users is one, it indicates that the target application system is a single-user system. Since a single-user system has only one system user accessing the application container to call the application, and no other system users access the application container to call the application, there is no risk of system user data leakage.

[0035] If there are multiple system users (i.e., at least two), the target application system is a multi-user system. Different system users may access the application container and invoke applications, posing a risk of system user data leakage. Therefore, it is necessary to identify the number of system users in the target application system to determine whether the target application system is at risk of system user data leakage.

[0036] In one embodiment, the system management backend of the target application system is accessed, and the user management module in the system management backend is further accessed. The system user list is viewed through the user management module, and it is further determined based on the system user list whether the number of system users is at least two.

[0037] In another embodiment, a system access log of the target application system is obtained, and system access users of the target application system in a historical time period are determined based on the system access log, and whether the number of system users is at least two is determined based on the system access users.

[0038] In another embodiment, the number of databases of the candidate databases configured for the target application system is determined. If the number of databases is at least two, the candidate table metadata information of each candidate database is further compared. If the metadata information of each candidate table is the same, it is identified whether the database scheduling mechanism of the target application system is a scheduling mechanism for switching databases based on user identifiers. If so, it is determined whether the number of system users is at least two.

[0039] S102: If it is determined that the number of system users is at least two, obtain candidate data source information of a candidate system data source associated with each candidate system user, and obtain first application container port information individually allocated to each candidate system user.

[0040] The candidate system data source represents the system data source connected to each candidate database configured in the target application system. The system data source provides the data required by the target application system and serves as the core channel for data exchange between the target application system and the outside world. The candidate data source information represents the data source parameters corresponding to the candidate system data source and is the core attribute parameter for configuring the data source connection.

[0041] In this embodiment, candidate system users are associated with candidate data sources. That is, each candidate system user corresponds to a single candidate data source. A candidate system user initiates requests, such as application call requests, to the target application system through the associated candidate data source, thereby enabling data interaction with the target application system. For example, assuming candidate system user 1 is associated with candidate data source A, candidate system user 1 initiates requests to the target application system through candidate data source A, thereby enabling data interaction with the target application system.

[0042] In this embodiment, exclusive application container port information is pre-assigned to each candidate system user as first application container port information, and the first application container port information corresponding to each candidate system user is different. Application container port information is a logical concept used in containerization technology to identify the communication endpoint of the internal process of the application container. It is exposed to the application system through port mapping for accessing the application container. In other words, based on any application container port information, the application container corresponding to the application container port information can be accessed. It can be understood that the exclusive application container port information is individually assigned to each candidate system user, laying the parameter foundation for the subsequent generation of user sub-application containers corresponding to each candidate system user.

[0043] For example, assuming that the target application system has candidate system user 1, candidate system user 2, and candidate system user 3, candidate system user 1 is individually assigned exclusive application container port information "81"; candidate system user 2 is individually assigned exclusive application container port information "82"; and candidate system user 3 is individually assigned exclusive application container port information "83".

[0044] In one embodiment, a system configuration file of the target application system is accessed, and candidate data source information of candidate system data sources associated with each candidate system user is obtained according to the system configuration file, and first application container port information individually allocated to each candidate system user is obtained.

[0045] S103: Update the current container context parameters according to the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user.

[0046] The current container context parameters are those of the target application system's primary application container. The primary application container provides callable applications and is a pre-created application container within the target application system. Application containers are lightweight virtualization technologies used to package applications and their dependencies into independent, portable runtime units. Container context parameters are key configuration items used to initialize and manage the application container's runtime environment. They typically store globally shared information. Application containers can be generated using container context parameters.

[0047] In one embodiment, a container interface corresponding to the primary application container, such as the ServletContext interface, is determined, and the current container context parameters of the primary application container are extracted through the container interface. Furthermore, a first position describing data source information and a second position describing application container port information are determined within the current container context parameters. The candidate data source information corresponding to any candidate system user is then updated to the first position, and the first application container port information corresponding to the candidate system user is updated to the second position. The updated current container context parameters are then used as the first container context parameters corresponding to the candidate system user.

[0048] S104: Generate a corresponding user sub-application container for each candidate system user in the target application system according to the current container context type and the first container context parameter of the main application container.

[0049] The current container context type refers to the container context type corresponding to the main application container. The container context type refers to the container implementation class used to manage the application container bean definition and lifecycle in different application scenarios. Each candidate system user invokes the application through the corresponding user sub-application container.

[0050] In one embodiment, the container interface corresponding to the main application container, such as the ServletContext interface, is determined, and the current container context type of the main application container is extracted through the container interface. Furthermore, the current container context type and the first container context parameter are input into the container generation tool, so that the container generation tool generates corresponding user sub-application containers for each candidate system user in the target application system based on the current container context type and the first container context parameter. For example, assuming that the first container context parameter corresponding to candidate system user 1 is container context parameter A, the current container context type and container context parameter A are input into the container generation tool, so that the container generation tool generates corresponding user sub-application containers for candidate system user 1 in the target application system based on the current container context type and the container context parameter A.

[0051] Furthermore, a target routing container is constructed based on the candidate user identifier and first application container port information corresponding to each candidate system user. The target routing container parses the candidate user identifier based on an application call request sent by any candidate system data source, determines the associated first application container port information based on the candidate user identifier, and then routes the application call request to the user sub-application container corresponding to the first application container port information based on the first application container port information, allowing the candidate system user to call the application through the user sub-application container.

[0052] The embodiment of the present invention generates a corresponding user sub-application container for each candidate system user in the target application system, and each candidate system user calls the application through the corresponding user sub-application container, thereby isolating the processes of system users calling the application from each other, reducing the risk of user data leakage when the system user calls the application, and improving the data security of the application system.

[0053] Example 2

[0054] Figure 2 This is a flowchart of a method for calling an application provided by the second embodiment of the present invention. This embodiment further optimizes and expands the above embodiment and can be combined with the above optional implementation methods. Figure 2 As shown, the method includes:

[0055] S201. Determine the number of candidate databases configured in the target application system. If the number of databases is at least two, obtain the candidate table metadata information corresponding to each candidate database, and compare the candidate table metadata information to determine whether the candidate table metadata information is the same.

[0056] A candidate database refers to at least one database configured in the target application system. It serves as the core data storage and management module that supports the business logic of the target application system. Essentially, it uses database technology to provide structured storage, secure management, and efficient access to the target application system's business data. The candidate database's candidate table metadata is core data used to describe the database table structure, attributes, and relationships, serving as the candidate database's "data dictionary."

[0057] In one embodiment, a system configuration file of a target application system is obtained, database identifiers are identified in the system configuration file, and the number of candidate databases is determined based on the number of identified database identifiers. If the number of databases is at least two, a metadata interface for each candidate database is further called to obtain metadata information about candidate tables corresponding to each candidate database.

[0058] Furthermore, metadata information of the candidate tables corresponding to the candidate databases is compared to determine whether the metadata information of the candidate tables includes the same metadata information.

[0059] S202: If the metadata information of each candidate table is the same, determine whether the database scheduling mechanism of the target application system is the target scheduling mechanism; if the database scheduling mechanism of the target application system is the target scheduling mechanism, determine that the number of system users is at least two.

[0060] The database scheduling mechanism refers to the core component of the target application system used to coordinate task execution and database allocation. Its core objectives are to ensure data consistency, optimize performance, and efficiently handle concurrent operations. The target scheduling mechanism switches databases based on user identification. This mechanism is primarily used in multi-user systems to automatically select the appropriate database for access based on user identification (such as ID or tenant code).

[0061] In one embodiment, if the candidate table metadata information corresponding to each candidate database is the same, the slow query log of the target application system is obtained, and the database scheduling mechanism of the target application system is further analyzed based on the slow query log. If it is determined that the database scheduling mechanism of the target application system is a "scheduling mechanism based on SQL statement execution", it means that the target application system is in a read-write separation state and no processing is performed; if it is determined that the database scheduling mechanism of the target application system is a target scheduling mechanism, that is, a scheduling mechanism that switches databases based on user identifiers, then the number of system users is determined to be at least two.

[0062] By determining the number of candidate databases configured in the target application system, if the number of databases is at least two, obtaining the candidate table metadata information corresponding to each candidate database; comparing the metadata information of each candidate table to determine whether the metadata information of each candidate table is the same; if the metadata information of each candidate table is the same, determining whether the database scheduling mechanism of the target application system is the target scheduling mechanism; if the database scheduling mechanism of the target application system is the target scheduling mechanism, determining that the number of system users is at least two, the beneficial effects are:

[0063] First, it achieves the effect of automatically identifying the number of system users, reduces manual inspection costs, and improves the efficiency of identifying the number of system users.

[0064] Secondly, by comparing table metadata information and identifying the database scheduling mechanism, the time spent on identifying the number of system users is shortened, and the accuracy of identifying the number of system users can be guaranteed.

[0065] S203: If it is determined that the number of system users is at least two, obtain candidate data source information of the candidate system data source associated with each candidate system user, and obtain first application container port information individually allocated to each candidate system user.

[0066] S204. Determine the current data source information and the current application container port information included in the current container context parameters; update the current data source information to the candidate data source information corresponding to any candidate system user, and update the current application container port information to the first application container port information corresponding to the candidate system user.

[0067] The current data source information indicates the data source information of the data source currently supported by the main application container, and the current application container port information indicates the current application container port information of the main application container.

[0068] In one embodiment, the current container context parameters are parsed to determine the current data source information and the current application container port information.

[0069] Furthermore, all current data source information is deleted, and the candidate data source information corresponding to any candidate system user is used as the new current data source information. For example, assuming that the current data source information includes the data source information of data source 1, data source 2, and data source 3, and candidate data source information X corresponding to candidate system user 1, all of this data source information is deleted, and candidate data source information X is used as the new current data source information.

[0070] At the same time, the current application container port information is deleted, and the first application container port information corresponding to the candidate system user is used as the new current application container port information. For example, if the current application container port information is "80" and the first application container port information corresponding to the candidate system user is "81", the current application container port information "80" is deleted, and the first application container port information "81" is used as the new current data source information.

[0071] By determining the current data source information and the current application container port information included in the current container context parameters; updating the current data source information to the candidate data source information corresponding to any candidate system user, and updating the current application container port information to the first application container port information corresponding to the candidate system user, the beneficial effects are:

[0072] First, since the only differences between different candidate system users are the "candidate data source information" and the "first application container port information", the current container context parameters are updated only based on the "candidate data source information" and the "first application container port information" without changing other information in the current container context parameters. This can not only ensure the efficiency of generating the first container context parameters, but also ensure that the user sub-application container generated based on the first container context parameters can still provide applications normally.

[0073] Secondly, it can ensure that different candidate system users operate independent user sub-application containers, avoid data mixing or unauthorized access, and further ensure the data security of each candidate system user.

[0074] S205: Determine a first container context parameter corresponding to the candidate system user according to the updated current container context parameter.

[0075] S206 : Generate a corresponding user sub-application container for each candidate system user in the target application system according to the current container context type and the first container context parameter of the main application container.

[0076] Each candidate system user calls the application program through the corresponding user sub-application container.

[0077] In one embodiment, after generating user sub-application containers corresponding to each candidate system user, all application layer beans of the main application container are removed to ensure that the main application container and each user sub-application container are isolated from each other, so that the main application container no longer provides callable applications, but instead each user sub-application container provides callable applications to the corresponding candidate system users.

[0078] Optionally, the method further includes:

[0079] A1. Determine candidate user identifiers corresponding to respective candidate system users, and generate first routing rules for a target routing container in a target application system based on the candidate user identifiers corresponding to respective candidate system users and first application container port information.

[0080] The candidate user identifier is a naming symbol used to uniquely identify a candidate user or a candidate user-defined element. The target routing container is the routing container set up in the target application system. The routing container is a core component used to manage network communication paths in a containerized environment. Its functionality is similar to that of a router in a traditional network, but it is designed specifically for container architectures.

[0081] In one embodiment, the candidate user identifiers and first application container port information corresponding to each candidate system user are placed in the target routing container for port orchestration, thereby constructing a first routing rule between each candidate user identifier and each first application container port information.

[0082] For example, candidate system user 1 corresponds to candidate user identifier "V" and first application container port information "85". The candidate user identifier "V" and the first application container port information "85" are placed in the target routing container for port orchestration, and the first routing rule between the candidate user identifier "V" and the first application container port information "85" is constructed.

[0083] B1. Control each candidate system user to access the corresponding user sub-application container according to the first routing rule through the target routing container to call the application program.

[0084] In one embodiment, the target application system obtains a first application call request sent according to any candidate system data source, determines a candidate user identifier of a candidate system user associated with the candidate system data source, and then controls the candidate system user to access its corresponding user sub-application container according to the first routing rule through the target routing container based on the candidate user identifier to call the application.

[0085] By determining the candidate user identifiers corresponding to each candidate system user, and generating a first routing rule for a target routing container in a target application system based on the candidate user identifiers and the first application container port information corresponding to each candidate system user, and controlling each candidate system user to access the corresponding user sub-application container according to the first routing rule through the target routing container to call the application program, the beneficial effects are:

[0086] First, by binding the candidate user ID with the application container port information, it ensures that the candidate system user can only access the authorized user sub-application container, preventing unauthorized operations and improving the data security of the candidate system user.

[0087] Secondly, when adding candidate system users or user sub-application containers, only the routing rules need to be updated without the need to reconstruct the overall architecture to adapt to the needs of rapid iteration.

[0088] Optionally, controlling each candidate system user to access the corresponding user sub-application container according to the first routing rule through the target routing container includes:

[0089] B11. Determine, through the target routing container, a candidate user identifier of a candidate system user associated with any candidate system data source based on the first application call request sent by the candidate system data source, as the first user identifier.

[0090] In one embodiment, any candidate system user sends a first application call request containing their candidate user identifier to the target application system through their associated candidate system data source. The target application system parses the first application call request through the target routing container and obtains the candidate user identifier of the candidate system user as the first user identifier.

[0091] B12. Determine, through the target routing container according to the first user identifier and the first routing rule, the first application container port information associated with the first user identifier as the first port information to be accessed.

[0092] For example, assuming that there is an association between the first user identifier "xxyy" and the first application container port information "83" in the first routing rule, the target routing container determines the first application container port information "83" associated with the first user identifier "xxyy" according to the first user identifier "xxyy" and the first routing rule as the first port information to be accessed.

[0093] B13. Forwarding the first application call request according to the first port to be accessed through the target routing container, so as to control the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

[0094] In one embodiment, the target application system determines the user sub-application container corresponding to the candidate system user based on the first port to be accessed through the target routing container, and then forwards the first application call request to the user sub-application container corresponding to the candidate system user, so that the candidate system user can access the user sub-application container corresponding to the candidate system user for calling the application.

[0095] The target routing container determines, based on a first application call request sent by any candidate system data source, a candidate user identifier of a candidate system user associated with the candidate system data source as the first user identifier; the target routing container determines, based on the first user identifier and a first routing rule, first application container port information associated with the first user identifier as the first port information to be accessed; and the target routing container forwards the first application call request based on the first port information to be accessed, so as to control the candidate system user associated with the candidate system data source to access the corresponding user sub-application container. The beneficial effects are:

[0096] Firstly, based on the dynamic matching mechanism between the user identifier and the first routing rule, automatic mapping between port resources and system users is achieved, thus avoiding manual maintenance of the port mapping table.

[0097] Secondly, the target application system can deploy multiple isolated user sub-application containers, achieve traffic isolation through the first routing rule, and ensure precise control of data access rights and resource allocation.

[0098] Example 3

[0099] Figure 3 This is a flowchart of a method for calling an application provided by the third embodiment of the present invention. This embodiment further optimizes and expands the above embodiment and can be combined with the above optional implementations. This embodiment is applicable to the situation where different system roles call applications through exclusive role sub-application containers. Figure 3 As shown, the method includes:

[0100] S301: Determine whether the number of candidate system roles of the target application system is at least two.

[0101] Among them, the candidate system role represents the system role of the target application system. The system role is a set of predefined permissions used to identify the responsibilities and operation scope of the system user in the application system, that is, one system user corresponds to one system role.

[0102] It is understood that the target application system can have one or more candidate system roles. When there is only one system role, it indicates that the target application system is a single-role system. Because a single-role system only has one system role accessing the application container to invoke applications, and no other system roles can access the application container to invoke applications, there is no risk of system role data leakage.

[0103] If there are multiple system roles (i.e., at least two), the target application system is a multi-role system. Different system roles may access the application container and invoke applications, posing a risk of system role data leakage. Therefore, it is necessary to identify the number of system roles in the target application system to determine whether the target application system is at risk of system role data leakage.

[0104] In one embodiment, the user details page of each candidate system user in the target application system is obtained, and the candidate system role to which each candidate system user belongs is determined based on each user details page, and then all candidate system roles are counted to determine whether the number of system roles of the candidate system roles is at least two.

[0105] In another embodiment, a role list of the target application system is obtained through a REST API of the target application system, and then it is determined whether the number of system roles of the candidate system roles is at least two according to the role list.

[0106] In another embodiment, the number of databases of the candidate databases configured for the target application system is determined; if the number of databases is one, it is determined whether the target user type field in the target system user table is used for user classification; if so, the number of system roles is determined to be at least two; if the number of databases is at least two, it is determined whether the target interceptor of the target application system has executed a data source switching operation for the main application container; if so, the number of system roles is determined to be at least two.

[0107] Optionally, determining whether the target application system has at least two candidate system roles includes:

[0108] S3011. Determine the number of candidate databases configured in the target application system. If the number of databases is one, obtain candidate table metadata information corresponding to the candidate database as target table metadata information.

[0109] For example, assuming that the target application system is only configured with the candidate database A, the candidate table metadata information corresponding to the candidate database A is used as the target table metadata information.

[0110] S3012: Determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification.

[0111] The target system user table is a structured data table within the target application system that stores core information about system users. The target user type field is a core field within the target system user table that distinguishes user roles or permission levels. This field typically implements differentiated management and control of user groups through codes, identifiers, or category names.

[0112] In one embodiment, based on the target table metadata, it is determined whether the table names of various system tables in the target application system include target keywords, including but not limited to account keywords, password keywords, or the "USER" keyword. The system tables containing the target keywords are then designated as target system user tables. Furthermore, the target user type field contained in the target system user table is detected to determine whether the target user type field is used for user classification.

[0113] S3013: If the target user type field is used for user classification, determine whether the target user type field contains target user features; if not, determine that the number of system roles is at least two.

[0114] Among them, target user characteristics are user characteristics that are unrelated to role characteristics, such as job characteristics.

[0115] In one embodiment, it is determined whether the target user type field is used for user classification. If the target user type field is used for user classification, it is further determined whether the target user type field contains user characteristics unrelated to role characteristics. If not, it is determined that the number of system roles is at least two.

[0116] By determining the number of candidate databases configured for the target application system, if the number of databases is one, obtaining the candidate table metadata information corresponding to the candidate database as the target table metadata information; determining the target system user table of the target application system based on the target table metadata information, and determining whether the target user type field in the target system user table is used for user classification; if the target user type field is used for user classification, determining whether the target user type field contains target user characteristics, if not, determining the number of system roles to be at least two, thereby ensuring the accuracy and efficiency of determining the number of system roles.

[0117] S302: If it is determined that the number of system roles is at least two, obtain the target common code of the target application system, the candidate role code corresponding to each candidate system role, and the second application container port information allocated separately for each candidate system role.

[0118] The target common code refers to the system common code set in the target application system. The system common code refers to standardized code snippets reused within the target application system. The candidate role code is a role code unique to each candidate system role. The role code is a coding system used to uniquely identify the permissions of different candidate system roles. Its meaning is usually closely related to the system function module, operation permissions, or business responsibilities.

[0119] In this embodiment, dedicated application container port information is pre-assigned to each candidate system role as the second application container port information. The second application container port information is different for each candidate system role. As can be understood, assigning dedicated application container port information to each candidate system role lays the parameter foundation for subsequently generating the corresponding role sub-application container for each candidate system role.

[0120] In one embodiment, code analysis is performed on the target application system to obtain the target common code of the target application system and the candidate role codes corresponding to each candidate system role. Furthermore, a system configuration file of the target application system is accessed to obtain, based on the system configuration file, the second application container port information individually allocated for each candidate system role.

[0121] Optionally, obtain the target public code of the target application system, including:

[0122] A first scanning expression is constructed according to the first package name of the target code package in the target application system; the system code of the target application system is scanned using the first scanning expression, and the target common code of the target application system is determined according to the scanning result.

[0123] Among them, the target code package is a system code package and / or a tool code package. The system code package is a code collection used to encapsulate functional modules in the development of the target application system, usually including program source code, dependent libraries, configuration files and other resources. The tool code package is a modular function collection used to improve efficiency in the development of the target application system, usually in the form of a function library, SDK or framework plug-in. It is understandable that both the system code package and the tool code package contain the target common code of the target application system. The first package name is used to uniquely identify the target code package in the global scope of the target application system. The first scanning expression is constructed based on the first package name and is used to match and filter the package path of the target code package.

[0124] In one embodiment, code packages of a target application system are identified, and the system code packages and tool code packages contained in the target application system are determined as target code packages. Furthermore, the package names of the target code packages are extracted as first package names, and a first scanning expression is constructed based on the first package names. The system code of the target application system is scanned using the first scanning expression, and the system code scanned based on the first scanning expression is used as the target common code.

[0125] By constructing a first scanning expression according to the first package name of the target code package in the target application system; scanning the system code of the target application system using the first scanning expression, and determining the target common code of the target application system according to the scanning result, the beneficial effects are:

[0126] First, by constructing the first scanning expression through the first package name, the target common code across modules such as basic tool classes and general configurations in the target application system can be quickly located, thereby improving the efficiency of determining the target common code.

[0127] Secondly, by using the first scanning expression to scan the system code of the target application system to determine the target common code, the accuracy of the determination of the target common code can be guaranteed.

[0128] Optionally, obtain the candidate role code corresponding to each candidate system role, including:

[0129] S3021: Determine a role routing rule corresponding to any candidate system role according to a candidate role identifier corresponding to the candidate system role, and determine a system routing address corresponding to the candidate system role according to the role routing rule.

[0130] The candidate role ID is a key field used to uniquely identify and distinguish different candidate system roles. Role routing rules dynamically control access rights to target application system interfaces based on candidate system roles. Role routing rules can be, for example, Vue routing rules. The system routing address refers to the routing address corresponding to the candidate system role in the target application system, which can be a URL, for example.

[0131] In one embodiment, based on the candidate role identifier corresponding to any candidate system role, the Vue code routing is scanned to determine the routing rules of the candidate system role in Vue as the role routing rules. Based on the role routing rules, the URL address corresponding to the candidate system role in the target application system is determined as the system routing address corresponding to the candidate system role.

[0132] S3022: Match the system routing address with the control class address of the candidate control class in the main application container, and determine the target control class from the candidate control classes according to the matching result.

[0133] The candidate control class refers to the class in the main application container that models the control behavior of a specific use case or business logic. The control class address is the address information of each candidate control class in the target application system.

[0134] In one embodiment, the system routing address corresponding to the candidate system role is matched with the control class address of the candidate control class in the main application container, and the candidate control class whose control class address matches the system routing address is used as the target control class.

[0135] S3023. Construct a second scanning expression according to the second package name of the class code package corresponding to the target control class, and use the second scanning expression to scan the system code of the target application system, and determine the candidate role code corresponding to the candidate system role according to the scanning result.

[0136] The second package name is used to uniquely identify the target control class corresponding class code package in the global scope of the target application system. The second scanning expression is constructed based on the second package name and is used to match and filter the package path of the target control class corresponding class code package.

[0137] In one embodiment, a class code package corresponding to a target control class is determined, the package name of the class code package is extracted as a second package name, and a second scanning expression is constructed based on the second package name. The system code of the target application system is scanned using the second scanning expression, and the system code scanned based on the second scanning expression is used as the candidate role code corresponding to the candidate system role.

[0138] By determining the role routing rule corresponding to any candidate system role according to the candidate role identifier corresponding to the candidate system role, and determining the system routing address corresponding to the candidate system role according to the role routing rule; matching the system routing address with the control class address of the candidate control class in the main application container, and determining the target control class from the candidate control class according to the matching result; constructing a second scanning expression according to the second package name of the class code package corresponding to the target control class, and using the second scanning expression to scan the system code of the target application system, and determining the candidate role code corresponding to the candidate system role according to the scanning result, the beneficial effects are:

[0139] First, the second scanning expression can quickly identify the candidate role code related to the candidate system role in the system code, thereby ensuring the efficiency of candidate role code identification.

[0140] Secondly, by using the second scanning expression to scan the system code of the target application system to determine the candidate role code, the accuracy of the determination of the candidate role code can be guaranteed.

[0141] Optionally, the method further includes:

[0142] A2. Determine the candidate role identifiers corresponding to the candidate system roles, and generate a second routing rule for the target routing container in the target application system according to the candidate role identifiers corresponding to the candidate system roles and the second application container port information.

[0143] In one embodiment, the candidate role identifiers and second application container port information corresponding to each candidate system role are placed in the target routing container for port orchestration, thereby constructing a second routing rule between each candidate role identifier and each second application container port information.

[0144] For example, candidate system role 1 corresponds to candidate role identifier "Y" and second application container port information "90", then the candidate role identifier "Y" and the second application container port information "90" are placed in the target routing container for port orchestration, and a second routing rule between the candidate role identifier "Y" and the second application container port information "90" is constructed.

[0145] B2. Control each candidate system role to access the corresponding role sub-application container according to the second routing rule through the target routing container to call the application program.

[0146] In one embodiment, the target application system obtains a second application call request sent based on any candidate system data source, determines the candidate role identifier of the candidate system role associated with the candidate system data source, and then controls the candidate system role to access its corresponding role sub-application container according to the second routing rule through the target routing container based on the candidate role identifier for calling the application.

[0147] By determining the candidate role identifiers corresponding to each candidate system role, and generating a second routing rule for the target routing container in the target application system based on the candidate role identifiers and the second application container port information corresponding to each candidate system role; and controlling each candidate system role to access the corresponding role sub-application container according to the second routing rule through the target routing container to call the application program, the beneficial effects are:

[0148] First, by binding the candidate role identifier with the application container port information, it is ensured that the candidate system role can only access the authorized role sub-application container, preventing unauthorized operations and improving the data security of the candidate system role.

[0149] Secondly, when adding a new candidate system role or role sub-application container, only the routing rules need to be updated without reconstructing the overall architecture to adapt to the needs of rapid iteration.

[0150] Optionally, controlling each candidate system role to access the corresponding role sub-application container according to the second routing rule through the target routing container includes:

[0151] B21. Determine, through the target routing container, the candidate role identifier of the candidate system role associated with any candidate system data source according to the second application call request sent by the candidate system data source, as the first role identifier.

[0152] In one embodiment, any candidate system user sends a second application call request containing their candidate role identifier to the target application system through their associated candidate system data source. The target application system parses the second application call request through the target routing container and obtains the candidate role identifier of the candidate system user as the first role identifier.

[0153] B22. Determine, through the target routing container according to the first role identifier and the second routing rule, the second application container port information associated with the first role identifier as the second port information to be accessed.

[0154] For example, assuming that there is an association between the first role identifier "aabb" and the second application container port information "90" in the second routing rule, the target routing container is used to determine the second application container port information "90" associated with the first role identifier "aabb" as the second port information to be accessed based on the first role identifier "aabb" and the second routing rule.

[0155] B23. Forwarding the second application call request according to the second port to be accessed through the target routing container, so as to control the candidate system role associated with the candidate system data source and access the corresponding role sub-application container.

[0156] In one embodiment, the target application system determines the role sub-application container corresponding to the candidate system role based on the second port information to be accessed through the target routing container, and then forwards the second application call request to the role sub-application container corresponding to the candidate system role, so that the candidate system role can access the role sub-application container corresponding to the candidate system role for calling the application.

[0157] The target routing container determines, based on a second application call request sent by any candidate system data source, a candidate role identifier of a candidate system role associated with the candidate system data source as the first role identifier; the target routing container determines, based on the first role identifier and the second routing rule, the port information of the second application container associated with the first role identifier as the second port information to be accessed; and the target routing container forwards the second application call request based on the second port information to be accessed, so as to control the candidate system role associated with the candidate system data source and access the corresponding role sub-application container. The beneficial effects are:

[0158] First, based on the dynamic matching mechanism of the role identifier and the second routing rule, automatic mapping between port resources and system roles is achieved, avoiding manual maintenance of the port mapping table.

[0159] Secondly, the target application system can deploy multiple isolated role sub-application containers, achieve traffic isolation through the second routing rule, and ensure precise control of data access rights and resource allocation.

[0160] S303: Update the current container context parameters according to the target public code, the candidate role code, and the second application container port information to generate second container context parameters corresponding to each candidate system role.

[0161] In one embodiment, a container interface corresponding to the primary application container, such as the ServletContext interface, is determined, and the current container context parameters of the primary application container are extracted through the container interface. Furthermore, a third position for describing the system code and a second position for describing the application container port information are determined within the current container context parameters. The second application container port information corresponding to any candidate system role is then updated to the second position, and the target public code and the candidate role code corresponding to the candidate system role are updated to the third position. The current container context parameters after the parameter updates are used as the second container context parameters corresponding to the candidate system role.

[0162] S304: Generate a corresponding role sub-application container for each candidate system role in the target application system according to the current container context type and the second container context parameter of the main application container.

[0163] Each candidate system role calls the application program through the corresponding role sub-application container.

[0164] In one embodiment, the container interface corresponding to the main application container, such as the ServletContext interface, is determined, and the current container context type of the main application container is extracted through the container interface. Furthermore, the current container context type and the second container context parameter are input into the container generation tool, so that the container generation tool generates corresponding role sub-application containers for each candidate system role in the target application system based on the current container context type and the second container context parameter. For example, assuming that the second container context parameter corresponding to the candidate system role 1 is the container context parameter B, the current container context type and the container context parameter B are input into the container generation tool, so that the container generation tool generates corresponding role sub-application containers for the candidate system role 1 in the target application system based on the current container context type and the container context parameter B.

[0165] Furthermore, a target routing container is constructed based on the candidate role identifier and second application container port information corresponding to each candidate system role. The target routing container parses the candidate role identifier based on an application call request sent by any candidate system data source, determines the second application container port information associated with the candidate role identifier, and then routes the application call request to the role sub-application container corresponding to the second application container port information based on the second application container port information, so that the candidate system role calls the application through the role sub-application container.

[0166] The embodiment of the present invention generates a corresponding role sub-application container for each candidate system role in the target application system, and each candidate system role calls the application through the corresponding role sub-application container, thereby isolating the processes of system roles calling the application from each other, reducing the risk of role data leakage when the system role calls the application, and improving the data security of the application system.

[0167] Optionally, after determining the number of candidate databases for the target application system configuration, the following steps are also included:

[0168] A3. If the number of databases is at least two, obtain the candidate table metadata information corresponding to each candidate database, and compare the metadata information of each candidate table to determine whether the metadata information of each candidate table is the same.

[0169] B3. If the metadata information of any two candidate tables is different, obtain at least one target interceptor included in the target application system.

[0170] Among them, the target interceptor is a programming mechanism that dynamically intercepts requests or method calls, and is mainly used to insert additional processing logic before and after the execution of the core business logic of the target application system.

[0171] In one embodiment, if the metadata information of any two candidate tables is different, at least one target interceptor included in the target application system is obtained according to the interceptor registry of the target application system.

[0172] C3. Determine, based on the code decompilation results of each target interceptor, whether each target interceptor has executed a data source switching operation for the main application container.

[0173] In one embodiment, the code of each target interceptor is decompiled, and based on the decompilation result of the code of each target interceptor, it is identified whether each target interceptor has executed a data source switching operation for the main application container.

[0174] D3. If any target interceptor has executed a data source switching operation for the main application container, it is determined that the number of system roles is at least two.

[0175] If the number of databases is at least two, the candidate table metadata information corresponding to each candidate database is obtained, and the metadata information of each candidate table is compared to determine whether the metadata information of each candidate table is the same; if the metadata information of any two candidate tables is different, at least one target interceptor included in the target application system is obtained; based on the code decompilation results of each target interceptor, it is determined whether each target interceptor has executed the data source switching operation for the main application container; if any target interceptor has executed the data source switching operation for the main application container, it is determined that the number of system roles is at least two, thereby achieving the effect of automatically identifying the number of system roles, reducing manual inspection costs, and improving the efficiency of identifying the number of system roles.

[0176] Optionally, after determining whether each target interceptor has executed a data source switching operation for the main application container, the following steps are further included:

[0177] If each target interceptor has not performed a data source switching operation for the main application container, determine whether the object relational mapping framework of the target application system has performed a data source scheduling operation; if the data source scheduling operation has been performed, determine that the number of system roles is at least two.

[0178] Among them, the object-relational mapping framework, also known as the orm framework, is a technical tool that solves the data mapping between object-oriented programming languages ​​and relational databases.

[0179] In one embodiment, if each target interceptor has not performed a data source switching operation on the main application container, it is determined whether the object-relational mapping framework of the target application system has performed a data source scheduling operation through the SQL statement where parameter. If the data source scheduling operation has been performed, it is determined that the number of system roles is at least two.

[0180] If none of the target interceptors have performed the data source switching operation for the main application container, it is determined whether the object-relational mapping framework of the target application system has performed the data source scheduling operation; if the data source scheduling operation has been performed, the number of system roles is determined to be at least two, thereby ensuring the efficiency and accuracy of determining the number of system roles.

[0181] Example 4

[0182] Figure 4 This is a structural diagram of a device for calling an application provided by the fourth embodiment of the present invention, which is applicable to the case where a system user calls an application through a dedicated user sub-application container. Figure 4 As shown, the device includes:

[0183] A system user number identification module 41 is used to determine whether the number of candidate system users of the target application system is at least two;

[0184] An information acquisition module 42 is configured to, if it is determined that the number of the system users is at least two, acquire candidate data source information of a candidate system data source associated with each candidate system user, and acquire first application container port information individually allocated to each candidate system user;

[0185] A first context parameter generation module 43 is configured to update current container context parameters based on the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user; wherein the current container context parameters are container context parameters of the primary application container of the target application system, and the primary application container provides a callable application;

[0186] The user sub-application container generation module 44 is used to generate a corresponding user sub-application container for each candidate system user in the target application system according to the current container context type of the main application container and the first container context parameter; wherein each candidate system user calls the application through the corresponding user sub-application container.

[0187] Optionally, the first context parameter generating module 43 is specifically configured to:

[0188] Determine the current data source information and the current application container port information included in the current container context parameters;

[0189] Updating the current data source information to the candidate data source information corresponding to any candidate system user, and updating the current application container port information to the first application container port information corresponding to the candidate system user;

[0190] Determine the first container context parameter corresponding to the candidate system user according to the updated current container context parameter.

[0191] Optionally, the device further includes a first routing rule generating module, specifically configured to:

[0192] Determine a candidate user identifier corresponding to each candidate system user, and generate a first routing rule for a target routing container in the target application system according to the candidate user identifier corresponding to each candidate system user and the first application container port information;

[0193] The target routing container controls each candidate system user to access the corresponding user sub-application container according to the first routing rule, so as to call the application program.

[0194] Optionally, the first routing rule generating module is further configured to:

[0195] Determining, by the target routing container according to the first application call request sent by any candidate system data source, a candidate user identifier of the candidate system user associated with the candidate system data source as the first user identifier;

[0196] Determining, by the target routing container according to the first user identifier and the first routing rule, the first application container port information associated with the first user identifier as the first port information to be accessed;

[0197] The first application call request is forwarded by the target routing container according to the first port to be accessed information, so as to control the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

[0198] Optionally, the system user number identification module 41 is specifically configured to:

[0199] Determine the number of candidate databases configured in the target application system, and if the number of databases is at least two, obtain candidate table metadata information corresponding to each candidate database;

[0200] Comparing the metadata information of each candidate table to determine whether the metadata information of each candidate table is the same;

[0201] If the metadata information of each candidate table is the same, determining whether the database scheduling mechanism of the target application system is a target scheduling mechanism; wherein the target scheduling mechanism is a scheduling mechanism for switching databases based on user identification;

[0202] If the database scheduling mechanism of the target application system is the target scheduling mechanism, it is determined that the number of system users is at least two.

[0203] Optionally, the device further includes a role sub-application container generation module, specifically configured to:

[0204] determining whether the number of candidate system roles possessed by the target application system is at least two;

[0205] If it is determined that the number of the system roles is at least two, obtaining a target common code of the target application system, a candidate role code corresponding to each of the candidate system roles, and second application container port information individually allocated to each of the candidate system roles;

[0206] updating the current container context parameters according to the target public code, the candidate role code, and the second application container port information to generate second container context parameters corresponding to each candidate system role;

[0207] According to the current container context type of the main application container and the second container context parameters, a corresponding role sub-application container is generated for each candidate system role in the target application system; wherein each candidate system role calls the application through the corresponding role sub-application container.

[0208] Optionally, the role sub-application container generation module is further configured to:

[0209] Constructing a first scanning expression according to the first package name of the target code package in the target application system; wherein the target code package is a system code package and / or a tool code package;

[0210] The system code of the target application system is scanned using the first scanning expression, and the target common code of the target application system is determined according to the scanning result.

[0211] Optionally, the role sub-application container generation module is further configured to:

[0212] Determining a role routing rule corresponding to the candidate system role according to the candidate role identifier corresponding to any of the candidate system roles, and determining a system routing address corresponding to the candidate system role according to the role routing rule;

[0213] Matching the system routing address with the control class address of the candidate control class in the main application container, and determining a target control class from the candidate control classes according to the matching result;

[0214] A second scanning expression is constructed according to the second package name of the class code package corresponding to the target control class, and the system code of the target application system is scanned using the second scanning expression, and the candidate role code corresponding to the candidate system role is determined according to the scanning result.

[0215] Optionally, the device further includes a second routing rule generating module, specifically configured to:

[0216] Determine candidate role identifiers corresponding to the candidate system roles, and generate a second routing rule for the target routing container in the target application system according to the candidate role identifiers corresponding to the candidate system roles and the second application container port information;

[0217] The target routing container controls each candidate system role to access the corresponding role sub-application container according to the second routing rule, so as to call the application program.

[0218] Optionally, the second routing rule generating module is further configured to:

[0219] Determining, by the target routing container according to the second application call request sent by any of the candidate system data sources, a candidate role identifier of the candidate system role associated with the candidate system data source as the first role identifier;

[0220] Determining, by the target routing container according to the first role identifier and the second routing rule, the port information of the second application container associated with the first role identifier as the second port information to be accessed;

[0221] The second application call request is forwarded through the target routing container according to the second port to be accessed information, so as to control the candidate system role associated with the candidate system data source and access the corresponding role sub-application container.

[0222] Optionally, the role sub-application container generation module is further configured to:

[0223] Determine the number of candidate databases configured in the target application system, and if the number of databases is one, obtain candidate table metadata information corresponding to the candidate database as target table metadata information;

[0224] Determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification;

[0225] If the target user type field is used for user classification, determine whether the target user type field contains target user characteristics, if not, determine that the number of system roles is at least two; wherein the target user characteristics are user characteristics unrelated to role characteristics.

[0226] Optionally, the device further includes a target interceptor acquisition module, specifically configured to:

[0227] If the number of the databases is at least two, obtaining the candidate table metadata information corresponding to each of the candidate databases, and comparing the candidate table metadata information to determine whether the candidate table metadata information is the same;

[0228] If metadata information of any two candidate tables is different, obtaining at least one target interceptor included in the target application system;

[0229] Determining, based on code decompilation results of each target interceptor, whether each target interceptor has performed a data source switching operation on the main application container;

[0230] If any of the target interceptors has executed a data source switching operation for the main application container, it is determined that the number of the system roles is at least two.

[0231] Optionally, the device further includes a data source scheduling operation identification module, specifically configured to:

[0232] If none of the target interceptors has executed a data source switching operation for the main application container, determining whether the object relational mapping framework of the target application system has executed a data source scheduling operation;

[0233] If the data source scheduling operation has been performed, it is determined that the number of the system roles is at least two.

[0234] The application calling device provided in the embodiment of the present invention can execute the application calling method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0235] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0236] Example 5

[0237] Figure 5 A schematic diagram of an electronic device 50 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0238] like Figure 5As shown, electronic device 50 includes at least one processor 51 and memory, such as read-only memory (ROM) 52 and random access memory (RAM) 53, communicatively connected to the at least one processor 51. The memory stores computer programs executable by the at least one processor. Processor 51 can perform various appropriate actions and processes based on the computer programs stored in ROM 52 or loaded from storage unit 58 into RAM 53. RAM 53 can also store various programs and data required for the operation of electronic device 50. Processor 51, ROM 52, and RAM 53 are interconnected via bus 54. An input / output (I / O) interface 55 is also connected to bus 54.

[0239] Multiple components in the electronic device 50 are connected to the I / O interface 55, including an input unit 56, such as a keyboard, a mouse, etc.; an output unit 57, such as various types of displays, speakers, etc.; a storage unit 58, such as a magnetic disk, an optical disk, etc.; and a communication unit 59, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 59 allows the electronic device 50 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0240] Processor 51 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any other suitable processor, controller, microcontroller, etc. Processor 51 executes the various methods and processes described above, such as the method for invoking an application.

[0241] In some embodiments, the method for calling an application program can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the method for calling an application program described above can be performed. Alternatively, in other embodiments, processor 51 can be configured to execute the method for calling an application program in any other appropriate manner (e.g., via firmware).

[0242] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0243] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0244] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, device, or apparatus. A computer-readable storage medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0245] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device that has: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0246] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0247] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0248] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0249] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for calling an application, characterized in that: The method comprises: determining whether the number of system users of the target application system that are candidate system users is at least two; If it is determined that the number of the system users is at least two, then obtaining candidate data source information of the candidate system data source associated with each candidate system user, and obtaining first application container port information individually allocated to each candidate system user; updating the current container context parameters based on the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user; wherein the current container context parameters are container context parameters of the primary application container of the target application system, and the primary application container provides a callable application; generating, in the target application system, a corresponding user sub-application container for each candidate system user according to the current container context type of the main application container and the first container context parameter; wherein each candidate system user calls the application program through the corresponding user sub-application container; The method further comprises: Determine a candidate user identifier corresponding to each candidate system user, and generate a first routing rule for a target routing container in the target application system according to the candidate user identifier corresponding to each candidate system user and the first application container port information; Determining, by the target routing container according to the first application call request sent by any candidate system data source, a candidate user identifier of the candidate system user associated with the candidate system data source as the first user identifier; Determining, by the target routing container according to the first user identifier and the first routing rule, the first application container port information associated with the first user identifier as the first port information to be accessed; The first application call request is forwarded by the target routing container according to the first port to be accessed information, so as to control the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

2. The method according to claim 1, characterized in that The updating of the current container context parameters according to the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user includes: Determine the current data source information and the current application container port information included in the current container context parameters; Updating the current data source information to the candidate data source information corresponding to any candidate system user, and updating the current application container port information to the first application container port information corresponding to the candidate system user; Determine the first container context parameter corresponding to the candidate system user according to the updated current container context parameter.

3. The method according to claim 1, characterized in that The determining whether the number of candidate system users of the target application system is at least two includes: Determine the number of candidate databases configured in the target application system, and if the number of databases is at least two, obtain candidate table metadata information corresponding to each candidate database; Comparing the metadata information of each candidate table to determine whether the metadata information of each candidate table is the same; If the metadata information of each candidate table is the same, determining whether the database scheduling mechanism of the target application system is a target scheduling mechanism; wherein the target scheduling mechanism is a scheduling mechanism for switching databases based on user identification; If the database scheduling mechanism of the target application system is the target scheduling mechanism, it is determined that the number of system users is at least two.

4. The method according to claim 1, wherein The method further comprises: determining whether the number of candidate system roles possessed by the target application system is at least two; If it is determined that the number of the system roles is at least two, obtaining a target common code of the target application system, a candidate role code corresponding to each of the candidate system roles, and second application container port information individually allocated to each of the candidate system roles; updating the current container context parameters according to the target public code, the candidate role code, and the second application container port information to generate second container context parameters corresponding to each candidate system role; According to the current container context type of the main application container and the second container context parameters, a corresponding role sub-application container is generated for each candidate system role in the target application system; wherein each candidate system role calls the application through the corresponding role sub-application container.

5. The method according to claim 4, characterized in that The obtaining of the target common code of the target application system includes: Constructing a first scanning expression according to the first package name of the target code package in the target application system; wherein the target code package is a system code package and / or a tool code package; The system code of the target application system is scanned using the first scanning expression, and the target common code of the target application system is determined according to the scanning result.

6. The method according to claim 4, characterized in that The obtaining of candidate role codes corresponding to the candidate system roles includes: Determining a role routing rule corresponding to the candidate system role according to the candidate role identifier corresponding to any of the candidate system roles, and determining a system routing address corresponding to the candidate system role according to the role routing rule; Matching the system routing address with the control class address of the candidate control class in the main application container, and determining a target control class from the candidate control classes according to the matching result; A second scanning expression is constructed according to the second package name of the class code package corresponding to the target control class, and the system code of the target application system is scanned using the second scanning expression, and the candidate role code corresponding to the candidate system role is determined according to the scanning result.

7. The method according to claim 4, characterized in that The method further comprises: Determine candidate role identifiers corresponding to the candidate system roles, and generate a second routing rule for the target routing container in the target application system according to the candidate role identifiers corresponding to the candidate system roles and the second application container port information; The target routing container controls each candidate system role to access the corresponding role sub-application container according to the second routing rule, so as to call the application program.

8. The method according to claim 7, characterized in that The controlling each candidate system role to access the corresponding role sub-application container according to the second routing rule through the target routing container includes: Determining, by the target routing container according to the second application call request sent by any of the candidate system data sources, a candidate role identifier of the candidate system role associated with the candidate system data source as the first role identifier; Determining, by the target routing container according to the first role identifier and the second routing rule, the port information of the second application container associated with the first role identifier as the second port information to be accessed; The second application call request is forwarded through the target routing container according to the second port to be accessed information, so as to control the candidate system role associated with the candidate system data source and access the corresponding role sub-application container.

9. The method according to claim 4, characterized in that The determining whether the number of candidate system roles of the target application system is at least two includes: Determine the number of candidate databases configured in the target application system, and if the number of databases is one, obtain candidate table metadata information corresponding to the candidate database as target table metadata information; Determine the target system user table of the target application system according to the target table metadata information, and determine whether the target user type field in the target system user table is used for user classification; If the target user type field is used for user classification, determine whether the target user type field contains target user characteristics, if not, determine that the number of system roles is at least two; wherein the target user characteristics are user characteristics unrelated to role characteristics.

10. The method according to claim 9, characterized in that After determining the number of candidate databases configured for the target application system, the method further includes: If the number of the databases is at least two, obtaining the candidate table metadata information corresponding to each of the candidate databases, and comparing the candidate table metadata information to determine whether the candidate table metadata information is the same; If metadata information of any two candidate tables is different, obtaining at least one target interceptor included in the target application system; Determining, based on code decompilation results of each target interceptor, whether each target interceptor has performed a data source switching operation on the main application container; If any of the target interceptors has executed a data source switching operation for the main application container, it is determined that the number of the system roles is at least two.

11. The method according to claim 10, characterized in that After determining whether each target interceptor has executed a data source switching operation for the main application container, the method further includes: If none of the target interceptors has executed a data source switching operation for the main application container, determining whether the object relational mapping framework of the target application system has executed a data source scheduling operation; If the data source scheduling operation has been performed, it is determined that the number of the system roles is at least two.

12. A device for calling an application, characterized in that: The device comprises: a system user quantity identification module, configured to determine whether the number of candidate system users of the target application system is at least two; an information acquisition module, configured to, if it is determined that the number of the system users is at least two, acquire candidate data source information of a candidate system data source associated with each candidate system user, and acquire first application container port information individually allocated to each candidate system user; a first context parameter generation module configured to update current container context parameters based on the candidate data source information and the first application container port information to generate first container context parameters corresponding to each candidate system user; wherein the current container context parameters are container context parameters of a primary application container of the target application system, and the primary application container provides a callable application; a user sub-application container generation module, configured to generate a corresponding user sub-application container for each candidate system user in the target application system according to the current container context type of the main application container and the first container context parameter; wherein each candidate system user calls the application program through the corresponding user sub-application container; The device further includes a first routing rule generating module, specifically configured to: Determine a candidate user identifier corresponding to each candidate system user, and generate a first routing rule for a target routing container in the target application system according to the candidate user identifier corresponding to each candidate system user and the first application container port information; Determining, by the target routing container according to the first application call request sent by any candidate system data source, a candidate user identifier of the candidate system user associated with the candidate system data source as the first user identifier; Determining, by the target routing container according to the first user identifier and the first routing rule, the first application container port information associated with the first user identifier as the first port information to be accessed; The first application call request is forwarded by the target routing container according to the first port to be accessed information, so as to control the candidate system user associated with the candidate system data source to access the corresponding user sub-application container.

13. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the method for calling the application program according to any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the method for calling an application program according to any one of claims 1 to 11.

15. A computer program product, characterized in that The invention comprises a computer program, which implements the method for calling the application program according to any one of claims 1 to 11 when being executed by a processor.

Citation Information

Patent Citations

  • Meeting notice system and method based on context service

    CN101645789A

  • Secure data container for web applications

    CN104603793A