Authorization control method and device under RESTful architecture
By adopting the remote-end and then local authority authentication method under the RESTful architecture, the problem of remote-end and local authorization conflicts is solved, and the smooth execution of service response is achieved.
Patent Information
- Application Number
- CN202510518476.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-07-18
AI Technical Summary
Under the RESTful architecture, remote authorization and local authorization conflict, resulting in failure in configuration operations and resource access.
Use the remote end first and then local authority authentication method. When the remote end authority authentication is successful, directly execute the service response operation to avoid local authorization failure.
Avoid the problem of successful remote authorization and failure of local authorization, ensuring the smooth progress of configuration operations and resource access.
Smart Images

Figure CN120342703A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and particularly relates to an authorization control method, device, computer device, storage medium, and computer program product under a RESTful architecture. Background Art
[0002] In the switch networking based on the SONiC (Software for Open Networking in the Cloud) white box system, the mgmt-framework management framework is adopted as one of its core management components to achieve comprehensive management of the switch configuration and status. This management framework supports Cisco-style command lines to issue and display switch configurations, and supports the RESTful (Representational State Transfer) architecture and the OpenAPI specification to automatically generate REST server-side and client-side codes. It can convert the issued commands into REST requests and send them to the REST server. The REST server receives the requests and performs relevant operations, and then completes rendering and display.
[0003] The management framework mgmt-framework supports authentication and corresponding authorization based on certificates, passwords, user roles, etc. Therefore, when a user issues a command, the REST server will perform identity authentication and resource authorization on the received REST request. Only the REST requests that pass the authentication and authorization are allowed to perform corresponding operations (including update, delete, setting, etc.). In this case, if the switch is configured with remote server authentication and authorization (such as TACACS+, radius, etc.), then once a remote user logs in, after passing the remote authentication and authorization, a local authorization operation of the internal REST server of the mgmt-framework will be performed, which conflicts with the original purpose of the switch, that is, handing over the authentication and authorization operations entirely to the remote server for processing. If the local authorization of the mgmt-framework continues to be used, it may lead to conflicts between local authorization and remote authorization, resulting in problems such as successful remote authorization but failed local authorization, and thus unable to perform configuration operations, resource access, etc. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide an authorization control method, device, computer device, storage medium, and computer program product under a RESTful architecture to solve the technical problem of conflicts between remote authorization and local authorization under the existing RESTful architecture.
[0005] According to a first aspect, an embodiment of the present invention provides an authorization control method under a RESTful architecture, which is applied to an architecture system including a remote permission authentication function and a local permission authentication function; the method includes: when a REST client receives a service request from a user, obtaining system permission authentication information configured by an AAA authentication function module and determining an authentication method based on the system permission authentication information; when the authentication method includes both a remote permission authentication method and a local permission authentication method, sending user authentication information corresponding to the service request to a remote server for remote permission authentication operation; when the remote permission authentication result is successful authentication, sending the service request to a REST server so that the REST server performs a service response operation.
[0006] Optionally, after sending user authentication information corresponding to the service request to a remote server for remote permission authentication operation when the authentication method includes both a remote permission authentication method and a local permission authentication method, the method further includes: when the remote permission authentication result is failed authentication, adding the remote permission authentication result to a header field of the service request and sending the service request with the added header field and the configured system permission authentication information to the REST server for local permission authentication operation; performing a feedback operation on the REST client based on the local permission authentication result of the REST server.
[0007] Optionally, after obtaining system permission authentication information configured by an AAA authentication function module and determining an authentication method based on the system permission authentication information when a REST client receives a service request from a user, the method further includes: when the authentication method only includes a remote permission authentication method, sending user authentication information corresponding to the service request to a remote server for remote permission authentication operation; when the remote permission authentication result is failed authentication, feeding back the failed authentication result to a user terminal; when the remote permission authentication result is successful authentication, sending the service request and the configured system permission authentication information to the REST server so that the REST server performs a service response operation.
[0008] Optionally, add the remote permission authentication result to the header field of the service request and send the service request with the added header field to the REST server for local permission authentication operations, including: setting the environment variable REMOTE_AUTHOR_SERVER of the REST client to FAILED through the AAA authorization accounting module, and checking whether the environment variable exists before the REST client sends the service request; when the environment variable exists, add the Remote-Local-Authorization field to the header field of the service request and set it to FAILED and send it to the REST server, so that when the REST server parses the received service request, when it parses that the header field contains the Remote-Local-Authorization field, it performs local permission authentication operations.
[0009] Optionally, the method further includes: controlling the REST server to return the response result corresponding to the service request to the REST client; performing a rendering operation on the response result through the command line interface and displaying the rendering operation result on the user terminal.
[0010] According to a second aspect, an embodiment of the present invention provides an authorization control device under a RESTful architecture, which is applied to an architecture system including a remote permission authentication function and a local permission authentication function; including: an acquisition module, configured to obtain system permission authentication information configured by the AAA authentication function module and determine a permission authentication method based on the system permission authentication information when the REST client receives a service request from a user; a first sending module, configured to send user authentication information corresponding to the service request to a remote server for remote permission authentication operations when the permission authentication method includes both a remote permission authentication method and a local permission authentication method; a second sending module, configured to send the service request to the REST server when the remote permission authentication result is authentication success, so that the REST server performs a service response operation.
[0011] Optionally, the device further includes: a third sending module, configured to add the remote permission authentication result to the header field of the service request and send the service request with the added header field and the configured system permission authentication information to the REST server for local permission authentication operations when the remote permission authentication result is authentication failure; a response module, configured to perform a feedback operation on the REST client based on the local permission authentication result of the REST server.
[0012] According to a third aspect, an embodiment of the present invention provides a computer device, including: a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the authorization control method under the RESTful architecture described in the first aspect or any optional implementation manner of the first aspect.
[0013] According to a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, the computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the authorization control method under the RESTful architecture described in the first aspect or any optional implementation manner of the first aspect.
[0014] According to a fifth aspect, an embodiment of the present invention provides a computer program product, including computer instructions, and the computer instructions are used to cause a computer to execute the authorization control method under the RESTful architecture described in the first aspect or any optional implementation manner of the first aspect.
[0015] The authorization control method under the RESTful architecture provided by the embodiment of the present invention is applied to an architecture system including a remote permission authentication function and a local permission authentication function. When the REST client receives a service request from a user, it obtains the system permission authentication information configured by the AAA authentication function module and determines the permission authentication method based on the system permission authentication information. When the permission authentication method includes both a remote permission authentication method and a local permission authentication method, the user authentication information corresponding to the service request is sent to the remote server for remote permission authentication operation. When the remote permission authentication result is successful authentication, the service request is sent to the REST server so that the REST server performs a service response operation. For an architecture system that includes both a remote permission authentication function and a local permission authentication function, when the AAA authentication function module is configured with both a remote permission authentication method and a local permission authentication method, the permission authentication method is first remote and then local. When the remote permission authentication is successful, the user's service request is sent to the REST server, causing the REST server to skip the local permission authentication operation and directly perform the service response operation, avoiding problems such as successful remote authorization but failed local authorization, resulting in inability to perform configuration operations, resource access, etc. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 It is a flowchart of an authorization control method under the RESTful architecture according to an embodiment of the present invention;
[0018] Figure 2 It is a schematic diagram of the SONiC system architecture according to an embodiment of the present invention;
[0019] Figure 3 It is a block diagram of the structure of an authorization control device under the RESTful architecture according to an embodiment of the present invention;
[0020] Figure 4 It is a schematic diagram of the hardware structure of a computer device provided by an embodiment of the present invention. Detailed implementation manners
[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0022] According to an embodiment of the present invention, an embodiment of an authorization control method under the RESTful architecture is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0023] In this embodiment, an authorization control method under the RESTful architecture is provided, which is applied to an architecture system including a remote permission authentication function and a local permission authentication function; the authorization control method under the RESTful architecture provided by the embodiments of the present application can be applied in a data center network architecture built based on a white-box switch of SONiC. For details, see Figure 2, the user terminal connects to the SONiC system device through the ssh port or serial port, configures the AAA (i.e., Authentication, Authorization, Accounting) in the SONiC bash as the AAA authentication function module. At the same time, through the SONiC CLI, the configuration data in the XML file can be read and applied to the device to achieve the configuration and deployment of the device. For example, network topology information, port settings, routing protocol configurations, etc. can all be described in XML format, and then these configurations are loaded into the SONiC device through CLI commands. It can also be used in a scenario with a RESTful architecture. In this embodiment of the application, the SONiC system architecture is taken as an example for illustration. As Figure 1 shown, the process includes the following steps:
[0024] Step S101, when the REST client receives a user service request, obtain the system privilege authentication information configured by the AAA authentication function module and determine the privilege authentication method based on the system privilege authentication information;
[0025] Exemplarily, the SONiC system device configures the system privilege authentication information through the AAA authentication function module, such as only requiring remote privilege authentication, or requiring a combination of remote privilege authentication and local privilege authentication. Receive the command issued by the user through the SONiC command line interface (SONiC-CLI) and convert the issued command into a service request and send it to the REST client (REST CLIENT). When the REST client receives the user service request, determine the adopted privilege authentication method by obtaining the system privilege authentication information configured by the AAA authentication function module.
[0026] Step S102, when the privilege authentication method includes both a remote privilege authentication method and a local privilege authentication method, send the user authentication information corresponding to the service request to the remote server for remote privilege authentication operation;
[0027] Exemplarily, when the privilege authentication method includes both a remote privilege authentication method and a local privilege authentication method, first send the user authentication information corresponding to the service request to the remote server for remote privilege authentication operation. Specifically, for example, send the identity identification information included in the user authentication information to the remote server through the AAA authorization and accounting module, so that the remote server can compare the identity identification information with the pre-stored privilege information, and determine whether to authorize based on the comparison result.
[0028] Step S103, when the remote privilege authentication result is successful authentication, send the service request to the REST server so that the REST server performs a service response operation.
[0029] Exemplarily, when the remote permission authentication result is successful authentication, i.e., the remote server authorizes, the remote server processes the authorization result through the AAA authorization accounting module in the SONiC management framework, and sends the service request issued by the user to the REST server through the AAA authorization accounting module, so that the REST server directly performs a service response operation on the service request, such as obtaining messages or data from the background subscribed containers or processes through the message distribution center REDIS.
[0030] The authorization control method under the RESTful architecture provided by the embodiments of the present invention is applied to an architecture system including a remote permission authentication function and a local permission authentication function. When the REST client receives a service request from a user, it obtains the system permission authentication information configured by the AAA authentication function module and determines the permission authentication method based on the system permission authentication information. When the permission authentication method includes both a remote permission authentication method and a local permission authentication method, the user authentication information corresponding to the service request is sent to the remote server for remote permission authentication operation. When the remote permission authentication result is successful authentication, the service request is sent to the REST server so that the REST server performs a service response operation. For an architecture system including both a remote permission authentication function and a local permission authentication function, when the AAA authentication function module is configured with both a remote permission authentication method and a local permission authentication method, through the permission authentication method of first remote and then local, when the remote permission authentication is successful, the service request of the user is sent to the REST server so that the REST server skips the local permission authentication operation and directly performs the service response operation, avoiding problems such as the remote authorization being successful but the local authorization being failed, resulting in inability to perform configuration operations, resource access, etc.
[0031] As an optional implementation manner of the embodiments of the present invention, after step S102, the method further includes: when the remote permission authentication result is failed authentication, adding the remote permission authentication result to the header field of the service request, and sending the service request with the added header field and the configured system permission authentication information to the REST server for local permission authentication operation; and performing a feedback operation on the REST client based on the local permission authentication result of the REST server.
[0032] Exemplarily, by adding the remote permission authentication result to the header field of the service request, the REST server that receives the service request with the added header field parses the service request. The REST server can determine that the current remote permission authentication fails according to the parsing result, and determine that it needs to perform a local permission authentication operation based on the configured system permission authentication information, and respond to the feedback operation of the REST client based on the local permission authentication result of the REST server. For example, when the local permission authentication result is still a failure, the authorization failure result is fed back to the REST client; or when the local permission authentication result is a success, the service response operation is performed based on the issued service request.
[0033] As an optional implementation manner of an embodiment of the present invention, step S103 includes: setting the environment variable REMOTE_AUTHOR_SERVER of the REST client to FAILED through the AAA authorization accounting module, and checking whether the environment variable exists before the REST client sends the service request; when the environment variable exists, adding a Remote-Local-Authorization field to the header field of the service request and setting it to FAILED and sending it to the REST server, so that when the REST server parses the received service request, when it parses that the header field contains the Remote-Local-Authorization field, it performs a local permission authentication operation.
[0034] Exemplarily, by adding a Remote-Local-Authorization field to the header field of the service request and setting it to FAILED and sending it to the REST server, when the REST server parses and obtains this header field, it can confirm that the remote authorization mode fails in the remote-local authorization mode. At this time, the REST server needs to perform a local permission authentication operation. By adding a remote permission authentication result field to the header field of the service request, the REST server can perform a local authorization authentication operation in a timely manner and delete this environment variable after completing the local authorization.
[0035] As an optional implementation manner of an embodiment of the present invention, after step S101, the method further includes:
[0036] When the permission authentication method only includes a remote permission authentication method, the user authentication information corresponding to the service request is sent to a remote server for remote permission authentication operation; for details, refer to the above remote permission authentication operation method, which will not be elaborated here.
[0037] When the remote permission authentication result is an authentication failure, the authentication failure result is fed back to the user terminal;
[0038] When the remote permission authentication result is successful authentication, the service request and the configured system permission authentication information are sent to the REST server so that the REST server performs a service response operation. In the case where only the remote permission authentication operation is required, when the remote permission authentication result is successful authentication, it indicates that the service response operation can be directly performed on the service request at this time. At the same time, the configured system permission authentication information is sent to the REST server, so that the REST server confirms that the service response operation can be directly performed without the local permission authentication operation, and further avoids the problem of conflict between the remote and local authentication results, and then can quickly respond to the user's service request.
[0039] As an optional implementation manner of an embodiment of the present invention, the method further includes: controlling the REST server to return the response result corresponding to the service request to the REST client; performing a rendering operation on the response result through a command line interface and displaying the rendering operation result on a user terminal. By displaying the rendering result to the user terminal, the user of the user terminal can intuitively and friendly obtain the service request result.
[0040] In this embodiment, an authorization control device under a RESTful architecture is further provided. This device is used to implement the above embodiments and preferred implementation manners, and the descriptions that have been made will not be repeated here. The term "module" used below can be a combination of software and / or hardware that can implement a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0041] This embodiment provides an authorization control device under a RESTful architecture, which is applied to an architecture system including a remote permission authentication function and a local permission authentication function; as Figure 3 shown, it includes:
[0042] An obtaining module 301, configured to obtain the system permission authentication information configured by the AAA authentication function module and determine a permission authentication method based on the system permission authentication information when the REST client receives a service request from a user;
[0043] A first sending module 302, configured to send the user authentication information corresponding to the service request to a remote server for remote permission authentication operation when the permission authentication method includes both a remote permission authentication method and a local permission authentication method;
[0044] A second sending module 303, configured to send the service request to the REST server when the remote permission authentication result is successful authentication so that the REST server performs a service response operation. For a detailed description, refer to the relevant description corresponding to the above method embodiment, which will not be repeated here.
[0045] In this embodiment, the authorization control device under the RESTful architecture is presented in the form of functional units. Here, the unit refers to an ASIC circuit, a processor and a memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0046] The authorization control device under the RESTful architecture provided in this embodiment is applied to an architecture system that includes a remote permission authentication function and a local permission authentication function. When the REST client receives a service request from a user, it obtains the system permission authentication information configured by the AAA authentication function module and determines the permission authentication method based on the system permission authentication information. When the permission authentication method includes both a remote permission authentication method and a local permission authentication method, the user authentication information corresponding to the service request is sent to the remote server for remote permission authentication operations. When the remote permission authentication result is successful authentication, the service request is sent to the REST server so that the REST server performs a service response operation. For an architecture system that includes both a remote permission authentication function and a local permission authentication function, when the AAA authentication function module is configured with both a remote permission authentication method and a local permission authentication method, the permission authentication method is first remote and then local. When the remote permission authentication is successful, the user's service request is sent to the REST server, causing the REST server to skip the local permission authentication operation and directly perform the service response operation, avoiding problems such as a successful remote authorization but a failed local authorization, resulting in an inability to perform configuration operations, resource access, etc.
[0047] As an optional implementation manner of an embodiment of the present invention, the device further includes: a third sending module, configured to, when the remote permission authentication result is failed authentication, add the remote permission authentication result to the header field of the service request and send the service request with the added header field and the configured system permission authentication information to the REST server for local permission authentication operations; a response module, configured to perform a feedback operation on the REST client based on the local permission authentication result of the REST server.
[0048] As an optional implementation manner of an embodiment of the present invention, the device further includes: a fourth sending module, configured to, when the permission authentication method only includes a remote permission authentication method, send the user authentication information corresponding to the service request to the remote server for remote permission authentication operations; a first feedback module, configured to, when the remote permission authentication result is failed authentication, feedback the failed authentication result to the user terminal; a fifth sending module, configured to, when the remote permission authentication result is successful authentication, send the service request and the configured system permission authentication information to the REST server so that the REST server performs a service response operation.
[0049] As an alternative embodiment of the embodiment of the present invention, the second sending module 303 includes: a first checking module, configured to set the environment variable REMOTE_AUTHOR_SERVER of the REST client to FAILED through the AAA authorization accounting module, and check whether the environment variable exists before the REST client sends the service request; a sixth sending module, configured to, when the environment variable exists, add a Remote-Local-Authorization field to the header field of the service request and send it to the REST server with the value set to FAILED, so that when the REST server parses the received service request, it performs a local permission authentication operation when it parses that the header field contains the Remote-Local-Authorization field.
[0050] As an alternative embodiment of the embodiment of the present invention, the device further includes: a second feedback module, configured to control the REST server to return the response result corresponding to the service request to the REST client; a rendering module, configured to perform a rendering operation on the response result through a command line interface and display the rendering operation result on a user terminal.
[0051] The further function descriptions of the above-mentioned various modules and units are the same as those in the corresponding embodiments above, and will not be elaborated here.
[0052] The authorization control device under the RESTful architecture in this embodiment is presented in the form of functional units. Here, the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and a memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0053] The embodiment of the present invention further provides a computer device having the above Figure 3 authorization control device under the RESTful architecture as shown.
[0054] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of a computer device provided by an alternative embodiment of the present invention. As shown in Figure 4As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including a high-speed interface and a low-speed interface. Each component communicates with each other using different buses and can be installed on a common motherboard or in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some alternative embodiments, if needed, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides part of the necessary operations (such as an array of servers, a set of blade servers, or a multi-processor system). Figure 4 In this example, one processor 10 is taken as an example.
[0055] The processor 10 can be a central processing unit, a network processor, or a combination thereof. Among them, the processor 10 can further include a hardware chip. The above hardware chip can be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The above programmable logic device can be a complex programmable logic device, a field programmable gate array, a generic array logic, or any combination thereof.
[0056] Among them, the memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiments.
[0057] The memory 20 can include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the computer device, etc. In addition, the memory 20 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some alternative embodiments, the memory 20 can optionally include a memory remotely set relative to the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0058] The memory 20 can include a volatile memory, such as a random access memory; the memory can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid-state drive; the memory 20 can also include a combination of the above types of memories.
[0059] The computer device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30, and the output device 40 may be connected by a bus or other means. Figure 4 Take the connection by bus as an example.
[0060] The input device 30 can receive input digital or character information, and generate key signal inputs related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED), and a haptic feedback device (e.g., a vibration motor), etc. The above display device includes, but is not limited to, a liquid crystal display, a light-emitting diode, a display, and a plasma display. In some alternative embodiments, the display device may be a touch screen.
[0061] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code that is originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored on such a software process on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiment is implemented.
[0062] A part of the present invention can be applied as a computer program product, such as computer program instructions. When executed by a computer, through the operation of the computer, the methods and / or technical solutions according to the present invention can be called or provided. Those skilled in the art should be able to understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible by the computer.
[0063] Although embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various edits and modifications without departing from the spirit and scope of the present invention, and such edits and modifications all fall within the scope defined by the appended claims.
Claims
1. An authorization control method under the RESTful architecture, which is applied to an architecture system including a remote permission authentication function and a local permission authentication function; characterized in that, Including: When the REST client receives a service request from a user, obtain the system privilege authentication information configured by the AAA authentication function module and determine the privilege authentication method based on the system privilege authentication information; When the privilege authentication method includes both a remote privilege authentication method and a local privilege authentication method, send the user authentication information corresponding to the service request to the remote server for remote privilege authentication operation; When the remote privilege authentication result is successful authentication, send the service request to the REST server so that the REST server performs a service response operation.
2. The method according to claim 1, wherein When the privilege authentication method includes both a remote privilege authentication method and a local privilege authentication method, after sending the user authentication information corresponding to the service request to the remote server for remote privilege authentication operation, the method further includes: When the remote privilege authentication result is failed authentication, add the remote privilege authentication result to the header field of the service request and send the service request with the added header field and the configured system privilege authentication information to the REST server for local privilege authentication operation; Based on the local privilege authentication result of the REST server, perform a feedback operation on the REST client.
3. The method according to claim 1, wherein After the REST client receives a service request from a user, obtains the system privilege authentication information configured by the AAA authentication function module, and determines the privilege authentication method based on the system privilege authentication information, the method further includes: When the privilege authentication method only includes a remote privilege authentication method, send the user authentication information corresponding to the service request to the remote server for remote privilege authentication operation; When the remote privilege authentication result is failed authentication, feedback the failed authentication result to the user terminal; When the remote privilege authentication result is successful authentication, send the service request and the configured system privilege authentication information to the REST server so that the REST server performs a service response operation.
4. The method according to claim 2, wherein Adding the remote privilege authentication result to the header field of the service request and sending the service request with the added header field to the REST server for local privilege authentication operation includes: Set the environment variable REMOTE_AUTHOR_SERVER of the REST client to FAILED through the AAA authorization accounting module, and check whether the environment variable exists before the REST client sends the service request; When the environment variable exists, add the Remote-Local-Authorization field to the header field of the service request and set it to FAILED and send it to the REST server, so that when the REST server parses the received service request and parses that the header field contains the Remote-Local-Authorization field, it performs a local privilege authentication operation.
5. The method according to any one of claims 1-4, characterized in that, The method further includes: Control the REST server to return the response result corresponding to the service request to the REST client; Perform a rendering operation on the response result through the command line interface and display the result of the rendering operation on the user terminal.
6. An authorization control device under the RESTful architecture, which is applied to an architecture system including a remote permission authentication function and a local permission authentication function; characterized in that, Comprising: An acquisition module, configured to, when the REST client receives a service request from a user, acquire the system privilege authentication information configured by the AAA authentication function module and determine a privilege authentication method based on the system privilege authentication information; A first sending module, configured to, when the privilege authentication method includes both a remote privilege authentication method and a local privilege authentication method, send the user authentication information corresponding to the service request to a remote server for remote privilege authentication operation; A second sending module, configured to, when the remote privilege authentication result is authentication success, send the service request to the REST server so that the REST server performs a service response operation.
7. The device according to claim 6, characterized in that, The apparatus further comprises: A third sending module, configured to, when the remote privilege authentication result is authentication failure, add the remote privilege authentication result to the header field of the service request and send the service request with the added header field and the configured system privilege authentication information to the REST server for local privilege authentication operation; A response module, configured to perform a feedback operation on the REST client based on the local privilege authentication result of the REST server.
8. A computer device, characterized in that, Comprising: A memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the authorization control method under the RESTful architecture according to any one of claims 1-5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to execute the authorization control method under the RESTful architecture according to any one of claims 1-5.
10. A computer program product, characterized in that, Comprising computer instructions for causing a computer to execute the authorization control method under the RESTful architecture according to any one of claims 1-5.