Single Sign-On Methods, Systems, and Storage Media
By deploying OIDC services and microservices on the target platform and automatically mapping roles, the cumbersome role mapping problem between the artificial intelligence training platform and the customer system is solved, and efficient system integration is achieved.
Patent Information
- Application Number
- CN202511079952.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-08-01
AI Technical Summary
In existing technologies, the role mapping between AI training platforms and customers' own systems requires manual configuration, which is cumbersome, error-prone, and reduces work efficiency.
Deploy OIDC service, first microservice and second microservice on the target platform. Obtain and verify user login information through OIDC service, and return account and role information. First microservice determines the role on the target platform according to the role mapping relationship, so as to realize automatic role mapping.
Automatic mapping of platform roles and system roles can be achieved without manual configuration, which simplifies the connection between customer systems and target platforms and improves work efficiency.
Smart Images

Figure CN120602221B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a single sign-on method, system, and storage medium. Background Technology
[0002] System integration is a fundamental requirement in the deployment and application of AI training platforms. Users need to deeply integrate the AI platform with their existing business systems (such as OA) or multiple subsystems to achieve unified cross-platform identity authentication and granular role-based access control for user convenience. For example, a client might want to automatically map the "Project Manager" role in their business system to the "Group Administrator" role on the AI platform, thus achieving a smooth migration of the access control system.
[0003] In existing technologies, AI training platforms initially only have a built-in super administrator, and new users must be created manually. When a client has their own system, users must be created within that system, making it inconvenient for users. Furthermore, manually configuring user role mappings is cumbersome, error-prone, and reduces work efficiency. For example, administrators must manually compare the correspondence between client system roles (such as ordinary users) and AI platform roles (such as group administrators) and manually configure user role operations. Summary of the Invention
[0004] This disclosure provides a single sign-on method, system, and storage medium that can automatically map roles based on role mapping relationships, thereby supporting automatic mapping of platform roles and system roles. This facilitates the integration of customer systems with target platforms, improves user convenience, and enhances work efficiency.
[0005] To address the aforementioned technical problems, this disclosure provides a single sign-on method, including:
[0006] Deploy the OIDC service, the first microservice, and the second microservice on the management node where the target platform is located;
[0007] In response to receiving a unified authentication command from a user to trigger the target platform, the OIDC service obtains the login information entered by the user through the target login page and verifies the login information;
[0008] When the verification is successful, the OIDC service will return the user's account information and first role information, wherein the first role information is used to indicate the user's role in the OIDC service;
[0009] The first microservice reads the role mapping relationship from the second microservice and determines the second role information corresponding to the first role information based on the role mapping relationship. The second role information is used to indicate the user's role in the target platform.
[0010] Log in to the target platform based on the account information and the second role information.
[0011] This disclosure also provides a single sign-on system, including:
[0012] The deployment module is used to deploy the OIDC service, the first microservice, and the second microservice on the management node where the target platform is located.
[0013] The login module is used to respond to a unified authentication command triggered by a user on the target platform. The OIDC service obtains the login information entered by the user through the target login page and verifies the login information.
[0014] The sending module is used to send the user's account information and first role information back to the OIDC service when the verification is successful, wherein the first role information is used to indicate the user's role in the OIDC service;
[0015] The determination module is used for the first microservice to read the role mapping relationship from the second microservice and determine the second role information corresponding to the first role information based on the role mapping relationship, wherein the second role information is used to indicate the user's role in the target platform;
[0016] The login module is used to log in to the target platform based on the account information and the second role information.
[0017] This disclosure also provides an electronic device, including:
[0018] Memory, used to store computer programs;
[0019] A processor is configured to execute a computer program to implement the steps of any of the single sign-on methods provided in the embodiments of this disclosure.
[0020] This disclosure also provides a computer-readable storage medium storing a computer program, wherein when executed by a processor, the computer program implements the steps of any of the single sign-on methods provided in this disclosure.
[0021] This disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the single sign-on methods provided in this disclosure.
[0022] This disclosure provides a single sign-on method, comprising: deploying an OIDC service, a first microservice, and a second microservice on the management node where the target platform is located; responding to a unified authentication command triggered by a user on the target platform, the OIDC service obtains the login information entered by the user through the target login page and verifies the login information; when the verification is successful, the OIDC service returns the user's account information and first role information, wherein the first role information indicates the user's role in the OIDC service; the first microservice reads the role mapping relationship from the second microservice and determines the second role information corresponding to the first role information based on the role mapping relationship, wherein the second role information indicates the user's role on the target platform; and logging into the target platform based on the account information and the second role information. This disclosure automatically performs role mapping based on the role mapping relationship through the OIDC service, the first microservice, and the second microservice, eliminating the need for manual configuration, thereby supporting automatic mapping of platform roles and system roles, facilitating the integration of customer systems with the target platform, improving user convenience, and increasing work efficiency.
[0023] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0024] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0025] Figure 1 A flowchart illustrating a single sign-on method provided in an embodiment of this disclosure;
[0026] Figure 2 A flowchart illustrating another single sign-on method provided in this embodiment of the present disclosure;
[0027] Figure 3 A flowchart illustrating yet another single sign-on method provided in this disclosure embodiment;
[0028] Figure 4 A flowchart illustrating yet another single sign-on method provided in this disclosure embodiment;
[0029] Figure 5 A flowchart illustrating yet another single sign-on method provided in this disclosure embodiment;
[0030] Figure 6 This is a schematic diagram of the structure of a single sign-on system provided in an embodiment of this disclosure;
[0031] Figure 7 This is a schematic diagram of another single sign-on system provided in an embodiment of this disclosure;
[0032] Figure 8 This is a schematic diagram of the structure of another single sign-on system provided in an embodiment of this disclosure. Detailed Implementation
[0033] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0034] The single sign-on method, system, and storage medium of this disclosure are described below with reference to the accompanying drawings.
[0035] Figure 1 This is a flowchart illustrating a single sign-on method provided according to an embodiment of this disclosure, such as... Figure 1 As shown, the method may include the following steps:
[0036] Step 101: Deploy the OIDC (OpenID Connect) service, the first microservice, and the second microservice on the management node where the target platform is located.
[0037] In some embodiments, the target platform described above may be an AI training management platform or an artificial intelligence platform.
[0038] In some embodiments, the first microservice described above can be used to determine the user's role after mapping.
[0039] In some embodiments, the second microservice described above can be used to store the mapping relationship between roles in the target platform and roles in the OIDC service, wherein the roles in the OIDC service can be roles in the system.
[0040] Step 102: In response to receiving the unified authentication command triggered by the user on the target platform, the OIDC service obtains the login information entered by the user through the target login page and verifies the login information.
[0041] In some embodiments, after deploying the OIDC service, the first microservice, and the second microservice on the management node where the target platform is located through the above steps, when a user logs into the target platform, they can click the unified authentication button on the login page of the target platform to trigger the unified authentication instruction of the target platform.
[0042] In some embodiments, in response to receiving a unified authentication instruction from a user to trigger the target platform, the target login page corresponding to the OIDC service can be output, and the OIDC service can obtain the login information entered by the user through the target login page and verify the login information.
[0043] In some embodiments, the login information may include a username and password.
[0044] In some embodiments, the OIDC service can store user information configured by the user on the OIDC service for subsequent verification of login information. In some embodiments, the user information configured by the user on the OIDC service may include an account, password, and corresponding role. It should be noted that in some embodiments, the role corresponding to the user configured by the user on the OIDC service can be a role in the system.
[0045] In some embodiments, after the OIDC service obtains the login information entered by the user, it can verify the login information based on the user information stored in the database. If the login information exists in the database, the verification is deemed successful; if the login information does not exist in the database, the verification is deemed unsuccessful.
[0046] In some embodiments, after obtaining the login information entered by the user, the OIDC service can verify the login information through multi-factor authentication. Specifically, in some embodiments, after performing first-factor authentication on the login information, a second-factor authentication is also required for the user. If both the first-factor authentication and the second-factor authentication pass verification, the user is determined to have passed verification; otherwise, the user is determined to have failed verification. In some embodiments, the second-factor authentication may include verification codes, SMS messages, and biometric authentication (such as fingerprints or facial features).
[0047] Step 103: When the verification is successful, the OIDC service will provide the user's account information and primary role information.
[0048] In some embodiments, after the login information verification is confirmed to be successful through the above steps, the OIDC service can provide the user's account information and first role information.
[0049] In some embodiments, the first role information is used to indicate the user's role in the OIDC service.
[0050] In some embodiments, the OIDC service can feed back the user's account information and first role information to the first microservice so that the first microservice can perform role mapping based on the obtained first role information.
[0051] Step 104: The first microservice reads the role mapping relationship from the second microservice and determines the second role information corresponding to the first role information based on the role mapping relationship.
[0052] In some embodiments, after the first microservice obtains the account information and first role information fed back by the OIDC service through the above steps, it can read the role mapping relationship from the second microservice and determine the second role information corresponding to the first role based on the role mapping relationship, so that the user can log in to the target platform based on the second role information.
[0053] In some embodiments, the second role information is used to indicate the user's role on the target platform.
[0054] In some embodiments, the role mapping relationship may include a mapping relationship between first role information of the OIDC service and second role information of the target platform, wherein the second role information corresponds to at least one first role information.
[0055] In some embodiments, the aforementioned second role information may include any of the following:
[0056] System administrator;
[0057] Group administrator;
[0058] Regular users;
[0059] Custom user.
[0060] For example, in some embodiments, the above role mapping relationship may include:
[0061] Group administrators: Role 1, Role 2, Role 3;
[0062] Regular users: Character 4, Character 5, Character 6;
[0063] System Administrators: Role 7, Role 8, Role 9.
[0064] In some embodiments, each second role information may correspond to at least one first role information, and each first role information may correspond to one second role information.
[0065] In some embodiments, the above role mapping relationship can automatically map platform roles and custom roles without manual configuration, which facilitates the connection between customer systems and target platforms, makes it easier for users to use, and improves work efficiency.
[0066] Step 105: Log in to the target platform based on account information and second role information.
[0067] In some embodiments, after obtaining account information and second role information through the above steps, one can log in to the target platform based on the account information and second role information.
[0068] For example, assuming the second role information is a regular user, the user logs into the target platform with account information and the regular user role.
[0069] The single sign-on method provided in this disclosure deploys an OIDC service, a first microservice, and a second microservice on the management node where the target platform is located. In response to receiving a unified authentication command from a user triggering the target platform, the OIDC service obtains the login information entered by the user through the target login page and verifies the login information. When the verification passes, the OIDC service returns the user's account information and first role information, where the first role information indicates the user's role in the OIDC service. The first microservice reads the role mapping relationship from the second microservice and determines the second role information corresponding to the first role information based on the role mapping relationship. The second role information indicates the user's role on the target platform. The user then logs into the target platform based on the account information and the second role information. This disclosure automatically maps roles according to the role mapping relationship through the OIDC service, the first microservice, and the second microservice, eliminating the need for manual configuration. This supports automatic mapping of platform roles and system roles, facilitating the integration between customer systems and the target platform, improving user convenience, and increasing work efficiency.
[0070] In some embodiments, as a detailed explanation of step 105, such as Figure 2 As shown, it may also include:
[0071] Step 201: When the second role information is group administrator, determine whether account information exists in the target platform.
[0072] In some embodiments, if the second role information is determined to be a group administrator, it is necessary to determine whether to modify the second role information based on the account information and grouping situation in the target platform, so that the user can successfully log in to the target platform based on the corresponding role.
[0073] In some embodiments, the existence of account information can be determined through user information in the target platform's database.
[0074] Step 202: If it is determined that account information exists on the target platform, then determine whether the account information is in the default group.
[0075] In some embodiments, if it is determined that account information exists on the target platform, it is necessary to determine whether the account information is in the default group in order to determine whether the second role information corresponding to the account information needs to be modified.
[0076] Step 203: If the account information is in the default group, then change the second role information to a regular user.
[0077] In some embodiments, if the account information is in the default group, there is no group administrator in the default group. Therefore, it is necessary to change the second role information to a regular user.
[0078] Step 204: If the account information is within the target group, then set the second role information to the group administrator of the target group.
[0079] In some embodiments, if the account information is in the target group, it means that the account information is not in the default group. Based on the fact that the second role information corresponding to the account information is a group administrator, the second role information is set as the group administrator of the target group.
[0080] For example, in some embodiments, if the target group is group g1 and the account information is within group g1, then the second role information is set as the group administrator of group g1.
[0081] Step 205: If it is determined that no account information exists on the target platform, the second role information is modified to a regular user and set in the default group.
[0082] In some embodiments, if it is determined that no account information exists on the target platform, it indicates that the user is a new user on the target platform. In this case, the second role information needs to be changed to a regular user and set in the default group.
[0083] It should be noted that, in some embodiments, when the second role information is a group administrator, the above steps can be used to determine whether to modify the second role information based on the account information and grouping situation in the target platform, so that the user can successfully log in to the target platform based on the corresponding role.
[0084] In some embodiments, a third microservice is also deployed on the management node where the target platform is located, such as... Figure 3 As shown, the above method may further include:
[0085] Step 301: The third microservice obtains the configuration file uploaded by the user and pushes the role mapping relationship in the configuration file to the second microservice.
[0086] In some embodiments, the configuration file can be a yml file, which may include the role mapping relationship described above.
[0087] In some embodiments, after the third microservice obtains the configuration file uploaded by the user, it can push the role mapping relationship in the configuration file to the second microservice through a message bus. In some embodiments, the message bus can be implemented using RabbitMQ.
[0088] Step 302: The second microservice stores the role mapping relationship.
[0089] In some embodiments, after the second microservice obtains the role mapping relationship through the message bus, it can store the role mapping relationship.
[0090] In some embodiments, the above steps can be used to achieve real-time propagation of role mapping relationships between the first microservice and the second microservice through a message bus, thereby ensuring that the first microservice can perform role mapping based on the role mapping relationship in the second microservice after receiving account information and first role information.
[0091] In some embodiments, such as Figure 4 As shown, the above method may further include:
[0092] Step 401: In response to a change in the configuration file in the third microservice, the third microservice pushes an update message to the second microservice and pushes the updated role mapping relationship to the second microservice.
[0093] In some embodiments, a listening mechanism (such as a Watch mechanism or file polling) can be used to detect whether the configuration file in the third microservice has changed. When a change in the configuration file in the third microservice is detected, the third microservice is triggered to push an update message to the second microservice, and the updated role mapping relationship is encapsulated as a message and published to the message bus and pushed to the second microservice.
[0094] Step 402: In response to the second microservice receiving the update message, the updated role mapping relationship is stored.
[0095] In some embodiments, after receiving an update message, the second microservice can load the updated role mapping relationship into the local memory cache for storage, thereby enabling hot updates of the configuration that take effect without restarting the service.
[0096] In some embodiments, the third microservice can push the updated role mapping relationship to the second microservice through the above steps, so that the second microservice can load the updated role mapping relationship into the local memory cache for storage, thereby realizing hot update of the configuration, which can take effect without restarting the service.
[0097] Based on the above description Figure 5 This is a flowchart illustrating a single sign-on method provided according to an embodiment of this disclosure, such as... Figure 5As shown, when a user logs into the AI platform, clicking the unified authentication button redirects them to the login page provided by the OIDC service for single sign-on. The OIDC service obtains the login information entered by the user and verifies the account and password. When the verification is successful, it returns the corresponding account information and first role information. The first microservice reads the role mapping relationship from the second microservice, determines the second role information mapped by the first role information based on the role mapping relationship, and logs into the AI platform based on the second role information and account information.
[0098] To implement the single sign-on method provided in this disclosure, this disclosure also provides a single sign-on system. For example... Figure 6 As shown, it includes:
[0099] Deployment module 611 is used to deploy the OIDC service, the first microservice, and the second microservice on the management node where the target platform is located.
[0100] The first login module 612 is used to respond to the unified authentication command triggered by the user on the target platform. The OIDC service obtains the login information entered by the user through the target login page and verifies the login information.
[0101] The sending module 613 is used to send the user's account information and first role information back to the OIDC service when the verification is successful. The first role information is used to indicate the user's role in the OIDC service.
[0102] The determination module 614 is used for the first microservice to read the role mapping relationship from the second microservice and determine the second role information corresponding to the first role information based on the role mapping relationship. The second role information is used to indicate the user's role in the target platform.
[0103] The second login module 615 is used to log in to the target platform based on account information and second role information.
[0104] The single sign-on system provided in this disclosure deploys an OIDC service, a first microservice, and a second microservice on the management node where the target platform is located. In response to receiving a unified authentication command from a user triggering the target platform, the OIDC service obtains the login information entered by the user through the target login page and verifies the login information. When the verification is successful, the OIDC service returns the user's account information and first role information, where the first role information indicates the user's role in the OIDC service. The first microservice reads the role mapping relationship from the second microservice and determines the second role information corresponding to the first role information based on the role mapping relationship. The second role information indicates the user's role on the target platform. The user then logs into the target platform based on the account information and the second role information. This disclosure automatically maps roles according to the role mapping relationship through the OIDC service, the first microservice, and the second microservice, eliminating the need for manual configuration. This supports automatic mapping of platform roles and system roles, facilitating the integration between customer systems and the target platform, improving user convenience, and increasing work efficiency.
[0105] Furthermore, in one possible implementation of this disclosure embodiment, the second role information includes any of the following:
[0106] System administrator;
[0107] Group administrator;
[0108] Regular user.
[0109] Furthermore, in one possible implementation of this disclosure embodiment, the above-mentioned role mapping relationship includes a mapping relationship between the first role information of the OIDC service and the second role information of the target platform, wherein the second role information corresponds to at least one of the first role information.
[0110] Furthermore, in one possible implementation of this disclosure embodiment, when the second role information is a group administrator, the aforementioned second login module 615 is specifically used for:
[0111] Determine if account information exists on the target platform;
[0112] If it is determined that account information exists on the target platform, then determine whether the account information is in the default group;
[0113] If the account information is in the default group, then change the second role information to a regular user;
[0114] If the account information is within the target group, then set the second role information to the group administrator of the target group;
[0115] If it is determined that no account information exists on the target platform, the second role information will be changed to a regular user and set in the default group.
[0116] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 7 As shown, the above-mentioned single sign-on system also includes a first push module 616, which is specifically used for:
[0117] The third microservice retrieves the configuration file uploaded by the user and pushes the role mapping relationship in the configuration file to the second microservice;
[0118] The second microservice stores the role mapping relationship.
[0119] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 8 As shown, the above-mentioned single sign-on system also includes a second push module 617, which is specifically used for:
[0120] In response to changes in the configuration file in the third microservice, the third microservice pushes an update message to the second microservice and pushes the updated role mapping relationship to the second microservice.
[0121] In response to the second microservice receiving an update message, the updated role mapping relationship is stored.
[0122] Embodiments of this disclosure also provide an electronic device including a memory and a processor, the memory storing a computer program, the processor being configured to run the computer program to perform the steps in any of the single sign-on method embodiments described above.
[0123] Embodiments of this disclosure also provide a computer-readable storage medium storing a computer program configured to execute the steps in any of the single sign-on method embodiments described above when the computer program is run.
[0124] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.
[0125] Embodiments of this disclosure also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above-described single sign-on method embodiments.
[0126] Embodiments of this disclosure also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in any of the above-described single sign-on method embodiments.
[0127] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0128] In embodiments of this disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution device, apparatus, or electronic device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media may include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor devices, apparatus, or electronic devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage electronics, magnetic storage electronics, or any suitable combination of the foregoing.
[0129] To provide interaction with a user, the apparatus and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of apparatus can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0130] The apparatus and techniques described herein can be implemented in computing devices that include backend components (e.g., as a data server), or computing devices that include middleware components (e.g., an application server), or computing devices that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the apparatus and techniques described herein), or computing devices that include any combination of such backend, middleware, or frontend components. The components of the apparatus can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), the Internet, and blockchain networks.
[0131] The single sign-on method provided by this disclosure has been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this disclosure. The descriptions of the embodiments above are only for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make several improvements and modifications to this disclosure without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this disclosure.
Claims
1. A single sign-on method, characterized in that, The method includes: Deploy OIDC service, first microservice and second microservice on the management node where the target platform is located. The first microservice is used to determine the role of the user after mapping. The second microservice is used to store the mapping relationship between the role in the target platform and the role in the OIDC service. The role in the OIDC service includes the role in the system. In response to receiving a unified authentication command from a user to trigger the target platform, the OIDC service obtains the login information entered by the user through the target login page and verifies the login information; When the verification is successful, the OIDC service will return the user's account information and first role information, wherein the first role information is used to indicate the user's role in the OIDC service; The first microservice reads the role mapping relationship from the second microservice and determines the second role information corresponding to the first role information based on the role mapping relationship. The second role information is used to indicate the user's role in the target platform. Log in to the target platform based on the account information and the second role information; When the second role information is a group administrator, logging into the target platform based on the account information and the second role information includes: Determine whether the account information exists on the target platform; If it is determined that the account information exists in the target platform, then determine whether the account information is in the default group; If the account information is in the default group, then the second role information will be changed to a regular user; If the account information is within the target group, then the second role information is set as the group administrator of the target group; If it is determined that the account information does not exist in the target platform, the second role information is modified to a regular user and set in the default group.
2. The method according to claim 1, characterized in that, The method further includes deploying a third microservice on the management node where the target platform is located, and also includes: The third microservice obtains the configuration file uploaded by the user and pushes the role mapping relationship in the configuration file to the second microservice; The second microservice stores the role mapping relationship.
3. The method according to claim 1, characterized in that, The second role information also includes: system administrator.
4. The method according to claim 2, characterized in that, The method further includes: In response to a change in the configuration file in the third microservice, the third microservice pushes an update message to the second microservice and pushes the updated role mapping relationship to the second microservice. In response to the second microservice receiving the update message, the updated role mapping relationship is stored.
5. The method according to any one of claims 1-4, characterized in that, The role mapping relationship includes the mapping relationship between the first role information of the OIDC service and the second role information of the target platform, wherein the second role information corresponds to at least one of the first role information.
6. A single sign-on system, characterized in that, The system includes: The deployment module is used to deploy the OIDC service, the first microservice, and the second microservice on the management node where the target platform is located. The first microservice is used to determine the user's role after mapping, and the second microservice is used to store the mapping relationship between the roles in the target platform and the roles in the OIDC service. The roles in the OIDC service include roles in the system. The login module is used to respond to a unified authentication command triggered by a user on the target platform. The OIDC service obtains the login information entered by the user through the target login page and verifies the login information. The sending module is used to send the user's account information and first role information back to the OIDC service when the verification is successful, wherein the first role information is used to indicate the user's role in the OIDC service; The determination module is used for the first microservice to read the role mapping relationship from the second microservice and determine the second role information corresponding to the first role information based on the role mapping relationship, wherein the second role information is used to indicate the user's role in the target platform; The login module is used to log in to the target platform based on the account information and the second role information. When the second role information is a group administrator, the login process based on the account information and the second role information includes: determining whether the account information exists in the target platform; if the account information exists in the target platform, determining whether the account information is in the default group; if the account information is in the default group, changing the second role information to a regular user; if the account information is in the target group, setting the second role information as the group administrator of the target group; if the account information does not exist in the target platform, changing the second role information to a regular user and setting it in the default group.
7. The system according to claim 6, characterized in that, A third microservice is also deployed on the management node where the target platform is located, and the system is further used for: The third microservice obtains the configuration file uploaded by the user and pushes the role mapping relationship in the configuration file to the second microservice; The second microservice stores the role mapping relationship.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the single sign-on method as described in any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the single sign-on method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Cross-platform joint identity authentication method and system, storage medium and equipment
CN114422260A
SSO cross-platform login method and device
CN116015791A
Implementation method for constructing unified user authentication center based on OIDC framework
CN120354390A