Inter-website data transmission method and device, equipment, storage medium and product
By using hidden forms and time-limited cookie data in the transmission process between websites, the problem of low security of data transmission between websites is solved, and safe and reliable data transmission is achieved.
Patent Information
- Application Number
- CN202510917924.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-09-05
AI Technical Summary
In the prior art, data transmission between websites has the problem of low security, especially when data is transmitted through URL links, which leads to a high risk of data leakage.
By responding to the website jump instruction, the information to be transmitted is filled into the newly created hidden form and transmitted to the backend server of the target website. After verifying that the verification information is consistent, a limited-time cookie data is generated and finally transmitted to the front-end application based on the redirection mechanism.
It achieves secure data transmission between websites, avoids logic leakage and sensitive information leakage, and improves the security of data transmission and user experience.
Smart Images

Figure CN120602550A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data transmission technology, and in particular to methods, devices, equipment, storage media and products for data transmission between websites. Background Art
[0002] Cross-website jumps are a common scenario in work. When users are browsing a website, they often need to jump to other websites. In order to get a better user experience, people often expect that when jumping to other websites, the information in the target website is synchronized or associated with the information on the source website, that is, there is data transmission between the target website and the source website.
[0003] In related technologies, data is often transferred via URLs. The source website appends data as parameters to the URL. When a user clicks the link, the target website retrieves the parameters in the URL, completing the data transfer. However, this method has security issues. The URL will be displayed in the browser's address or cache, creating the risk of data leakage and reducing the security of data transmission between websites. Summary of the Invention
[0004] The main purpose of this application is to provide a method, device, equipment, storage medium and product for data transmission between websites, aiming to solve the technical problem of low security of data transmission between websites.
[0005] To achieve the above objectives, the present application proposes a method for transmitting data between websites, the method comprising:
[0006] In response to the website jump instruction, fill the information to be transferred into the newly created hidden form;
[0007] Transmitting the hidden form to the backend server of the target website;
[0008] After verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, generating time-limited cookie data according to the information to be transmitted;
[0009] Based on the redirection mechanism, the time-limited cookie data is transmitted to the front-end application of the target website.
[0010] In one embodiment, the step of transmitting the hidden form to the backend server of the target website includes:
[0011] Obtain the interface configuration rules of the target website's backend server;
[0012] Sending the hidden form to the static server of the target website;
[0013] Based on the interface configuration rules, the static server extracts information from the hidden form and adapts the rules to obtain a corresponding request instruction;
[0014] The proxy sends the request instruction to the background server.
[0015] In one embodiment, after verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, the step of generating time-limited cookie data according to the information to be transmitted includes:
[0016] According to the hidden form, searching the verification database preset in the backend server to determine the first verification information to be checked;
[0017] Parsing the hidden form to obtain the second verification information according to the preset parsing rules;
[0018] If the first verification information is consistent with the second verification information, a time-limited cookie data is generated according to the information to be transmitted in the hidden form and the preset setting validity period.
[0019] In one embodiment, the step of transmitting the time-limited cookie data to the front-end application of the target website based on the redirection mechanism includes:
[0020] Determine the pre-stored website address of the target website in the backend server according to the hidden form;
[0021] After the time-limited cookie data is generated, the target transmission URL of the time-limited cookie data is redirected to the pre-stored website address.
[0022] In one embodiment, the step of transmitting the time-limited cookie data to the front-end application of the target website based on the redirection mechanism includes:
[0023] The time-limited cookie data is combined and processed by the front-end application to obtain the information to be transmitted;
[0024] When it is detected that the front-end application obtains the information to be transmitted, the time-limited cookie data is deleted;
[0025] When it is detected that the retention time of the time-limited cookie data in the front-end application meets the corresponding time limit, the time-limited cookie data is deleted.
[0026] In one embodiment, the step of filling the information to be transferred into the newly created hidden form in response to the website jump instruction includes:
[0027] In response to the website jump instruction, create the initial form;
[0028] Determining the information to be transmitted and the target website request instruction according to the website jump instruction;
[0029] Filling the initial form based on the information to be transferred and the target website request instruction;
[0030] Perform parameter hiding settings on the initial form to obtain a hidden form.
[0031] In addition, to achieve the above-mentioned purpose, the present application also proposes an inter-website data transmission device, the inter-website data transmission device comprising:
[0032] A filling module is used to fill the information to be transferred into the newly created hidden form in response to the website jump instruction;
[0033] A backend transmission module, used to transmit the hidden form to the backend server of the target website;
[0034] A generating module, configured to verify that the first verification information in the backend server is consistent with the second verification information in the hidden form, and then generate time-limited cookie data according to the information to be transmitted;
[0035] The front-end transmission module is used to transmit the time-limited cookie data to the front-end application of the target website based on a redirection mechanism.
[0036] In addition, to achieve the above-mentioned purpose, the present application also proposes a device for transmitting data between websites, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the computer program is configured to implement the steps of the method for transmitting data between websites as described above.
[0037] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the inter-website data transmission method as described above are implemented.
[0038] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the inter-website data transmission method as described above.
[0039] One or more technical solutions proposed in this application have at least the following technical effects:
[0040] Compared with the related art, in which data is transmitted through a URL link, the source website splices the data in the form of parameters behind the URL link. When the user clicks the link, the target website obtains the parameter data in the URL link, completing the data transmission from the source website to the target website, the present application fills the information to be transmitted into a newly created hidden form in response to the website jump instruction; transmits the hidden form to the backend server of the target website; after verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, generates a time-limited cookie data based on the information to be transmitted; and transmits the time-limited cookie data to the frontend application of the target website based on the redirect mechanism. It can be understood that the present application avoids a series of security issues such as logic leakage and sensitive information leakage by filling the information to be transmitted into the hidden form and sending the hidden form to the backend server of the target website. When the verification is passed, the information to be transmitted is obtained from the hidden form, and a time-limited cookie data is generated and transmitted to the frontend of the target website, thereby achieving secure transmission of data between websites. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0042] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0043] Figure 1 A flowchart of the first embodiment of the method for transmitting data between websites of this application;
[0044] Figure 2 A flowchart of the second embodiment of the method for transmitting data between websites of this application;
[0045] Figure 3 This is a brief flowchart of the data transmission method between websites in this application;
[0046] Figure 4 This is a schematic diagram of the module structure of the device for transmitting data between websites according to an embodiment of the present application;
[0047] Figure 5Schematic diagram of the device structure of the hardware operating environment involved in the method for data transmission between websites in the embodiment of the present application.
[0048] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0049] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0050] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0051] The main solutions of the embodiments of this application are:
[0052] In response to the website jump instruction, fill the information to be transferred into the newly created hidden form;
[0053] Transmitting the hidden form to the backend server of the target website;
[0054] After verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, generating time-limited cookie data according to the information to be transmitted;
[0055] Based on the redirection mechanism, the time-limited cookie data is transmitted to the front-end application of the target website.
[0056] In this embodiment, the present application uses the inter-website data transmission device as the execution subject. For the convenience of description, it is specifically described below as "device".
[0057] Existing data transfer methods use URLs. The source website appends data as parameters to the URL. When a user clicks the link, the target website retrieves the parameters, completing the data transfer. However, this method presents security issues. The URL can be displayed in the browser's address or cache, creating the risk of data leakage and reducing the security of data transmission between websites.
[0058] This application provides a solution by filling the information to be transmitted into a hidden form and sending the hidden form to the backend server of the target website. When the verification is passed, the information to be transmitted is obtained from the hidden form, and a limited-time cookie data is generated and transmitted to the front end of the target website, avoiding a series of security issues such as logic leakage and sensitive information leakage, thereby achieving secure data transmission between websites.
[0059] Based on this, the embodiment of the present application provides a method for data transmission between websites, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the method for transmitting data between websites of the present application.
[0060] In this embodiment, the method for transmitting data between websites includes steps S10 to S40:
[0061] Step S10, in response to the website jump instruction, fill the information to be transferred into the newly created hidden form;
[0062] It should be noted that website jump instructions include but are not limited to interactive behaviors such as users clicking on hyperlinks, triggering button events, executing script jumps, etc., which initiate transfer from the source website to the target website.
[0063] The information to be transmitted includes but is not limited to user identity credentials (such as encrypted tokens), business status data (such as shopping cart IDs), permission identifiers (such as role permission codes), session context (such as language preferences), and other sensitive information that needs to be synchronized between websites.
[0064] Hidden form refers to an HTML form element that is made invisible by setting CSS properties (such as display:none) or DOM position (such as moving it out of the visible area). Its core features include: <input> / <textarea> Set method="post" to avoid URL exposure, and dynamically construct actions to point to specific endpoints on the target website.< / textarea>
[0065] It can be understood that this embodiment constructs a data container and trigger mechanism for secure transmission. By encapsulating sensitive data in an invisible standardized HTML form, it not only complies with the W3C specification to ensure cross-browser compatibility, but also avoids the risk of data leakage caused by URL parameter transmission.
[0066] In a feasible implementation, the step of filling the information to be transferred into the newly created hidden form in response to the website jump instruction includes:
[0067] In response to the website jump instruction, create the initial form;
[0068] Determining the information to be transmitted and the target website request instruction according to the website jump instruction;
[0069] Filling the initial form based on the information to be transferred and the target website request instruction;
[0070] Perform parameter hiding settings on the initial form to obtain a hidden form.
[0071] It should be noted that the initial form refers to an unconfigured form object dynamically created by document.createElement('form'), including but not limited to a blank form that has not set the action / method attribute and a form that only contains the basic DOM structure (such as <form>< / form> tag body).
[0072] The target website request instruction includes the jump target address and interface protocol requirements.
[0073] Filling the initial form means dynamically adding two types of elements: data carriers, insert <input type="hidden"> or <textarea> Store the information to be transmitted; configure the protocol, set action to the target address, method="post", and enctype="application / json"< / textarea>
[0074] Parameter hiding setting means achieving visual hiding through CSS property display:none or DOM manipulation.
[0075] It can be understood that this implementation method builds an extensible secure transmission infrastructure framework: by separating form creation, parameter configuration, and data injection, it improves code maintainability; adjusts data format and transmission protocol in real time according to the jump target; ensures that users cannot directly obtain sensitive data through hidden settings; and converts business data into a W3C standard form structure to eliminate browser compatibility risks.
[0076] In this implementation, by constructing standardized hidden forms in steps, the data exposure risk in traditional jumps and the poor compatibility of third-party solutions are solved, and lightweight and secure transmission with zero new components is achieved.
[0077] Step S20, transmitting the hidden form to the backend server of the target website;
[0078] It should be noted that the backend server includes but is not limited to the target website's business processing server, middleware layer, and data verification microservice; the static server refers to the front-end proxy server (such as Nginx), which is responsible for receiving the initial form request, performing protocol conversion (such as HTTP / HTTPS), and load balancing distribution.
[0079] It can be understood that this implementation method builds the core mechanism of a secure transmission channel: utilizing the browser's native form submission capability to avoid the security risks of manually constructing requests; transmitting data through the POST request body to avoid leakage of URL parameters of GET requests; relying on HTTPS encrypted channels to prevent network sniffing; static servers assume the responsibility of protocol adaptation, allowing background services to focus on business logic; the front-end and back-end interact through a standard HTTP interface to reduce system coupling; among them, the static server can intercept malicious requests (such as SQL injection) to form the first line of defense.
[0080] In a feasible implementation manner, the step of transmitting the hidden form to the backend server of the target website includes:
[0081] Obtain the interface configuration rules of the target website's backend server;
[0082] Sending the hidden form to the static server of the target website;
[0083] Based on the interface configuration rules, the static server extracts information from the hidden form and adapts the rules to obtain a corresponding request instruction;
[0084] The proxy sends the request instruction to the background server.
[0085] It should be noted that interface configuration rules include, but are not limited to, data format specifications, security verification mechanisms, and protocol version requirements. A static server refers to a proxy service (such as Nginx / Apache) located in front of the target website. Its core functions are to receive raw form requests, perform protocol conversion and data cleansing, and add / remove security header information.
[0086] In this embodiment, the protocol conversion layer of the static server solves the compatibility issues and interface exposure risks of heterogeneous system docking, and realizes secure data transmission with zero client transformation.
[0087] Step S30: after verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, generating time-limited cookie data according to the information to be transmitted;
[0088] It should be noted that the first verification information refers to information pre-stored on the target website's backend server and used to verify the legitimacy and authenticity of the data. It can be a pre-set key, token, user ID, etc. The second verification information refers to the corresponding verification information carried in the hidden form sent from the source website to the target website, such as an encrypted user ID or a specific verification key.
[0089] After verification, the target website's backend server generates a time-limited cookie based on the information to be passed in the hidden form (such as user identity and business status), following specific rules and formats. This cookie contains various information to be passed to the target website's front-end application and has an expiration date, after which the cookie expires.
[0090] As you can understand, by verifying the verification information in the backend server and the hidden form, we can effectively prevent malicious users or attackers from forging data for transmission, ensuring that legitimate, verified data is accepted and processed, thereby improving the security of data transmission between websites and avoiding security issues such as the leakage of sensitive information. Generating limited-time cookie data ensures that the information to be transmitted can be accurately and completely transmitted from the backend server to the front-end application of the target website, and is valid for a limited time. This ensures that users receive the correct business status and information after redirecting to the target website, improving the user experience.
[0091] In a feasible implementation manner, after verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, the step of generating time-limited cookie data according to the information to be transmitted includes:
[0092] According to the hidden form, searching the verification database preset in the backend server to determine the first verification information to be checked;
[0093] Parsing the hidden form to obtain the second verification information according to the preset parsing rules;
[0094] If the first verification information is consistent with the second verification information, a time-limited cookie data is generated according to the information to be transmitted in the hidden form and the preset setting validity period.
[0095] It should be noted that searching the verification database preset within the backend server refers to accessing a database pre-set and stored in the target website's backend server. This database stores various verification data used for verification, such as keys, tokens, user identification, and other corresponding relationships. The preset validity period is the length of time the cookie data is valid, which is pre-defined in the system.
[0096] As you can see, by retrieving the verification database on the backend server and comparing it with the verification information in the hidden form, and only proceeding with subsequent operations when the two are consistent, we effectively prevent the acceptance and processing of illegal or forged data, ensuring the legitimacy and authenticity of the data. The generated time-limited cookie data can securely transmit the information to be transmitted from the backend to the frontend within a limited time, ensuring the accuracy and timeliness of information transmission, while also enhancing the security of the data transmission process and reducing the risk of data interception and tampering.
[0097] For example, when a user clicks a link on social media platform A to view specific news on news website B, social media platform A constructs a hidden form containing the user's identity information (e.g., an encrypted user ID) as the information to be transmitted, and a key for verification as the second verification information. This hidden form is sent to the backend server of news website B. Upon receiving the form, the backend server of news website B parses the user's identity information and key from the form according to preset parsing rules. Simultaneously, the backend server searches a preset verification database for the pre-stored key corresponding to the source news website B as the first verification information. If the comparison confirms that the first verification information and the second verification information are consistent, indicating that the data is legitimate, the backend server generates a limited-time cookie based on the user's identity information and a preset validity period of one minute. This cookie contains the user's identity information, interests, and other information, and is used to provide personalized recommendations of relevant news and other content to the user on news website B. It automatically expires after one minute, ensuring the secure transmission and proper use of data during the redirection process.
[0098] Step S40: Based on the redirection mechanism, the time-limited cookie data is transmitted to the front-end application of the target website.
[0099] In a feasible implementation, the step of transmitting the time-limited cookie data to the front-end application of the target website based on the redirection mechanism includes:
[0100] Determine the pre-stored website address of the target website in the backend server according to the hidden form;
[0101] After the time-limited cookie data is generated, the target transmission URL of the time-limited cookie data is redirected to the pre-stored website address.
[0102] It's understandable that the redirection mechanism ensures that time-limited cookie data is automatically transferred from the backend server to the target website's frontend application without the user's knowledge, ensuring smooth and convenient data transfer and enhancing the user experience. Transmitting time-limited cookie data through the redirection mechanism ensures that data reaches the frontend accurately from the backend. Furthermore, due to the cookie's scope restrictions and the browser's security mechanisms, the risk of data interception and tampering is reduced, ensuring data security.
[0103] For example, after a user completes editing a document on online office platform A and clicks a link to save the file on cloud storage platform B, office platform A sends the user's document information and identity credentials as information to be transferred to cloud storage platform B's backend server via a hidden form. After verification, the backend server generates a time-limited cookie containing the user's identity and document information. This time-limited cookie is then transferred to cloud storage platform B's frontend application through a redirect mechanism. Specifically, the backend server returns a redirect response with the Location field in the response header pointing to the URL of cloud storage platform B's file save page. The response header also carries the time-limited cookie data via the Set-Cookie setting. Upon receiving this response, the browser automatically initiates a request to cloud storage platform B's file save page and sends the cookie data as part of the request. Cloud storage platform B's frontend application retrieves this time-limited cookie data through the JavaScript document.cookie interface and, based on the information contained in the cookie, provides the user with a personalized file save interface and workflow. Users can conveniently save documents to their own cloud storage space, and the entire redirect and data transfer process is seamless and user-friendly, requiring no additional effort.
[0104] In a feasible implementation manner, the step of transmitting the time-limited cookie data to the front-end application of the target website based on the redirection mechanism includes:
[0105] The time-limited cookie data is combined and processed by the front-end application to obtain the information to be transmitted;
[0106] When it is detected that the front-end application obtains the information to be transmitted, the time-limited cookie data is deleted;
[0107] When it is detected that the retention time of the time-limited cookie data in the front-end application meets the corresponding time limit, the time-limited cookie data is deleted.
[0108] It should be noted that the front-end application refers to the code that the target website runs on the user's browser. It will perform a series of operations on the received limited-time cookie data, such as parsing and extraction, and reassemble the information to be transmitted contained therein into a usable data format according to specific rules or requirements, so that it can be displayed or processed on the front-end of the target website. After certain conditions are met, the limited-time cookie data stored in the browser is removed through technical means to avoid the security risks or information confusion that may be caused by the long-term existence of this data in the browser. The retention period refers to the length of time that the limited-time cookie data exists in the front-end application (browser). The limited-time period is the pre-set effective existence time of the cookie data. When the actual retention period reaches or exceeds this set time, it is considered that the deletion condition is met.
[0109] It's understandable that by combining and processing limited-time cookie data through front-end applications, the information to be delivered can be quickly and accurately extracted and applied to the target website's front-end display or business logic, providing users with a personalized and consistent user experience while avoiding interference from unnecessary or expired data. After the front-end application obtains the information to be delivered and when the cookie data retention period reaches its limit, the cookie data is promptly deleted, reducing the risk of data leakage caused by long-term storage in the browser and effectively protecting user privacy and data security.
[0110] For example, suppose a user completes a series of courses on learning platform A and then clicks a link to jump to certificate issuance platform B to obtain the corresponding course certificate. Learning platform A will send the user's course information and identity information as the information to be transmitted to the backend server of certificate issuance platform B via a hidden form. After the backend server verifies the information, it generates a time-limited cookie containing the user's course information and identity information (set to a time limit of 15 minutes). Based on the redirect mechanism, this time-limited cookie data is transmitted to the front-end application of certificate issuance platform B.
[0111] When the front-end application of the certificate issuing platform B is loaded, the limited-time cookie data is combined and processed through JavaScript scripts to parse the user's specific course information (such as course name, learning duration, etc.) and identity information (such as user name, ID, etc.), and display this information on the certificate preview page, so that users can view their certificate content.
[0112] At the same time, the front-end application will detect whether it has successfully obtained the information to be transmitted. Once the information is obtained, it will immediately delete the limited-time cookie data to prevent the cookie from being retained in the browser for a long time. In addition, the front-end application will also set a timer. If for some reason (such as the user not viewing the certificate preview page in time) the limited-time cookie data is retained in the browser for 15 minutes, the function of deleting the cookie data will be automatically triggered to ensure that the user's course information and identity information will not be maliciously obtained or abused, thus ensuring the security and efficiency of the entire data transmission and use process.
[0113] This embodiment provides a method for transmitting data between websites. The method fills the information to be transmitted into a hidden form and sends the hidden form to the backend server of the target website. When verification is passed, the information to be transmitted is obtained from the hidden form, and a time-limited cookie data is generated and transmitted to the front end of the target website. This avoids a series of security issues such as logic leakage and sensitive information leakage, thereby achieving secure data transmission between websites.
[0114] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 2 When a user performs an action on the front-end application of source website A, triggering a request to jump to target website B, the front-end application of source website A first forms the data into a customized format, encapsulating the information to be transmitted in a specific format within a hidden form. It also pre-packages the request, including setting form properties to ensure the correct submission direction and method. Next, it triggers the request transfer and sends the encapsulated form through the browser's form submission mechanism.
[0115] The front-end application of target website B initiates a data transfer request to retrieve the data passed from source website A. Target website B's front-end application also includes a cookie security mechanism to ensure secure operations on cookie data. When the request reaches Nginx, the front-end application of target website B, Nginx first adapts the request, adjusting its format and parameters to meet the requirements of target website B's back-end services. It then proxies the adapted request to target website B's back-end application. During this process, Nginx also provides static resource services, such as images, style sheets, and other static files required by the website.
[0116] After receiving the request, the backend application of target website B first verifies the data to ensure its integrity and security. Once verification is successful, a redirection mechanism is used to generate a time-limited cookie from the information to be transferred and transmit it to the frontend application of target website B. This completes the secure data transmission process from source website A to target website B, ensuring the confidentiality, integrity, and availability of the data during transmission, providing users with a secure and reliable data transmission solution between websites.
[0117] For example, to help understand the implementation process of the inter-website data transmission method obtained by combining this embodiment with the above embodiment 1, please refer to Figure 3 , Figure 3 A brief flowchart of a method for transmitting data between websites is provided, specifically:
[0118] First, in the front-end application of source website A, the data is formatted and the request is pre-packaged. Then, the request transfer is triggered and the packaged request is sent.
[0119] When the request reaches the front-end application of target website B, a request to transfer data will be initiated. At the same time, the front-end application of target website B will perform security processing on the cookie.
[0120] The request passes through Nginx, the front-end application of target website B. Nginx adapts and proxies the request and provides static resource services.
[0121] Finally, in the background application of the target website B, the data is verified, and the redirection mechanism and data cookie transmission are used to complete the secure data transmission.
[0122] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the data transmission method between websites of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.
[0123] This application also provides a data transmission device between websites, please refer to Figure 4 , the inter-website data transmission device includes:
[0124] A filling module is used to fill the information to be transferred into the newly created hidden form in response to the website jump instruction;
[0125] A backend transmission module, used to transmit the hidden form to the backend server of the target website;
[0126] A generating module, configured to verify that the first verification information in the backend server is consistent with the second verification information in the hidden form, and then generate time-limited cookie data according to the information to be transmitted;
[0127] The front-end transmission module is used to transmit the time-limited cookie data to the front-end application of the target website based on a redirection mechanism.
[0128] And / or, the backend transmission module includes:
[0129] The first acquisition module is used to obtain the interface configuration rules of the backend server of the target website;
[0130] A first sending module, configured to send the hidden form to a static server of a target website;
[0131] A first adaptation module is configured to extract information and adapt rules of the hidden form through the static server based on the interface configuration rules to obtain a corresponding request instruction;
[0132] The second sending module is used for sending the request instruction to the background server on behalf of the server.
[0133] And / or, the generating module includes:
[0134] A first retrieval module is configured to retrieve a verification database preset in the backend server according to the hidden form to determine first verification information to be checked;
[0135] A first parsing module, configured to parse and obtain second verification information in the hidden form according to a preset parsing rule;
[0136] The first generating module is configured to generate time-limited cookie data according to the information to be transmitted in the hidden form and the preset effective time if the first verification information is consistent with the second verification information.
[0137] And / or, the front-end transmission module includes:
[0138] A first determining module is used to determine the pre-stored website address of the target website in the backend server according to the hidden form;
[0139] The first redirection module is used to redirect the target transmission URL of the time-limited cookie data to the pre-stored website address after generating the time-limited cookie data.
[0140] And / or, the inter-website data transmission device includes:
[0141] A first processing module is used to combine and process the time-limited cookie data through a front-end application to obtain the information to be transmitted;
[0142] A first deletion module is configured to delete the time-limited cookie data upon detecting that the front-end application has acquired the information to be transmitted;
[0143] The second deletion module is used to delete the time-limited cookie data when it is detected that the retention time of the time-limited cookie data in the front-end application meets the corresponding time limit.
[0144] And / or, the filling module includes:
[0145] The first creation module is used to create an initial form in response to a website jump instruction;
[0146] A second determining module is used to determine the information to be transferred and the target website request instruction according to the website jump instruction;
[0147] A first filling module is used to fill the initial form based on the information to be transferred and the target website request instruction;
[0148] The first hiding module is used to perform parameter hiding settings on the initial form to obtain a hidden form.
[0149] The inter-website data transmission device provided in this application utilizes the inter-website data transmission method in the above-described embodiment, thereby resolving the technical issue of low security for inter-website data transmission. Compared to the prior art, the inter-website data transmission device provided in this application achieves the same beneficial effects as the inter-website data transmission method in the above-described embodiment. Other technical features of the inter-website data transmission device are the same as those disclosed in the above-described embodiment and are not further elaborated here.
[0150] The present application provides an inter-website data transmission device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the inter-website data transmission method in the above-mentioned embodiment 1.
[0151] Reference below Figure 5, which shows a schematic diagram of the structure of an inter-website data transmission device suitable for implementing the embodiments of the present application. The inter-website data transmission device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, tablet computers, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), and fixed terminals such as digital televisions and desktop computers. Figure 5 The inter-website data transmission device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0152] like Figure 5 As shown, the inter-site data transmission device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the inter-site data transmission device. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and communication device 1009. Communication device 1009 can allow the inter-site data transmission device to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows an inter-site data transmission device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or have alternatively.
[0153] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0154] The inter-website data transmission device provided in this application utilizes the inter-website data transmission method of the aforementioned embodiment to address the technical issue of low security for inter-website data transmission. Compared to the prior art, the inter-website data transmission device provided in this application achieves the same beneficial effects as the inter-website data transmission method of the aforementioned embodiment. Other technical features of this inter-website data transmission device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0155] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0156] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0157] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer program) stored thereon, and the computer-readable program instructions are used to execute the inter-website data transmission method in the above-mentioned embodiment.
[0158] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0159] The computer-readable storage medium may be included in the inter-website data transmission device; or it may exist independently without being assembled into the inter-website data transmission device.
[0160] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the inter-website data transmission device, the inter-website data transmission device: responds to the website jump instruction, fills the information to be transferred into the newly created hidden form;
[0161] Transmitting the hidden form to the backend server of the target website;
[0162] After verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, generating time-limited cookie data according to the information to be transmitted;
[0163] Based on the redirection mechanism, the time-limited cookie data is transmitted to the front-end application of the target website.
[0164] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0165] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0166] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0167] The computer-readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described inter-website data transmission method. This computer-readable storage medium can address the technical issue of low security for inter-website data transmission. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the inter-website data transmission method provided in the above-described embodiment, and are not further elaborated here.
[0168] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned inter-website data transmission method when executed by a processor.
[0169] The computer program product provided in this application can solve the technical problem of low security in data transmission between websites. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the method for data transmission between websites provided in the above embodiment, and will not be elaborated here.
[0170] All acquisition of signals, information or actions in this application are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.
[0171] The above description is only part of the embodiments of the present application and does not limit the scope of protection of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the scope of patent protection of the present application.
Claims
1. A method for transmitting data between websites, characterized in that: The method includes: In response to the website jump instruction, fill the information to be transmitted into the newly created hidden form; Transmitting the hidden form to the backend server of the target website; After verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, generating time-limited cookie data according to the information to be transmitted; Based on the redirection mechanism, the time-limited cookie data is transmitted to the front-end application of the target website.
2. The method according to claim 1, wherein The step of transmitting the hidden form to the backend server of the target website includes: Obtain the interface configuration rules of the target website's backend server; Sending the hidden form to the static server of the target website; Based on the interface configuration rules, the static server extracts information from the hidden form and adapts the rules to obtain a corresponding request instruction; The proxy sends the request instruction to the background server.
3. The method according to claim 1, wherein After verifying that the first verification information in the backend server is consistent with the second verification information in the hidden form, the step of generating time-limited cookie data according to the information to be transmitted includes: According to the hidden form, searching the verification database preset in the backend server to determine the first verification information to be checked; Parsing the hidden form to obtain the second verification information according to the preset parsing rules; If the first verification information is consistent with the second verification information, a time-limited cookie data is generated according to the information to be transmitted in the hidden form and the preset setting validity period.
4. The method according to claim 1, wherein The step of transmitting the time-limited cookie data to the front-end application of the target website based on the redirection mechanism includes: Determine the pre-stored website address of the target website in the backend server according to the hidden form; After the time-limited cookie data is generated, the target transmission URL of the time-limited cookie data is redirected to the pre-stored website address.
5. The method according to claim 1, wherein The step of transmitting the time-limited cookie data to the front-end application of the target website based on the redirection mechanism includes: The time-limited cookie data is combined and processed by the front-end application to obtain the information to be transmitted; When it is detected that the front-end application obtains the information to be transmitted, the time-limited cookie data is deleted; When it is detected that the retention time of the time-limited cookie data in the front-end application meets the corresponding time limit, the time-limited cookie data is deleted.
6. The method according to claim 1, wherein The step of filling the information to be transferred into the newly created hidden form in response to the website jump instruction includes: In response to the website jump instruction, create the initial form; Determining the information to be transmitted and the target website request instruction according to the website jump instruction; Filling the initial form based on the information to be transferred and the target website request instruction; Perform parameter hiding settings on the initial form to obtain a hidden form.
7. A data transmission device between websites, characterized in that: The device comprises: A filling module is used to fill the information to be transferred into the newly created hidden form in response to the website jump instruction; A backend transmission module, used to transmit the hidden form to the backend server of the target website; A generating module, configured to verify that the first verification information in the backend server is consistent with the second verification information in the hidden form, and then generate time-limited cookie data according to the information to be transmitted; The front-end transmission module is used to transmit the time-limited cookie data to the front-end application of the target website based on a redirection mechanism.
8. A data transmission device between websites, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the method for inter-website data transmission according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the inter-website data transmission method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the inter-website data transmission method according to any one of claims 1 to 7 are implemented.