AUTHORIZING APPLICATION ACCESS TO SECURE RESOURCES
    1.
    发明申请
    AUTHORIZING APPLICATION ACCESS TO SECURE RESOURCES 有权
    授权应用程序访问安全资源

    公开(公告)号:US20130145427A1

    公开(公告)日:2013-06-06

    申请号:US13308572

    申请日:2011-12-01

    IPC分类号: G06F21/00 G06F17/30

    摘要: An application submits a permission request to a resource server. In response to receiving the request, the resource server generates a user interface that asks the user to grant or deny the requested permissions. If the permissions are granted, data is stored indicating that the application has the requested permissions. When a runtime request for a resource is received, the resource server determines whether the request has been made by a user, by an application, or by an application on behalf of a user. If the request is made by an application only, the request is granted only if the application has permission to access the resource by way of a direct call not on behalf of a user. If the request is made by an application on behalf of a user, the request is granted only if both the user and the application have sufficient permission.

    摘要翻译: 应用程序向资源服务器提交权限请求。 响应于接收到请求,资源服务器生成用户界面,要求用户授予或拒绝所请求的权限。 如果授予权限,则存储指示应用程序具有请求的权限的数据。 当接收到对资源的​​运行时请求时,资源服务器确定请求是由用户,应用程序还是由应用程序代表用户进行的。 如果请求仅由应用程序进行,则仅当应用程序具有通过不代表用户的直接呼叫访问资源的权限时,才会授予该请求。 如果请求是由应用程序代表用户进行的,则仅当用户和应用程序都有足够的权限时才会授予该请求。

    Authorizing application access to secure resources
    2.
    发明授权
    Authorizing application access to secure resources 有权
    授权应用程序访问以确保资源安全

    公开(公告)号:US09015807B2

    公开(公告)日:2015-04-21

    申请号:US13308572

    申请日:2011-12-01

    IPC分类号: H04L29/06 G06F21/62

    摘要: An application submits a permission request to a resource server. In response to receiving the request, the resource server generates a user interface that asks the user to grant or deny the requested permissions. If the permissions are granted, data is stored indicating that the application has the requested permissions. When a runtime request for a resource is received, the resource server determines whether the request has been made by a user, by an application, or by an application on behalf of a user. If the request is made by an application only, the request is granted only if the application has permission to access the resource by way of a direct call not on behalf of a user. If the request is made by an application on behalf of a user, the request is granted only if both the user and the application have sufficient permission.

    摘要翻译: 应用程序向资源服务器提交权限请求。 响应于接收到请求,资源服务器生成用户界面,要求用户授予或拒绝所请求的权限。 如果授予权限,则存储指示应用程序具有请求的权限的数据。 当接收到对资源的​​运行时请求时,资源服务器确定请求是由用户,应用程序还是由应用程序代表用户进行的。 如果请求仅由应用程序进行,则仅当应用程序具有通过不代表用户的直接呼叫访问资源的权限时,才会授予该请求。 如果请求是由应用程序代表用户进行的,则仅当用户和应用程序都有足够的权限时才会授予该请求。

    Transition from WS-Federation Passive Profile to Active Profile
    3.
    发明申请
    Transition from WS-Federation Passive Profile to Active Profile 有权
    从WS-Federation被动配置文件转移到活动配置文件

    公开(公告)号:US20120159601A1

    公开(公告)日:2012-06-21

    申请号:US12968823

    申请日:2010-12-15

    IPC分类号: G06F21/00

    CPC分类号: G06F21/335

    摘要: A server system sends a first credential request to a passive requestor at a client device. After sending the first credential request, the server system receives a credential for a user of the client device. If the credential is valid, the server system can provide the passive requestor with access to a resource provided by the server system. After providing the passive requestor with access to the resource, the server system provides an active requestor at the client device with access to the resource without sending a second credential request to the active requestor. Consequently, it may not be necessary for a user of the client device to provide credentials twice in order for the passive requestor and the active requestor to access the resource.

    摘要翻译: 服务器系统向客户端设备的被动请求者发送第一个凭证请求。 在发送第一凭证请求之后,服务器系统接收客户端设备的用户的证书。 如果凭证有效,则服务器系统可以向被动请求者提供对服务器系统提供的资源的访问。 在向被动请求者提供对资源的访问之后,服务器系统在客户端设备处提供对资源的访问,而不向主动请求者发送第二凭证请求。 因此,客户端设备的用户可能不需要两次提供凭证,以便被动请求者和主动请求者访问该资源。

    Transition from WS-Federation passive profile to active profile
    4.
    发明授权
    Transition from WS-Federation passive profile to active profile 有权
    从WS-Federation被动轮廓转换为主动轮廓

    公开(公告)号:US08370914B2

    公开(公告)日:2013-02-05

    申请号:US12968823

    申请日:2010-12-15

    IPC分类号: G06F21/00

    CPC分类号: G06F21/335

    摘要: A server system sends a first credential request to a passive requestor at a client device. After sending the first credential request, the server system receives a credential for a user of the client device. If the credential is valid, the server system can provide the passive requestor with access to a resource provided by the server system. After providing the passive requestor with access to the resource, the server system provides an active requestor at the client device with access to the resource without sending a second credential request to the active requestor. Consequently, it may not be necessary for a user of the client device to provide credentials twice in order for the passive requestor and the active requestor to access the resource.

    摘要翻译: 服务器系统向客户端设备的被动请求者发送第一个凭证请求。 在发送第一凭证请求之后,服务器系统接收客户端设备的用户的证书。 如果凭证有效,则服务器系统可以向被动请求者提供对服务器系统提供的资源的访问。 在向被动请求者提供对资源的访问之后,服务器系统在客户端设备处提供对资源的访问,而不向主动请求者发送第二凭证请求。 因此,客户端设备的用户可能不需要两次提供凭证,以便被动请求者和主动请求者访问该资源。

    MANAGEMENT OF COLLECTIONS OF WEBSITES
    5.
    发明申请
    MANAGEMENT OF COLLECTIONS OF WEBSITES 有权
    网站收藏管理

    公开(公告)号:US20120042010A1

    公开(公告)日:2012-02-16

    申请号:US13281196

    申请日:2011-10-25

    IPC分类号: G06F15/16

    摘要: This disclosure describes techniques that enable a subscriber of a data center to manage a site collection group hosted by the data center. A site collection group is a set of site collections that belong to a single subscriber. A site collection is a collection of websites. A website is a collection of related resources. Each of the site collections is associated with an “owner”. As described herein, the data center presents management interfaces that enable owners of site collections to manage the site collections. In addition, the data center presents management interfaces that enable subscribers to manage architectural aspects of their site collection groups.

    摘要翻译: 本公开描述使得数据中心的订户能够管理由数据中心托管的站点集合组的技术。 站点集合组是属于单个订阅者的一组网站集。 网站集是网站的集合。 网站是相关资源的集合。 每个网站集都与“所有者”相关联。 如本文所述,数据中心呈现管理接口,使得站点集合的所有者可以管理站点集合。 此外,数据中心还提供管理界面,使用户能够管理其站点集合组的架构。

    Management of collections of websites
    6.
    发明授权
    Management of collections of websites 有权
    管理网站收藏

    公开(公告)号:US08606816B2

    公开(公告)日:2013-12-10

    申请号:US13281196

    申请日:2011-10-25

    IPC分类号: G06F7/00 G06F17/30

    摘要: This disclosure describes techniques that enable a subscriber of a data center to manage a site collection group hosted by the data center. A site collection group is a set of site collections that belong to a single subscriber. A site collection is a collection of websites. A website is a collection of related resources. Each of the site collections is associated with an “owner”. As described herein, the data center presents management interfaces that enable owners of site collections to manage the site collections. In addition, the data center presents management interfaces that enable subscribers to manage architectural aspects of their site collection groups.

    摘要翻译: 本公开描述使得数据中心的订户能够管理由数据中心托管的站点集合组的技术。 站点集合组是属于单个订阅者的一组网站集。 网站集是网站的集合。 网站是相关资源的集合。 每个网站集都与“所有者”相关联。 如本文所述,数据中心呈现管理接口,使得站点集合的所有者可以管理站点集合。 此外,数据中心还提供管理界面,使用户能够管理其站点集合组的架构。

    Web Service Proxy Interface Augmentation
    7.
    发明申请
    Web Service Proxy Interface Augmentation 有权
    Web服务代理接口增强

    公开(公告)号:US20120291009A1

    公开(公告)日:2012-11-15

    申请号:US13104084

    申请日:2011-05-10

    IPC分类号: G06F9/44

    CPC分类号: G06F8/38

    摘要: In a web application platform context, web service proxy interface augmentation is provided without undue loss of customization capabilities. After obtaining an address of a web service endpoint, sending a metadata query to the endpoint, and extracting operational information from the response, a contract is generated in the form of an interface. The interface does not rely on non-contract programming constructs. A file containing the interface is added to a project in an integrated development environment (IDE). From a developer perspective, the IDE displays service application(s) of a server farm identified by the developer. The developer selects a service application and receives a list of web service endpoint(s). After choosing an endpoint, the developer receives an automatically generated interface containing operational information for an operation exposed by the web service endpoint. The developer also creates in the IDE a web proxy project item that includes the interface.

    摘要翻译: 在Web应用程序平台上下文中,提供Web服务代理接口扩充,而不会造成不必要的定制功能损失。 在获得web服务端点的地址之后,向端点发送元数据查询,并从响应中提取操作信息,以接口的形式生成合同。 接口不依赖于非合同编程结构。 包含该界面的文件将添加到集成开发环境(IDE)中的项目中。 从开发人员的角度来看,IDE会显示由开发人员标识的服务器场的服务应用程序。 开发人员选择服务应用程序并接收Web服务端点列表。 选择一个端点后,开发者将收到包含由Web服务端点公开的操作的操作信息的自动生成的接口。 开发人员还在IDE中创建了一个包含该界面的Web代理项目项目。

    Use Of A Single Service Application Instance For Multiple Data Center Subscribers
    8.
    发明申请
    Use Of A Single Service Application Instance For Multiple Data Center Subscribers 审中-公开
    使用多个数据中心用户的单一服务应用程序实例

    公开(公告)号:US20090234858A1

    公开(公告)日:2009-09-17

    申请号:US12049284

    申请日:2008-03-15

    IPC分类号: G06F17/30

    CPC分类号: G06F16/958

    摘要: This disclosure describes techniques of using a single instance of a network service application to provide a network service on behalf of multiple subscribers of a data center. As described herein, a data center may execute an instance of a service application that provides a service that is used by web applications that serve web sites associated with different subscribers of the data center. The instance of the service application stores service-specific data associated with the different web sites in separate partitions of a database. Storing the service-specific data associated with different web sites in separate partitions of the database enables the instance of the service application to control the data used to perform the service on a subscriber-by-subscriber basis while allowing for shared data between subscribers.

    摘要翻译: 本公开描述了使用网络服务应用的单个实例来代表数据中心的多个订户提供网络服务的技术。 如这里所述,数据中心可以执行服务应用的实例,该服务应用提供由用于数据中心的不同用户的web站点的Web应用所使用的服务。 服务应用程序的实例将与不同网站相关联的服务特定数据存储在数据库的单独分区中。 将与不同网站相关联的服务特定数据存储在数据库的单独分区中使得服务应用程序的实例能够以用户为单位来控制用于执行服务的数据,同时允许用户之间的共享数据。

    Management of collections of websites
    9.
    发明授权
    Management of collections of websites 有权
    管理网站收藏

    公开(公告)号:US08065327B2

    公开(公告)日:2011-11-22

    申请号:US12049311

    申请日:2008-03-15

    IPC分类号: G06F7/00 G06F17/30

    摘要: This disclosure describes techniques that enable a subscriber of a data center to manage a site collection group hosted by the data center. A site collection group is a set of site collections that belong to a single subscriber. A site collection is a collection of websites. A website is a collection of related resources. Each of the site collections is associated with an “owner”. As described herein, the data center presents management interfaces that enable owners of site collections to manage the site collections. In addition, the data center presents management interfaces that enable subscribers to manage architectural aspects of their site collection groups.

    摘要翻译: 本公开描述使得数据中心的订户能够管理由数据中心托管的站点集合组的技术。 站点集合组是属于单个订阅者的一组网站集。 网站集是网站的集合。 网站是相关资源的集合。 每个网站集都与“所有者”相关联。 如本文所述,数据中心呈现管理接口,使得站点集合的所有者可以管理站点集合。 此外,数据中心还提供管理界面,使用户能够管理其站点集合组的架构。

    Web service proxy interface augmentation
    10.
    发明授权
    Web service proxy interface augmentation 有权
    Web服务代理接口扩充

    公开(公告)号:US08856736B2

    公开(公告)日:2014-10-07

    申请号:US13104084

    申请日:2011-05-10

    IPC分类号: G06F9/44

    CPC分类号: G06F8/38

    摘要: In a web application platform context, web service proxy interface augmentation is provided without undue loss of customization capabilities. After obtaining an address of a web service endpoint, sending a metadata query to the endpoint, and extracting operational information from the response, a contract is generated in the form of an interface. The interface does not rely on non-contract programming constructs. A file containing the interface is added to a project in an integrated development environment (IDE). From a developer perspective, the IDE displays service application(s) of a server farm identified by the developer. The developer selects a service application and receives a list of web service endpoint(s). After choosing an endpoint, the developer receives an automatically generated interface containing operational information for an operation exposed by the web service endpoint. The developer also creates in the IDE a web proxy project item that includes the interface.

    摘要翻译: 在Web应用程序平台上下文中,提供Web服务代理接口扩充,而不会造成不必要的定制功能损失。 在获得web服务端点的地址之后,向端点发送元数据查询,并从响应中提取操作信息,以接口的形式生成合同。 接口不依赖于非合同编程结构。 包含该界面的文件将添加到集成开发环境(IDE)中的项目中。 从开发人员的角度来看,IDE会显示由开发人员标识的服务器场的服务应用程序。 开发人员选择服务应用程序并接收Web服务端点列表。 选择一个端点后,开发者将收到包含由Web服务端点公开的操作的操作信息的自动生成的接口。 开发人员还在IDE中创建了一个包含该界面的Web代理项目项目。