US2018032749A1PendingUtilityA1

On-demand database service system, method and computer program product for conditionally allowing an application of an entity access to data of another entity

Assignee: SALESFORCE COM INCPriority: Jul 19, 2007Filed: Jun 29, 2017Published: Feb 1, 2018
Est. expiryJul 19, 2027(~1 yrs left)· nominal 20-yr term from priority
G06F 16/24573G06F 21/31G06F 21/6227H04L 63/102G06F 2221/2141G06F 8/61G06F 2221/2105H04W 4/50G06F 21/6218H04L 67/306G06F 2221/2147G06F 8/65G06F 17/30525H04W 4/001
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In accordance with embodiments, there are provided mechanisms and methods for conditionally allowing an application of an entity access to data of another entity in an on-demand database service. These mechanisms and methods for conditionally allowing an application of an entity access to data of another entity in an on-demand database service can enable embodiments to limit such access to the data, as desired. Furthermore, embodiments of such mechanisms and methods may provide additional security when sharing data among different subscribers to an on-demand database service.

Claims

exact text as granted — not AI-modified
1 - 14 . (canceled) 
     
     
         15 . A method, comprising:
 determining, by a computer system, that a user of a database service, is authorized to obtain a package that includes an application of an entity;   in response to the determining, installing the package by the computer system;   extracting, by the computer system, one or more profiles from the package, wherein the one or more profiles include a plurality of permissions for accessing, by the application, data of the user within the database service, including actions that may be performed on the data by the application;   presenting, by the computer system, the plurality of permissions on the computer system for the user to accept; and   in response to rejecting, by the user, at least one permission of the plurality of permissions of the one or more profiles, removing the at least one permission from the one or more profiles.   
     
     
         16 . The method of  claim 15 , wherein installing the package comprises authenticating, by the computer system, the application before installing is initiated. 
     
     
         17 . The method of  claim 15 , wherein the package includes one or more components associated with the application, and wherein one profile of the one or more profiles is defined at a package level and a set of permissions associated with the one profile are applied to all of the one or more components. 
     
     
         18 . The method of  claim 17 , wherein a plurality of profiles are included in the package and a second profile is defined for a particular one of the one or more components within the package. 
     
     
         19 . The method of  claim 18 , wherein the second profile includes permissions not included in the set of permissions. 
     
     
         20 . The method of  claim 15 , wherein the actions include allowing the application to access special methods of the database service, wherein special methods include one or more application programming interfaces. 
     
     
         21 . The method of  claim 15 , wherein the actions include allowing the application to have write access to metadata. 
     
     
         22 . The method of  claim 15 , wherein the actions include allowing the application to perform create, read, update, and delete operations on the data. 
     
     
         23 . A non-transitory computer-readable medium carrying one or more sequences of instructions which, when executed by one or more processors, cause the one or more processors to carry out operations of:
 determining that a user of a database service, is authorized to obtain a package that includes an application of an entity;   in response to the determining, installing the package;   extracting one or more profiles from the package, wherein the one or more profiles include a plurality of permissions for accessing, by the application, data of the user within the database service, including actions that may be performed on the data by the application;   presenting the plurality of permissions on a computer system for the user to accept; and   in response to rejecting, by the user, at least one permission of the plurality of permissions of the one or more profiles, removing the at least one permission from the one or more profiles.   
     
     
         24 . The non-transitory computer-readable medium of  claim 23 , wherein to install the package, the operations further comprise authenticating the application before installing is initiated. 
     
     
         25 . The non-transitory computer-readable medium of  claim 23 , wherein the package includes one or more components associated with the application, and wherein one profile of the one or more profiles is defined at a package level and a set of permissions associated with the one profile are applied to all of the one or more components. 
     
     
         26 . The non-transitory computer-readable medium of  claim 25 , wherein a plurality of profiles are included in the package and a second profile is defined for a particular one of the one or more components within the package. 
     
     
         27 . The non-transitory computer-readable medium of  claim 26 , wherein the second profile includes permissions not included in the set of permissions. 
     
     
         28 . The non-transitory computer-readable medium of  claim 23 , wherein the actions include allowing the application to access special methods of the database service, wherein special methods include one or more application programming interfaces. 
     
     
         29 . The non-transitory computer-readable medium of  claim 23 , wherein the actions include allowing the application to have write access to metadata. 
     
     
         30 . The non-transitory computer-readable medium of  claim 23 , wherein the actions include allowing the application to perform create, read, update, and delete operations on the data. 
     
     
         31 . A method, comprising:
 submitting, by a user of a database service, authentication information to the database service;   in response to submitting the authentication information, receiving, by a computer system, a package that includes an application of an entity and one or more profiles;   installing the package, by the computer system, in response to determining that the user is authorized to obtain the package;   extracting, by the computer system, the one or more profiles from the package, wherein the one or more profiles include a plurality of limitations for accessing, by the application, data of the user within the database service, including actions that may be performed on the data by the application;   presenting, by the computer system, the plurality of limitations on the computer system for the user to accept; and   in response to rejecting, by the user, one or more of the presented plurality of limitations, adding to the plurality of limitations at least one additional limitation for accessing the data of the user by the application.   
     
     
         32 . The method of  claim 31 , wherein the authentication information includes a user name and a password associated with the user. 
     
     
         33 . The method of  claim 31 , wherein the plurality of limitations for accessing the data of the user by the application indicate a set of objects the user may access. 
     
     
         34 . The method of  claim 31 , wherein presenting the plurality of limitations comprises presenting to the user via a user interface, and wherein rejecting the plurality of limitations comprises receiving an indication that the user has rejected the presented plurality of limitations via the user interface.

Join the waitlist — get patent alerts

Track US2018032749A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.