Maintaining a session across multiple web applications
Abstract
A technique for maintaining user sessions across multiple web applications includes receiving, by a first web application running on a first server, a cross-application request from a client application. The cross-application request indicates a user action to access a second web application, which runs on a second server. In response to receiving the cross-application request, the first web application sends a single-use password to the client application, which may send the single-use password to the second web application. The first web application receives a session request, which includes the single-use password, from the second web application. In response to receiving the session request, the first web application sends session data to the second web application, enabling the second web application to participate in a session with the client application.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of maintaining user sessions across multiple web applications, the method comprising:
receiving, by a first web application running on a first server, a cross-application request from a client application running on a client device, the cross-application request indicating a user action to access a second web application, the second web application running on a second server; sending, by the first web application in response to receiving the cross-application request, a single-use password to the client application; receiving, by the first web application, a session request from the second web application, the session request including (i) the single-use password as received by the second web application from the client application and (ii) a service secret that identifies the second web application as trusted; and in response to confirming that the service secret as received from the second web application is valid, sending, by the first web application, session data to the second web application, the session data (i) pertaining to a session previously established between the client application and the first web application and (ii) enabling the second web application to participate in the session with the client application.
2 . The method of claim 1 , further comprising:
the first server generating the single-use password in response to the first web application receiving the cross-application request, the first server generating the single-use password with a predefined expiration period, wherein the first web application is configured to treat the single-use password as invalid after the expiration period has elapsed.
3 . The method of claim 2 , further comprising, prior to the first server receiving the cross-application request:
creating the session data upon establishing the session with the client application and after successfully authenticating a user of the client application; assigning a session key to the session data, the session key uniquely identifying the session data for the session from among other session data for other sessions; and sending the session key to the client application.
4 . The method of claim 3 , wherein the session key is a random or pseudorandom value.
5 . The method of claim 3 , wherein the cross-application request received from the client device includes the session key as previously sent to the client application.
6 . The method of claim 5 , further comprising, after establishing the session with the client application and prior to receiving the cross-application request, sending a web page to the client device to be rendered by the client application, the web page including a user control configured to issue the cross-application request when operated by the user.
7 . The method of claim 1 , further comprising, when sending the session data to the second web application, also sending the session key to the second web application.
8 . The method of claim 1 , wherein the session data as sent to the second web application includes a list of allowed operations that the user is permitted to perform, such that the web second application can restrict activities of the user to those included in the list of allowed operations.
9 . The method of claim 1 wherein, prior to the first web application receiving the cross-application request, the method further includes assigning the service secret to the second web application by a platform server that unifies the first web application and the second web application under a common framework,
10 . A system, comprising a first server that runs a first web application and a second server that runs a second web application,
the first web application configured to:
receive a cross-application request from a client application that runs on a client device, the cross-application request indicating a user action to access the second web application; and
in response to receipt of the cross-application request, send a single-use password to the client application;
the second web application configured to:
receive an access request from the client application, the access request including the single-use password; and
send a session request to the first web application, the session request including (i) the single-use password as received by the second web application in the access request and (ii) a service secret that identifies the second web application as trusted;
wherein the first web application is further configured to send, in response to confirmation that the service secret as received from the second web application is valid, session data to the second web application, the session data pertaining to a session previously established between the client application and the first web application, and wherein the second web application is further configured to participate in the session with the client application.
11 . The method of claim 10 , wherein the first web application and the second web application are hosted from different Internet domains.
12 . The method of claim 11 , wherein the second web application configured to participate in the session with the client application is further configured to send content to the client application within the session.
13 . The method of claim 12 , wherein the first web application is further configured to successfully authenticate a user of the client application and provide an indication of successful authentication of the user in the session data,
wherein the second web application is further configured to send the content to the client application based on the successful authentication of the user by the first web application and without requiring additional authentication of the user by the second web application.
14 . A system, comprising a first server that includes a set of processors coupled to memory to form control circuitry, the control circuitry including instructions that implement a first web application constructed and arranged to:
receive a cross-application request from a client application that runs on a client device, the cross-application request indicating a user action to access the second web application; in response to receipt of the cross-application request, send a single-use password to the client application; receive a session request from a second web application that runs on a second server, the session request including the single-use password as received by the second web application from the client application; and in response to receipt of the session request, send session data to the second web application, the session data (i) pertaining to a session previously established between the client application and the first web application and (ii) enabling the second web application to participate in the session with the client application, the session data including a list of allowed operations that the user is permitted to perform, such that the second web application can restrict activities of the user to those included in the list of allowed operations.
15 . The system of claim 14 , wherein the first web application is further constructed and arranged to:
generate the single-use password, having a predefined expiration period, in response to the first web application receiving the cross-application request, wherein the first web application is further constructed and arranged to treat the single-use password as invalid after the expiration period has elapsed.
16 . The system of claim 15 , wherein the first web application is further constructed and arranged, prior to receipt of the cross-application request, to:
create the session data upon establishing the session with the client application and after successfully authenticating a user of the client application; assign a session key to the session data, the session key uniquely identifying the session data for the session from among other session data for other sessions; and send the session key to the client application.
17 . The system of claim 16 , wherein the cross-application request received from the client device includes the session key as previously sent to the client application.
18 . The system of claim 17 , wherein the first web application is further constructed and arranged to, after establishment of the session with the client application and prior to receipt the cross-application request, send a web page to the client device to be rendered by the client application, the web page including a user control configured to issue the cross-application request when operated by the user.
19 . The system of claim 14 , wherein the session request received from the second web application further includes a service secret that identifies the second web application as trusted, and wherein the first web application is constructed and arranged to send the session data to the second web application only after the first web application confirms that the service secret as received from the second web application is valid.
20 . The system of claim 19 , wherein the first web application constructed and arranged to send the session data to the second web application is further constructed and arranged to send the session key to the second web application.Join the waitlist — get patent alerts
Track US2021297492A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.