Asynchronous authorization of application access to resources
Abstract
According to examples, an apparatus may include a processor that may access a request for access by an application to a resource and may record the request in a data store. The processor may also identify an authorized entity to evaluate the request and output a notification to the authorized entity to evaluate the request, in which the authorized entity is to evaluate the request asynchronously with submission of the request by the application. In addition, the processor may determine whether a response is received from the authorized entity and, based on a determination that the response is received, may reject or grant the request based on the response and clear the record of the request from the data store.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . An apparatus comprising:
a processor; and a memory on which is stored machine-readable instructions that cause the processor to:
output a notification for an authorized entity to evaluate a request for access by an application to a resource, wherein the authorized entity is to evaluate the request asynchronously with submission of the request by the application;
receive an indication from the authorized entity that the request is granted; and
based on a determination that the request is granted,
submit an authorization grant for the application to access the resource to an authorization server that is to respond with an access token that the application is to submit to access the resource; and
forward the access token to the resource to the application.
22 . The apparatus of claim 21 , wherein the instructions cause the processor to:
initiate a timer set to a predefined duration responsive to the output of the notification; and determine whether the response is received prior to expiration of the predefined duration; based on a determination that the response is not received prior to expiration of the predefined duration, output a reminder notification to the authorized entity.
23 . The apparatus of claim 22 , wherein the instructions cause the processor to:
initiate a second timer set to a second predefined duration responsive to the output of the reminder notification; determine whether the response is received prior to expiration of the second predefined duration; and based on a determination that the response is not received prior to expiration of the second predefined duration,
reject the request for access by the application to the resource; and
clear the record of the request from the data store.
24 . The apparatus of claim 21 , wherein the instructions cause the processor to:
send a message to a user of the application regarding whether the user would like to seek approval for the request; and output the notification to the authorized entity based on receipt of an instruction from the user to seek approval for the request.
25 . The apparatus of claim 24 , wherein the instructions cause the processor to:
based on the receipt of the instruction from the user to not seek approval for the request,
reject the request for access by the application to the resource; and
clear a record of the request from a data store.
26 . The apparatus of claim 21 , wherein, to identify the authorized entity, the instructions cause the processor to:
select the authorized entity from a list of authorized entities.
27 . The apparatus of claim 21 , wherein the notification comprises:
a push notification to a device of the authorized entity; an email message to the authorized entity; and/or an entry in a queue of pending requests displayed in a dedicated web portal or a mobile application.
28 . The apparatus of claim 21 , wherein the instructions cause the processor to:
access the request for access by the application to the resource; record the request in a data store; and clear the record of the request from the data store after the access token to the resources has been forwarded to the application.
29 . A method comprising:
outputting, by a processor, a notification for an authorized entity to evaluate a request for access by an application to a resource, wherein the authorized entity is to evaluate the request asynchronously with submission of the request by the application; receiving, by the processor, an indication from the authorized entity that the request is granted; and based on a determination that the request is granted,
submitting, by the processor, an authorization grant for the application to access the resource to an authorization server that is to respond with an access token; and
forwarding, by the processor, the access token to the resource to the application, wherein the application is to submit the access token to a resource server to access the resource.
30 . The method of claim 29 , further comprising:
initiating a timer set to a predefined duration responsive to the output of the notification; determining whether the response is received prior to expiration of the predefined duration; and based on a determination that the response is not received prior to expiration of the predefined duration, outputting a reminder notification to the authorized entity.
31 . The method of claim 30 , further comprising:
initiating a second timer set to a second predefined duration responsive to the output of the reminder notification; determining whether the response is received prior to expiration of the second predefined duration; and based on a determination that the response is not received prior to expiration of the second predefined duration,
rejecting the request for access by the application to the resource; and
clearing a record of the request from a data store.
32 . The method of claim 29 , further comprising:
sending a message to a user of the application regarding whether the user would like to seek approval for the request; and outputting the notification to the authorized entity based on receipt of an instruction from the user to seek approval for the request.
33 . The method of claim 32 , further comprising:
based on receipt of an instruction from the user to not seek approval for the request,
rejecting the request for access by the application to the resource; and
clearing the record of the request from the data store.
34 . The method of claim 29 , further comprising:
identifying the authorized entity by selecting the authorized entity from a list of authorized entities.
35 . The method of claim 29 , wherein the notification comprises:
a push notification to a device of the authorized entity; an email message to the authorized entity; and/or an entry in a queue of pending requests displayed in a dedicated web portal or a mobile application.
36 . The method of claim 29 , further comprising:
accessing the request for access by the application to the resource; recording the accessed request in a data store; and clearing the record of the request from the data store following forwarding of the access token to the resources has been forwarded to the application.
37 . A non-transitory computer-readable medium on which is stored computer-readable instructions that when executed by a processor, cause the processor to:
output a notification to an authorized entity, wherein the authorized entity is to evaluate the request asynchronously with submission by the application of the request and the authorized entity is to return a response as to whether the request is rejected or granted; receive an indication from the authorized entity that the request is granted; and based on a determination that the request is granted,
submit an authorization grant for the application to access the resource to an authorization server that is to respond with an access token; and
forward the access token to the resource to the application, wherein the application is to submit the access token to a resource server to access the resource.
38 . The non-transitory computer-readable medium of claim 37 , wherein the instructions further cause the processor to:
initiate a timer set to a predefined duration responsive to the output of the notification; determine whether the response is received prior to expiration of the predefined duration; and based on a determination that the response is not received prior to expiration of the predefined duration,
output a reminder notification to the authorized entity; or
reject the request.
39 . The non-transitory computer-readable medium of claim 37 , wherein the instructions further cause the processor to:
send a message to a user of the application regarding whether the user would like to seek approval for the request; based on receipt of an instruction from the user to seek approval for the request, output the notification to the authorized entity; and based on receipt of an instruction from the user to not seek approval for the request,
reject the request for access by the application to the resource; and
clear the record of the request from the data store.
40 . The non-transitory computer-readable medium of claim 37 , wherein the instructions further cause the processor to:
access the request for access by the application to the resource; record the request in a data store; and clear the record of the request from the data store after the access token to the resources has been forwarded to the application.Join the waitlist — get patent alerts
Track US2023359750A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.