IP Library Granted Patent US 11,924,207
Granted Patent B2
US 11,924,207 · App. 16/588,466 · Granted Mar 5, 2024

Inter-application management of user credential data

Inventors: John Simone (San Francisco, CA); Fiaz Hossain (San Francisco, CA)
Assignee: Salesforce, Inc.
H04L63/10G06F8/20G06F16/951G06F21/41H04L63/08H04L67/01H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,207
App. No.
16/588,466
Granted
Mar 5, 2024
Kind
B2
Abstract

A system and apparatus for enhancing the functionality and utility of an authentication process for web applications is disclosed.

Claims (25)

1. A computer-implemented method for providing user authorizations utilizing a set of authorization application program interfaces (APIs), the method comprising:

providing an SDK for a client web application which performs user authorizations for multiple resources within an on-demand services environment, wherein the SDK comprises the set of authorization APIs, and wherein the set of authorization APIs is configured to:

utilize a server-side storage for storing developer-defined user information;

performing user authorizations with the set of authorization APIs developed by the SDK, wherein the performing the user authorizations with the set of authorization APIs is through a client web application executed by a hardware computing device to allow access to the multiple resources within the on-demand database services environment without needing to switch between the multiple resources, by creating a custom object that utilizes the developer-defined user information and comprises a mashup of select customized user data extracted from multiple web applications; and

providing, based on the user authorizations and with one or more computing devices, the multiple resources with access to an access token without the use of cookies through a shared session cache memory.

2. The method of claim 1 , wherein the security framework comprises a plurality of generic servlet filters and spring security filters.

3. The method of claim 2 , wherein the generic servlet filters perform OAuth flow and routes the user to a login page.

4. The method of claim 2 , wherein the generic servlet filters are used within servlet-based web applications that operate without using any specific security framework.

5. The method of claim 2 , further comprising:

operating at least one of the generic servlet filters to:

find a cookie or session containing the user's SecurityContext so that the user is recognized;

not find a cookie or session containing the user's SecurityContext, and sending the user to an authorization Uniform Resource Location (URL) to begin an OAuth handshake; or

send a token request to obtain a Session ID, API endpoint, and authentication (refresh) token.

6. The method of claim 1 , further comprising:

facilitating a choice between storing user data in browser cookies or server side sessions so that application instances are completely stateless.

7. The method of claim 1 , further comprising:

during a server side session, using a shared session cache, wherein each of a plurality of servers is configured to write to a specific session cache.

8. The method of claim 1 , wherein the developer-defined user information consists of frequently looked-up data.

9. A multi-tenant database system, comprising:

a processor; and

memory, the memory storing instructions to cause the processor to execute a method, the method comprising:

providing an SDK for a client web application which performs user authorizations for multiple resources within an on-demand services environment, wherein the SDK comprises the set of authorization APIs, and wherein the set of authorization APIs is configured to:

utilize a server-side storage for storing developer-defined user information;

performing user authorizations with the set of authorization APIs developed by the SDK, wherein the performing the user authorizations with the set of authorization APIs is through a client web application executed by a hardware computing device to allow access to the multiple resources within the on-demand database services environment without needing to switch between the multiple resources, by creating a custom object that utilizes the developer-defined user information and comprises a mashup of select customized user data extracted from multiple web applications; and

providing, based on the user authorizations and with one or more computing devices, the multiple resources with access to an access token without the use of cookies through a shared session cache memory.

Assignments (2)
CHANGE OF NAME Recorded Dec 18, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069717/0444 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2020
From: SIMONE, JOHN; HOSSAIN, FIAZ
To: SALESFORCE.COM, INC.
Reel/Frame 053710/0982 →
Continuity (5)
Continuation 16042983 · Jul 23, 2018
Continuation 15197728 · Jun 29, 2016
Continuation 13178511 · Jul 8, 2011
Provisional Application 61474538 · Apr 12, 2011
Related Publication 20200204552A1 · Jun 25, 2020