ACCOUNT AUTHORIZATION MAPPING
Methods and systems for account authorization mapping are described. An application server may transmit one or more authorization requests to one or more authorization entities associated with one or more applications. The application server may receive one or more access tokens associated with the one or more applications and may store one or more indications of authorization. The application server may further associate, at the authorization management entity, the one or more indications of authorization.
1 . A method for user authentication at an application server, comprising:
transmitting, from an authorization management entity to a first authorization entity associated with a first application, a first authorization request based at least in part on a state parameter that identifies a user;
receiving, at the authorization management entity and from the first authorization entity, a first access token associated with the first application;
storing, at the authorization management entity, a first indication of authorization associated with the user and the first application based at least in part on receiving the first access token;
transmitting, from the authorization management entity to a second authorization entity associated with a second application, a second authorization request based at least in part on the state parameter;
receiving, at the authorization management entity and from the second authorization entity, a second access token associated with the first application;
storing, at the authorization management entity, a second indication of authorization associated with the user and the second application based at least in part on receiving the second access token; and
associating, at the authorization management entity, the first indication of authorization and the second indication of authorization.
2 . The method of claim 1 , wherein:
transmitting the first authorization request is based at least in part on a first identity token associated with the first authorization request; and
transmitting the second authorization request is based at least in part on a second identity token associated with the second authorization request.
3 . The method of claim 2 , further comprising:
verifying the first identity token, wherein transmitting the second authorization request is based at least in part on verifying the first identity token.
4 . The method of claim 1 , further comprising:
receiving, from a user, an authorization association request for the first application and the second application.
5 . The method of claim 1 , further comprising:
receiving, at the authorization management entity and from the first application, the state parameter, wherein the state parameter is associated with a user account associated with the first application.
6 . The method of claim 1 , further comprising:
creating a user account associated with the first application, wherein the state parameter is based at least in part on creating the user account associated with the first application.
7 . An apparatus for user authentication at an application server, comprising:
a processor;
memory coupled with the processor; and
instructions stored in the memory and executable by the processor to cause the apparatus to:
transmit, from an authorization management entity to a first authorization entity associated with a first application, a first authorization request based at least in part on a state parameter that identifies a user;
receive, at the authorization management entity and from the first authorization entity, a first access token associated with the first application;
store, at the authorization management entity, a first indication of authorization associated with the user and the first application based at least in part on receiving the first access token;
transmit, from the authorization management entity to a second authorization entity associated with a second application, a second authorization request based at least in part on the state parameter;
receive, at the authorization management entity and from the second authorization entity, a second access token associated with the first application;
store, at the authorization management entity, a second indication of authorization associated with the user and the second application based at least in part on receiving the second access token; and
associate, at the authorization management entity, the first indication of authorization and the second indication of authorization.
8 . The apparatus of claim 7 , wherein:
transmitting the first authorization request is based at least in part on a first identity token associated with the first authorization request; and
transmitting the second authorization request is based at least in part on a second identity token associated with the second authorization request.
9 . The apparatus of claim 8 , wherein the instructions are further executable by the processor to cause the apparatus to:
verify the first identity token, wherein transmitting the second authorization request is based at least in part on verifying the first identity token.
10 . The apparatus of claim 7 , wherein the instructions are further executable by the processor to cause the apparatus to:
receive, from a user, an authorization association request for the first application and the second application.
11 . The apparatus of claim 7 , wherein the instructions are further executable by the processor to cause the apparatus to:
receive, at the authorization management entity and from the first application, the state parameter, wherein the state parameter is associated with a user account associated with the first application.
12 . The apparatus of claim 7 , wherein the instructions are further executable by the processor to cause the apparatus to:
create a user account associated with the first application, wherein the state parameter is based at least in part on creating the user account associated with the first application.
13 . A non-transitory computer-readable medium storing code for user authentication at an application server, the code comprising instructions executable by a processor to:
transmit, from an authorization management entity to a first authorization entity associated with a first application, a first authorization request based at least in part on a state parameter that identifies a user;
receive, at the authorization management entity and from the first authorization entity, a first access token associated with the first application;
store, at the authorization management entity, a first indication of authorization associated with the user and the first application based at least in part on receiving the first access token;
transmit, from the authorization management entity to a second authorization entity associated with a second application, a second authorization request based at least in part on the state parameter;
receive, at the authorization management entity and from the second authorization entity, a second access token associated with the first application;
store, at the authorization management entity, a second indication of authorization associated with the user and the second application based at least in part on receiving the second access token; and
associate, at the authorization management entity, the first indication of authorization and the second indication of authorization.
14 . The non-transitory computer-readable medium of claim 13 , wherein:
transmitting the first authorization request is based at least in part on a first identity token associated with the first authorization request; and
transmitting the second authorization request is based at least in part on a second identity token associated with the second authorization request.
15 . The non-transitory computer-readable medium of claim 14 , wherein the instructions are further executable by the processor to:
verify the first identity token, wherein transmitting the second authorization request is based at least in part on verifying the first identity token.
16 . The non-transitory computer-readable medium of claim 13 , wherein the instructions are further executable by the processor to:
receive, from a user, an authorization association request for the first application and the second application.
17 . The non-transitory computer-readable medium of claim 13 , wherein the instructions are further executable by the processor to:
receive, at the authorization management entity and from the first application, the state parameter, wherein the state parameter is associated with a user account associated with the first application.
18 . The non-transitory computer-readable medium of claim 13 , wherein the instructions are further executable by the processor to:
create a user account associated with the first application, wherein the state parameter is based at least in part on creating the user account associated with the first application.