IP Library › Granted Patent US 10,079,905
Granted Patent B2
US 10,079,905 · App. 15/344,345 · Granted Sep 18, 2018

Cross domain in-browser proxy

Inventors: Alex Toussaint (San Francisco, CA); Chris Jolley (Lone Tree, CO); Jay Hurst (San Francisco, CA); Stephen L. Pepper (Highlands Ranch, CO); Kari L. Hotchkiss (Denver, CO); Saptarshi Roy (South San Francisco, CA)
Assignee: salesforce.com, inc.
H04L67/2814H04L67/02H04L67/42G06F17/30861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,079,905
App. No.
15/344,345
Granted
Sep 18, 2018
Kind
B2
Abstract

An in-browser proxy enables an application in a frame to make a cross domain request. The proxy executes within the browser, which has a first domain. The browser provides a frame in which a client application executes, which has a second domain. The request from the client application is a request for data access to the external domain. The proxy identifies a registration of the client application, and forwards the request to the external domain. The proxy receives a response to the request and provides the response back to the client application within the frame.

Claims (82)

1. A method performed by a system having at least a processor and a memory therein, wherein the method comprises:

executing a browser at the system, wherein the system and the browser operates within a first domain;

hosting an interface to a remote application within the browser executing at the system, the remote application executing within a second domain associated with an on-demand host server remote from the system;

executing a proxy within the browser, the proxy being associated with both the first and the second domains;

receiving, at the proxy executing within the browser, a request from the remote application executing within the second domain, the request seeking access to data or resources of the system operating within the first domain and outside of the second domain of the remote application associated with the on-demand host server;

wherein the remote application includes configured access to components hosted by the on-demand host server and which are accessible via the remote application executing within the second domain directly from within its domain and further wherein the application includes configured access to components hosted by the system operating within the first domain, wherein access to the components hosted by the system in the first domain are accessible to the remote application executing within the second domain through the proxy executing within the browser; and

providing a response to the request based on successful access to the data or resources of the system operating within the first domain by the remote application executing within the second domain.

2. The method of claim 1 :

wherein the request comprises a request by the remote application for data or resources hosted by the system in the first domain, external from the second domain within which the remote application operates;

wherein the new request comprises a new request for the data or resources hosted by the system in the first domain, the new request being generated within the first domain;

wherein the response to the new request comprises a response providing the data or resources hosted by the system in the first domain as requested by the new request; and

wherein providing the response to the application comprises providing the data or resources hosted by the system in the first domain to the application executing within the second domain associated with the on-demand host server.

3. The method of claim 1 :

wherein the interface to the remote application executes within a client frame of the browser;

wherein the proxy comprises a cross domain proxy for requests outside of the first domain within which the browser executes;

wherein the interface to the remote application includes addresses of services and/or processes to execute via the remote application executing at the second domain; and

wherein the application further comprises configured access to the cross domain proxy executing via the browser.

4. The method of claim 1 :

wherein the interface to the remote application executes within a client frame of the browser with configured access to components hosted by a parent server operating within the second domain and associated with the on-demand host server remote from the system through the proxy executing within the browser;

wherein the method further comprises identifying a registration of the remote application with the proxy by a parent frame to the client frame registering for asynchronous requests originating at the client frame from the interface executing within the client frame, wherein the registering includes the parent frame providing an identifier or handle to the client frame, with the identifier or handle to be monitored by the client frame and stored by the client frame; and

wherein the interface executing at the system accesses components hosted by the parent server by first determining that requested services associated with the components are outside of its domain and then making a request, via the proxy, requesting the proxy to access the second domain within which the components reside on behalf of the interface.

5. The method of claim 1 :

wherein the request comprises an XML (extensible markup language) HTTP (hypertext transport protocol) request (XHR).

6. The method of claim 4 , wherein identifying the registration of the remote application further comprises checking authentication information for the remote application, and authorizing the remote application in the external domain in accordance with the authentication of the remote application with the proxy.

7. The method of claim 1 , wherein the interface executing within the browser of the system interacts with a primary page of the second domain and generates a request to execute the remote application;

wherein the on-demand host server responsively provides application code for the remote application which is installed by the browser within a hosted space for the system under the second domain; and

wherein the system then executes the remote application under the second domain and references the hosted space back to a frame within the browser executing at the first domain.

8. Non-transitory computer readable storage media having instructions stored thereupon that, when executed by a processor of a system, the instructions cause the system to perform operations including:

executing a browser at the system, wherein the system and the browser operates within a first domain;

hosting an interface to a remote application within the browser executing at the system, the remote application executing within a second domain associated with an on-demand host server remote from the system;

executing a proxy within the browser, the proxy being associated with both the first and the second domains;

receiving, at the proxy executing within the browser, a request from the remote application executing within the second domain, the request seeking access to data or resources of the system operating within the first domain and outside of the second domain of the remote application associated with the on-demand host server;

wherein the remote application includes configured access to components hosted by the on-demand host server and which are accessible via the remote application executing within the second domain directly from within its domain and further wherein the application includes configured access to components hosted by the system operating within the first domain, wherein access to the components hosted by the system in the first domain are accessible to the remote application executing within the second domain through the proxy executing within the browser; and

providing a response to the request based on successful access to the data or resources of the system operating within the first domain by the remote application executing within the second domain.

9. The non-transitory computer readable storage media of claim 8 :

wherein the request comprises a request by the remote application for data or resources hosted by the system in the first domain, external from the second domain within which the remote application operates;

wherein the new request comprises a new request for the data or resources hosted by the system in the first domain, the new request being generated within the first domain;

wherein the response to the new request comprises a response providing the data or resources hosted by the system in the first domain as requested by the new request; and

wherein providing the response to the application comprises providing the data or resources hosted by the system in the first domain to the application executing within the second domain associated with the on-demand host server.

10. The non-transitory computer readable storage media of claim 8 :

wherein the interface to the remote application executes within a client frame of the browser;

wherein the proxy comprises a cross domain proxy for requests outside of the first domain within which the browser executes;

wherein the interface to the remote application includes addresses of services and/or processes to execute via the remote application executing at the second domain; and

wherein the application further comprises configured access to the cross domain proxy executing via the browser.

11. The non-transitory computer readable storage media of claim 8 :

wherein the interface to the remote application executes within a client frame of the browser with configured access to components hosted by a parent server operating within the second domain and associated with the on-demand host server remote from the system through the proxy executing within the browser;

wherein the method further comprises identifying a registration of the remote application with the proxy by a parent frame to the client frame registering for asynchronous requests originating at the client frame from the interface executing within the client frame, wherein the registering includes the parent frame providing an identifier or handle to the client frame, with the identifier or handle to be monitored by the client frame and stored by the client frame; and

wherein the interface executing at the system accesses components hosted by the parent server by first determining that requested services associated with the components are outside of its domain and then making a request, via the proxy, requesting the proxy to access the second domain within which the components reside on behalf of the interface.

12. The non-transitory computer readable storage media of claim 11 , wherein identifying the registration of the remote application further comprises checking authentication information for the remote application, and authorizing the remote application in the external domain in accordance with the authentication of the remote application with the proxy.

13. The non-transitory computer readable storage media of claim 8 :

wherein the request comprises an XML (extensible markup language) HTTP (hypertext transport protocol) request (XHR).

14. The non-transitory computer readable storage media of claim 11 :

wherein the interface executing within the browser of the system interacts with a primary page of the second domain and generates a request to execute the remote application;

wherein the on-demand host server responsively provides application code for the remote application which is installed by the browser within a hosted space for the system under the second domain; and

wherein the system then executes the remote application under the second domain and references the hosted space back to a frame within the browser executing at the first domain.

15. A system comprising:

a processor;

a memory to perform instructions;

the processor of the system to execute a browser;

network interface hardware to connect the system with a first domain, wherein the system and the browser operate within the first domain;

the browser to host an interface to a remote application, the remote application executing within a second domain associated with an on-demand host server remote from the system;

the processor of the system to execute a proxy within the browser, the proxy being associated with both the first and the second domains;

the proxy to receive a request from the remote application executing within the second domain, the request seeking access to data or resources of the system operating within the first domain and outside of the second domain of the remote application associated with the on-demand host server;

wherein the remote application includes configured access to components hosted by the on-demand host server and which are accessible via the remote application executing within the second domain directly from within its domain and further wherein the application includes configured access to components hosted by the system operating within the first domain, wherein access to the components hosted by the system in the first domain are accessible to the remote application executing within the second domain through the proxy executing within the browser; and

the proxy to provide a response to the request based on successful access to the data or resources of the system operating within the first domain by the remote application executing within the second domain.

16. The system of claim 15 :

wherein the request comprises a request by the remote application for data or resources hosted by the system in the first domain, external from the second domain within which the remote application operates;

wherein the new request comprises a new request for the data or resources hosted by the system in the first domain, the new request being generated within the first domain;

wherein the response to the new request comprises a response providing the data or resources hosted by the system in the first domain as requested by the new request; and

wherein providing the response to the application comprises providing the data or resources hosted by the system in the first domain to the application executing within the second domain associated with the on-demand host server.

17. The system of claim 15 :

wherein the interface to the remote application executes within a client frame of the browser;

wherein the proxy comprises a cross domain proxy for requests outside of the first domain within which the browser executes;

wherein the interface to the remote application includes addresses of services and/or processes to execute via the remote application executing at the second domain; and

wherein the application further comprises configured access to the cross domain proxy executing via the browser.

18. The system of claim 15 :

wherein the interface to the remote application executes within a client frame of the browser with configured access to components hosted by a parent server operating within the second domain and associated with the on-demand host server remote from the system through the proxy executing within the browser;

wherein the proxy is to further identify a registration of the remote application with the proxy in which a parent frame to the client frame registers for asynchronous requests originating at the client frame from the interface executing within the client frame, wherein the registration includes the parent frame providing an identifier or handle to the client frame, with the identifier or handle to be monitored by the client frame and stored by the client frame; and

wherein the interface executing at the system is to access components hosted by the parent server by first determining that requested services associated with the components are outside of its domain and then making a request, via the proxy, the request to instruct the proxy to access the second domain within which the components reside on behalf of the interface.

19. The system of claim 18 , wherein identification of the registration of the remote application further comprises a check of authentication information for the remote application, and an authorization of the remote application in the external domain in accordance with the authentication of the remote application with the proxy.

20. The system of claim 15 :

wherein the request comprises an XML (extensible markup language) HTTP (hypertext transport protocol) request (XHR).

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2016
From: TOUSSAINT, ALEX; JOLLEY, CHRISTOPHER; HURST, JAY; PEPPER, STEPHEN L.; HOTCHKISS, KARI L.; ROY, SAPTARSHI
To: SALESFORCE.COM, INC.
Reel/Frame 040331/0157 →
Continuity (3)
Continuation 14025400 · Sep 12, 2013
Provisional Application 61702020 · Sep 17, 2012
Related Publication 20170078429A1 · Mar 16, 2017