Authorization identifiers with executable code blocks
Techniques using authorization identifiers with code blocks include one or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors of an authorization server, cause the one or more processors to perform a method including receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier; determining whether the API authorization identifier is valid; and in response to determining that the API authorization identifier is valid: executing a code block in the API authorization identifier; adding an output generated by the execution of the code block to a response to the authorization request; and returning the response to the API server.
1 . One or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors of an authorization server, cause the one or more processors to perform a method comprising:
receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier, the API authorization identifier comprising an authentication identifier and an executable code block separate from the authentication identifier;
determining whether the API authorization identifier is valid based on the authentication identifier; and
in response to determining that the API authorization identifier is valid:
executing the executable code block;
adding an output generated by the execution of the executable code block to a response to the authorization request; and
returning the response to the API server.
2 . The one or more non-transitory computer-readable media of claim 1 , wherein the output generated by the executing of the executable code block includes business data of a client associated with the API authorization identifier.
3 . The one or more non-transitory computer-readable media of claim 1 , wherein executing the executable code block comprises executing the executable code block within a container instance.
4 . The one or more non-transitory computer-readable media of claim 1 , wherein the method further comprises validating the executable code block before executing the executable code block.
5 . The one or more non-transitory computer-readable media of claim 4 , wherein the method further comprises in response to the executable code block failing the validating, adding a code block error to the response to the authorization request.
6 . The one or more non-transitory computer-readable media of claim 4 , wherein validating the executable code block comprises validating a syntax of the executable code block.
7 . The one or more non-transitory computer-readable media of claim 4 , wherein validating the executable code block comprises determining that each function call in the executable code block is included in a white list of permitted function calls.
8 . The one or more non-transitory computer-readable media of claim 4 , wherein validating the executable code block comprises determining whether a client associated with the API authorization identifier has exceeded a quota of a number of executable code blocks that can be executed over a time period.
9 . The one or more non-transitory computer-readable media of claim 1 , wherein the method further comprises in response to the API authorization identifier failing the validating, returning an error to the API server.
10 . The one or more non-transitory computer-readable media of claim 1 , wherein the API authorization identifier is provided by a client requesting access to a service provided by the API server.
11 . The one or more non-transitory computer-readable media of claim 1 , wherein the output generated by the executing of the executable code block is added to a response returned to a client that provided the API authorization identifier.
12 . The one or more non-transitory computer-readable media of claim 1 , wherein the authentication identifier is a key, a token, or a certificate.
13 . A computer-implemented method of processing an authorization request, the computer-implemented method comprising:
receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier, the API authorization identifier comprising an authentication identifier and an executable code block separate from the authentication identifier;
determining whether the API authorization identifier is valid based on the authentication identifier; and
in response to determining that the API authorization identifier is valid:
executing the executable code block in the API authorization identifier;
adding an output generated by the execution of the executable code block to a response to the authorization request; and
returning the response to the API server.
14 . The computer-implemented method of claim 13 , wherein the output generated by the executing of the executable code block includes business data of a client associated with the API authorization identifier.
15 . The computer-implemented method of claim 13 , wherein executing the executable code block comprises executing the executable code block within a container instance.
16 . The computer-implemented method of claim 13 , further comprising validating the executable code block before executing the executable code block.
17 . The computer-implemented method of claim 16 , further comprising in response to the executable code block failing the validating, adding a code block error to the response to the authorization request.
18 . The computer-implemented method of claim 16 , wherein validating the executable code block comprises validating a syntax of the executable code block.
19 . The computer-implemented method of claim 16 , wherein validating the executable code block comprises determining that each function call in the executable code block is included in a white list of permitted function calls.
20 . The computer-implemented method of claim 16 , wherein validating the executable code block comprises determining whether a client associated with the API authorization identifier has exceeded a quota of a number of code blocks that can be executed over a time period.
21 . The computer-implemented method of claim 13 , further comprising in response to the API authorization identifier failing the validating, returning an error to the API server.
22 . The computer-implemented method of claim 13 , wherein the API authorization identifier is provided by a client requesting access to a service provided by the API server.
23 . The computer-implemented method of claim 13 , wherein the output generated by the executing of the executable code block is added to a response returned to a client that provided the API authorization identifier.
24 . The method of claim 13 , wherein the authentication identifier is a key, a token, or a certificate.
25 . A system comprising:
a memory storing instructions; and
one or more processors coupled to the memory and, when executing the instructions, are configured to perform operations comprising:
receiving, from an application programming interface (API) server, an authorization request, the authorization request including an API authorization identifier, the API authorization identifier comprising an authentication identifier and an executable code block separate from the authentication identifier;
determining whether the API authorization identifier is valid based on the authentication identifier; and
in response to determining that the API authorization identifier is valid:
executing the executable code block in the API authorization identifier;
adding an output generated by the execution of the executable code block to a response to the authorization request; and
returning the response to the API server.
26 . The system of claim 25 , wherein the output generated by the executing of the executable code block includes business data of a client associated with the API authorization identifier.
27 . The system of claim 25 , wherein executing the executable code block comprises executing the executable code block within a container instance.
28 . The system of claim 25 , wherein the operations further comprise validating the executable code block before executing the executable code block.
29 . The system of claim 28 , wherein the operations further comprise in response to the executable code block failing the validating, adding a code block error to the response to the authorization request.
30 . The system of claim 28 , wherein validating the executable code block comprises validating a syntax of the executable code block.
31 . The system of claim 28 , wherein validating the executable code block comprises determining that each function call in the executable code block is included in a white list of permitted function calls.
32 . The system of claim 28 , wherein validating the executable code block comprises determining whether a client associated with the API authorization identifier has exceeded a quota of a number of code blocks that can be executed over a time period.
33 . The system of claim 25 , wherein the operations further comprise in response to the API authorization identifier failing the validating, returning an error to the API server.
34 . The system of claim 25 , wherein the API authorization identifier is provided by a client requesting access to a service provided by the API server.
35 . The system of claim 25 , wherein the output generated by the executing of the executable code block is added to a response returned to a client that provided the API authorization identifier.
36 . The system of claim 25 , wherein the authentication identifier is a key, a token, or a certificate.