发明名称 Secure framework for invoking server-side APIs using AJAX
摘要 Techniques for securely invoking a server-side API from client-side Web application code using AJAX. In one set of embodiments, a request to invoke a server-side API is received from a client-side component of a Web application, where the request is sent asynchronously using AJAX. One or more security handlers are then invoked to process the request in a manner that mitigates various security attacks. In one embodiment, a security handler is invoked to defend against a plurality of different types of Web application/AJAX security attacks. In another embodiment, authentication and authorization security handlers are invoked to authenticate a user of the Web application that originated the request and determine whether the user is authorized to call the server-side API. In yet another embodiment, configuration is implemented at the data storage tier to enforce user-access and data security on data that is retrieved/stored as a result of invoking the server-side API.
申请公布号 US8332654(B2) 申请公布日期 2012.12.11
申请号 US20080330008 申请日期 2008.12.08
申请人 ANBUSELVAN ANANTHALAKSHMI;ORACLE INTERNATIONAL CORPORATION 发明人 ANBUSELVAN ANANTHALAKSHMI
分类号 G06F11/30;G06F9/44 主分类号 G06F11/30
代理机构 代理人
主权项
地址