User management notification method and device for graph database document site
By configuring the target notification group name collection and event listening mechanism in the graph database document site, we will automatically send permission change notification emails to users, which solves the problem of untimely notification of permission change notifications and improves user experience and system efficiency.
Patent Information
- Application Number
- CN202510829419.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-20
AI Technical Summary
In the prior art, the user permission change notification of the graph database document site is not promptly and the administrator has heavy burdens, resulting in users not being able to understand the permission changes in time, affecting work efficiency and system reliability.
By preconfiguring the target notification group name collection in the identity access management service, using the event listening mechanism to capture administrator events, identify the association creation events of users joining the user group, and automatically send the user permission change notification email, including the user name and the added target notification group name.
It realizes timely and accurate communication of permission change notifications, reduces the burden on administrators, improves user experience and system efficiency, and ensures data security.
Smart Images

Figure CN120337190A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of graph databases, and particularly to a user management notification method and device for a graph database document site. Background Art
[0002] In order to achieve efficient and secure user authentication and permission management, a graph database document site is usually integrated with mature identity authentication and access management (IAM) technologies such as Keycloak. Keycloak is an open-source IAM platform that provides powerful user management, authentication, and authorization functions. When a user accesses a graph database document site, they need to log in and register through Keycloak. This integration method not only improves development efficiency but also ensures the security and reliability of user authentication.
[0003] However, although the integration of the graph database document site with Keycloak provides many conveniences in user authentication and permission management, there are significant deficiencies in user permission notifications.
[0004] When an administrator assigns or modifies permissions for a user, the user often cannot be informed in a timely manner that their permissions have changed. This information asymmetry causes the user not to attempt to access certain resources when they need to, because they do not know that they already have the corresponding permissions. This not only affects the user's work efficiency but also may cause the user to doubt the usability and reliability of the system. For example, a newly joined employee may still not know that they have new access permissions after obtaining them, so they will not attempt to access the relevant resources.
[0005] In addition, the administrator needs to manually notify the user of the permission changes, which not only increases the administrator's workload but also easily leads to omissions or errors, further exacerbating the information asymmetry problem between the user and the administrator. For example, the administrator may forget to notify some users of the permission updates, or there may be information errors during the notification process, resulting in the user not being able to correctly understand their permission scope. This manual notification method is not only inefficient but also prone to human errors, affecting the overall management efficiency of the system. Summary of the Invention
[0006] The purpose of the present invention is to provide a user management notification method and device for a graph database document site to solve the problems of untimely permission change notifications and heavy administrator burden when the user permissions of the database document site are modified in the prior art.
[0007] To achieve the above object, the present application adopts the following technical solutions:
[0008] A user management notification method for a graph database document site of the present application includes the following steps:
[0009] Obtain a set of pre-configured target notification group names in the identity access management service, where the target notification groups are associated with the access rights of the graph database document site;
[0010] Capture administrator events through the event listening mechanism of the identity access management service, and identify whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event;
[0011] In response to identifying the associated creation event, parse the event data, extract the group identifier of the operated user group and the user identifier of the added user, and query the group attribute information according to the group identifier to obtain the group name;
[0012] If the obtained group name belongs to the set of target notification group names, query the user attribute information according to the user identifier to obtain the user name and user contact information;
[0013] Construct a notification message including the user name and the name of the target notification group he / she joined, and send the notification message to the user through the user contact information.
[0014] Preferably, the obtaining of the set of pre-configured target notification group names in the identity access management service includes:
[0015] Initialize a static and immutable empty set to store the target notification group names;
[0016] Read the notification group configuration parameters in the environment variables of the identity access management service;
[0017] If the configuration parameter is a non-empty value, extract all the target notification group names with commas as separators, and add all the target notification group names to the set;
[0018] When the environment variable is not set or is empty, record a warning log and skip the initialization.
[0019] Preferably, the identifying whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event includes:
[0020] Extract the operation type and resource type from the event object;
[0021] When the operation type is a creation operation and the resource type is a user group membership relationship, determine that the current event is an associated creation event of adding a user to a user group.
[0022] Preferably, the parsing of the event data, extracting the group identifier of the operated user group and the user identifier of the added user, and querying the group attribute information according to the group identifier to obtain the group name includes:
[0023] Extract the resource path from the event and verify whether the resource path conforms to a preset format;
[0024] If it conforms, split the path string according to the path hierarchy structure to obtain the group identifier of the operated user group and the user identifier of the added user;
[0025] Obtain the group model object according to the group identifier, and extract the name attribute value from the group model object to obtain the group name.
[0026] Preferably, the querying of the user attribute information according to the user identifier to obtain the user name and the user contact information includes:
[0027] Obtain the user model according to the user identifier, and extract the user name field and the email address field from the user model object to obtain the user name and the email address.
[0028] Preferably, the constructing of the notification message including the user name and the name of the target notification group joined by the user, and sending the notification message to the user through the user contact information includes:
[0029] Construct the email content in a structured text format, dynamically embed the user name and the list of the names of the target notification groups joined by the user, and the list includes at least one target notification group name;
[0030] Package the email subject, the email address and the email content to generate a notification email;
[0031] Call the email service built in the identity access management service to send the notification email to the user mailbox.
[0032] Preferably, the method further includes:
[0033] Set up a timed task scheduler to poll the event cache queue of adding users to user groups at fixed time intervals;
[0034] When preset conditions are met, trigger the scheduler shutdown process;
[0035] Execute a pre-shutdown check to determine whether the scheduler has been initialized and is in a running state;
[0036] If both are satisfied, initiate a shutdown request and set a maximum waiting time;
[0037] If the task is not completed after the timeout, forcibly terminate the scheduler process.
[0038] A user management notification device for a graph database document site, comprising:
[0039] An acquisition module, configured to acquire a set of target notification group names pre-configured in an identity access management service, where the target notification groups are associated with access permissions to the graph database document site;
[0040] An identification module, configured to capture an administrator event through an event listening mechanism of the identity access management service, and identify whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event;
[0041] A response module, configured to, in response to identifying the associated creation event, parse event data, extract the group identifier of the user group being operated on and the user identifier of the user being added, and query group attribute information according to the group identifier to obtain the group name;
[0042] A query module, configured to, if the obtained group name belongs to the set of target notification group names, query user attribute information according to the user identifier to obtain the user name and user contact information;
[0043] A notification module, configured to construct a notification message including the user name and the name of the target notification group to which the user is added, and send the notification message to the user through the user contact information.
[0044] An electronic device, comprising a memory and a processor, where the memory is used to store one or more computer instructions, and wherein the one or more computer instructions are executed by the processor to implement a user management notification method for a graph database document site as described in any one of the above.
[0045] A computer-readable storage medium storing a computer program, where the computer program, when executed by a computer, implements a user management notification method for a graph database document site as described in any one of the above.
[0046] The present invention has the following beneficial effects:
[0047] The present invention can automatically send a permission change notification to a user when an administrator assigns or modifies permissions for the user, which not only improves the user experience, but also reduces the workload of the administrator, ensures the efficient operation of the system and the security of data. In particular, through the integration with Keycloak, it ensures that the permission notification can be conveyed to the user in a timely and accurate manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0049] Figure 1 It is a flowchart of a user management notification method for a graph database document site provided by an embodiment of the present application;
[0050] Figure 2 It is a full flowchart from enabling the authentication connection to the administrator changing the user's access permission to notifying the user of the access permission change;
[0051] Figure 3 It is a schematic structural diagram of a user management notification device for a graph database document site provided by an embodiment of the present application;
[0052] Figure 4 It is a schematic diagram of an electronic device for implementing a user management notification method for a graph database document site provided by an embodiment of the present application. Detailed implementation manners
[0053] To make the technical solutions of the present application clearer, the following will further describe the present invention in detail with reference to the accompanying drawings and specific embodiments. The terms "first", "second", etc. in the claims and the description of the present application are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances. This is only a way of distinguishing objects with the same attributes when describing the embodiments of the present application. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units that are not clearly listed or are inherent to these processes, methods, products or devices.
[0054] Embodiment 1
[0055] As Figure 1 shown, a user management notification method for a graph database document site includes the following steps:
[0056] S110. Obtain a set of target notification group names pre-configured in the identity access management service, where the target notification group is associated with the access permission of the graph database document site;
[0057] S120. Capture the administrator event through the event listening mechanism of the identity access management service, and identify whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event;
[0058] S130. In response to identifying it as an associated creation event, parse the event data, extract the group identifier of the operated user group and the user identifier of the added user, and query the group attribute information according to the group identifier to obtain the group name;
[0059] S140. If the obtained group name belongs to the target notification group name set, query the user attribute information according to the user identifier to obtain the user name and user contact information;
[0060] S150. Construct a notification message including the user name and the target notification group name he / she joined, and send the notification message to the user through the user contact information.
[0061] In this embodiment, the identity access management service adopts Keycloak, and the access request of the external user to the graph database document site is redirected to Keycloak through the reverse proxy layer for unified authentication.
[0062] Specifically, when implementing, use the Nginx server as the reverse proxy of the graph database document site, integrate the Oauth2 Proxy container in the Nginx server, and establish an authentication connection with Keycloak. Among them, the reverse proxy configuration, Oauth2Proxy container integration and Keycloak linkage method refer to the technical solutions disclosed in the Chinese patent application for invention with the application publication number CN120090882A and the invention name "A method for implementing user authentication and DingTalk notification of a graph database document site".
[0063] After the entire architecture is built, this embodiment will use the configuration parameter of the target notification group name to specify in Keycloak the group name, i.e., the target notification group name, to which a notification needs to be sent to the corresponding user when an administrator adds a user to a user group. This configuration parameter can specify multiple target notification groups at the same time, and the names of each target notification group are separated by commas. For example, KEYCLOAK_NOTIFIED_GROUPS=doc-viewer,admin, which means that two groups, doc-viewer and admin, are configured to receive Keycloak notifications. In Keycloak, a group is a collection of users, which can be used to simplify user management and permission allocation. A user can belong to multiple groups and inherit the attributes and role mappings of the group. In this embodiment, the target notification group is associated with the access permission of the graph database document site. For example, users in this target notification group can view and browse the content on the document site but cannot make any modifications, or users in this target notification group can not only view the documents but also modify, update or delete the documents. The administrator has the highest level of access rights and can manage user roles, allocate permissions, backup and restore data, etc.
[0064] Before performing the judgment operation of whether to send a notification to a user, it is necessary to first obtain the set of target notification group names configured in Keycloak to match the user group name that the user joins.
[0065] In some embodiments, obtaining the set of target notification group names pre-configured in the identity access management service includes:
[0066] Initialize a static and immutable empty set to store the target notification group names;
[0067] Read the notification group configuration parameter in the identity access management service environment variable;
[0068] If the configuration parameter is a non-empty value, extract all the target notification group names with a comma as the delimiter and add all the target notification group names to the set;
[0069] When the environment variable is not set or is empty, record a warning log and skip the initialization.
[0070] Specifically, first define a static and immutable empty Set collection NOTIFIED_GROUPS to store the group names that need to trigger notifications, i.e., the target notification group names. Among them, Set is a data structure used to store non-repeating elements. At the same time, in this embodiment, the notification method is email, the email information is the smtp email information configured in the Keycloak realm public, and the email address is the user email address configured in the corresponding user model.
[0071] In the constructor of the GroupJoinListenerProvider class, receive a KeycloakSession instance and assign it to the session property of the current class. Then, use the synchronized keyword to lock the GroupJoinListenerProvider class to ensure that only one thread can execute the initialization code block in a multi-threaded environment, avoiding repeated initialization. Inside the synchronized code block, check the static boolean variable initialized (declared elsewhere in the class to mark whether initialization has been performed). If it has not been initialized, i.e., initialized is false, then execute the initialization logic.
[0072] The initialization logic includes:
[0073] a. Read the value of KEYCLOAK_NOTIFIED_GROUPS from the system environment variables, and its value is the target notification group name;
[0074] b. If this environment variable exists and is not empty, split it by commas to obtain all the target notification group names, and add each split target notification group name to the NOTIFIED_GROUPS set to obtain the target notification group name set, and record a log showing the initialized target notification group names;
[0075] c. If the environment variable does not exist or is empty, record a warning log and prompt that the target notification group is not configured;
[0076] d. Record a log indicating that the GroupJoinListenerProvider has been initialized;
[0077] e. Set the initialized flag to true so that the GroupJoinListenerProvider instance will not be re-initialized the next time it is created.
[0078] It is also necessary to register an event listener in Keycloak. This event listener is used to capture administrator events, which is prior art and will not be elaborated here.
[0079] When the event listener captures an administrator event, it is necessary to determine whether the current event is an associated creation event for adding a user to a user group based on the operation type and resource type included in the event.
[0080] In some embodiments, identifying whether the current event is an associated creation event for adding a user to a user group based on the operation type and resource type in the event includes:
[0081] Extract the operation type and resource type from the event object;
[0082] When the operation type is a create operation and the resource type is a user group membership, determine that the current event is an associated create event for adding a user to a user group.
[0083] Specifically, determine whether the operation type of the event is CREATE and whether its resource type is GROUP_MEMBERSHIP. If both conditions are met, determine that the event is an associated create event for an administrator to add a user to a user group. Then continue to obtain the resource path of the event and its corresponding realm, and check whether its resource path starts with "users / ". If not, record a warning log and end the processing; if so, determine whether the resource path conforms to the preset format users / {userId} / groups / {groupId}. If it meets the requirements, split the resource path by " / ", and check whether the length of the split array is at least 4 and whether the third element is "groups". If not, record a warning log and end the processing; if so, extract the user identifier (user ID) and group identifier (group ID) from the split array, then obtain the group model object (GroupModel) based on the group ID, and extract the group name from the group model object. Then determine whether the group name is in the target notified group name set NOTIFIED_GROUPS. If it is, call the cacheGroupJoinEvent() method to cache this user adding to user group event. If not, record a log indicating that the group is not in the NOTIFIED_GROUPS set.
[0084] It should also be noted here that if any exception occurs during this processing, capture and record the error log.
[0085] The code example corresponding to this processing is as follows:
[0086] public void onEvent(AdminEvent event, boolean includeRepresentation){
[0087] / / Print the received administrator event information, including the operation type and resource type
[0088] logger.info("Received admin event: " + event.getOperationType() +" - " + event.getResourceType());
[0089] / / Check if the operation type of the administrator event is CREATE and the resource type is GROUP_MEMBERSHIP
[0090] if (event.getOperationType() == OperationType.CREATE &&
[0091] event.getResourceType() == ResourceType.GROUP_MEMBERSHIP) {
[0092] / / Print the resource path of the association creation event that is adding a user to a user group and is being processed
[0093] logger.info("Processing group membership event: " +event.getResourcePath());
[0094] try {
[0095] / / Get the Realm to which the event belongs
[0096] RealmModel realm = session.realms().getRealm(event.getRealmId());
[0097] String resourcePath = event.getResourcePath();
[0098] / / Ensure that the resource path starts with "users / " to meet the expected format
[0099] if (resourcePath != null && resourcePath.startsWith("users / ")) {
[0100] / / Split the resource path by " / " to extract the user ID and group ID
[0101] String[] parts = resourcePath.split(" / ");
[0102] if (parts.length >= 4 && "groups".equals(parts[2])) {
[0103] String userId = parts[1]; / / Extract the user ID
[0104] String groupId = parts[3]; / / Extract the group ID
[0105] / / Obtain the group model object based on the group ID
[0106] GroupModel group = session.groups().getGroupById(realm, groupId);
[0107] if (group != null && NOTIFIED_GROUPS.contains(group.getName())) {
[0108] / / If the group is in the target notified group set, cache the event of creating the association between the user and the user group
[0109] cacheGroupJoinEvent(realm, userId, groupId);
[0110] } else {
[0111] / / If the group name is not in the target notified group set, record the log
[0112] logger.info("Group is not in notified list.Group: " + (group != null? group.getName() : groupId));
[0113] }
[0114] } else {
[0115] / / If the resource path format is incorrect, record a warning log
[0116] logger.warn("Invalid resource path format: " +resourcePath);
[0117] }
[0118] } else {
[0119] / / If the resource path does not meet the expected format, record a warning log
[0120] logger.warn("Resource path does not start with 'users / '. Path: " + resourcePath);
[0121] }
[0122] } catch (Exception e) {
[0123] / / Capture the exception and record the error log
[0124] logger.error("Error processing group join event", e);
[0125] }
[0126] }
[0127] }
[0128] After determining that the administrator adds a user to the target notification group, an email is constructed to inform the corresponding user of the access permission change message, as Figure 2 shown, which shows the entire process from opening the authentication connection to the administrator changing the user's access permission to notifying the user of the access permission change.
[0129] In some embodiments, a notification message including the username and the name of the target notification group joined by the user is constructed, and the notification message is sent to the user through the user contact information, including:
[0130] Construct the email content in a structured text format, dynamically embed the username and the list of names of the target notification groups joined by the user, and the list contains at least one name of the target notification group;
[0131] Package the email subject, email address, and email content to generate a notification email;
[0132] Call the email service built in the identity access management service to send the notification email to the user's email box.
[0133] Get the built-in email service EmailSenderProvider from the Keycloak session and check if the service is available. If it is not available, record an error log and terminate the process. If it is available, call the generateEmailContent() method to generate the HTML-formatted email body, and record a log indicating that an attempt is being made to send an email to the user's mailbox. Then call the emailSender.send() method to send the email. The parameters of the emailSender.send() method include: 1) the SMTP configuration information obtained from the Realm configuration, including the SMTP server address, port, and authentication information, etc.; 2) the user's email address obtained from the user object; 3) the email subject (fixed as "You have been added to new groups"); 4) the email body (HTML format); 5) the email body (plain text format, where the content of both is the same, but in practice, the plain text format may remove HTML tags). If the email is sent successfully, record a success log; if an "EmailException" is thrown during the sending process, catch the exception and record an error log.
[0134] Among them, the specific steps for generating the email content include:
[0135] 1. Receive the user information and the group list as parameters;
[0136] 2. Use the StringBuilder() method to construct a list of target notification group names in HTML format (each target notification group name as a list item ` `)
[0137] 3. Return a complete HTML document string, which includes: 1) A greeting to the user (using the username); 2) An explanatory text (informing the user that they have been added to the following groups); 3) A list of the constructed target notification group names; 4) A prompt, such as "You can access to the Docs"; 5) The sender's signature, such as YueshuGraph IDP System.
[0138] If the group that the administrator adds the user to does not belong to the target notification group, only a prompt message will be generated in the log and no email will be sent.
[0139] The method provided in this embodiment can automatically send permission change notifications to users when the administrator assigns or modifies permissions for users. This not only improves the user experience but also reduces the workload of the administrator, ensuring the efficient operation of the system and the security of data. Especially through the integration with Keycloak, it ensures that the permission notifications can be conveyed to users in a timely and accurate manner.
[0140] In some embodiments, a user management notification method for a graph database document site further includes:
[0141] Set a timed task scheduler to poll the event cache queue of adding users to user groups at fixed time intervals;
[0142] When preset conditions are met, trigger the scheduler shutdown process;
[0143] Before execution, check whether the scheduler has been initialized and is in a running state;
[0144] If both are satisfied, initiate a shutdown request and set the maximum waiting time;
[0145] If the task is not completed after the timeout, forcibly terminate the scheduler process.
[0146] Specifically, set a timed task scheduler that is configured to trigger user permission change tasks, that is, the event of the administrator adding a user to a user group, at a predetermined time interval. This design not only ensures that permission changes can be processed in a timely manner but also effectively avoids the phenomenon of task queue blocking caused by continuous or overly frequent permission changes. Once the previous permission change task is completed, the next task will start to execute according to its order in the queue and the preset time interval, rather than immediately entering the execution state.
[0147] When the scheduler object is destroyed or no longer needs to be called, the process of shutting down the scheduler will be triggered. The shutdown process of the scheduler includes: checking whether the scheduler has been initialized and has not been shut down. If both conditions are met, a shutdown request will be sent and the scheduler will wait for 10 seconds for the tasks in the scheduler to complete. If the timeout occurs, the scheduler will be forcibly shut down. If the timeout does not occur, the initialized flag will be marked as uninitialized. If a thread interruption exception is caught during the process of waiting for the tasks to complete, an error log will be recorded and the scheduler will be forcibly shut down. If any of the conditions is not met, it will be skipped directly.
[0148] Meanwhile, under normal circumstances, the event that an administrator adds a user to a user group will be placed in the timed task scheduler for asynchronous processing. However, if the scheduler is shut down, the system will switch to synchronous processing of this event.
[0149] In this embodiment, by introducing the timed task scheduling mechanism, the execution frequency and timing of an administrator adding a user to a user group can be effectively controlled, thereby preventing a single task from occupying system resources for a long time and ensuring the smooth progress of the permission change process.
[0150] Embodiment 2
[0151] As Figure 3 shown, a user management notification device for a graph database document site includes:
[0152] An acquisition module, configured to acquire a set of target notification group names pre-configured in the identity access management service, where the target notification groups are associated with the access permissions of the graph database document site;
[0153] An identification module, configured to capture administrator events through the event listening mechanism of the identity access management service, and identify whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event;
[0154] A response module, configured to, in response to identifying an associated creation event, parse the event data, extract the group identifier of the user group being operated on and the user identifier of the user being added, and query the group attribute information according to the group identifier to obtain the group name;
[0155] A query module, configured to, if the obtained group name belongs to the set of target notification group names, query the user attribute information according to the user identifier to obtain the user name and user contact information;
[0156] A notification module, configured to construct a notification message including the user name and the name of the target notification group to which the user is added, and send the notification message to the user through the user contact information.
[0157] This embodiment is used to implement the method provided in the above embodiment and has the corresponding beneficial effects of the above method. For the technical details not described in detail in this embodiment, reference may be made to the methods provided in all the foregoing embodiments of the present invention.
[0158] Embodiment 3
[0159] As Figure 4 shown, an electronic device includes a memory 401 and a processor 402. The memory 401 is used to store one or more computer instructions. Among them, the one or more computer instructions are executed by the processor 402 to implement the above-mentioned user management notification method for a graph database document site.
[0160] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described electronic device can refer to the corresponding process in the foregoing method embodiment and will not be described in detail here.
[0161] A computer-readable storage medium storing a computer program, where the computer program, when executed by a computer, implements the above-mentioned user management notification method for a graph database document site.
[0162] Exemplarily, the computer program can be divided into one or more modules / units. One or more modules / units are stored in the memory 401 and executed by the processor 402, and the I / O interface transmission of data is completed by the input interface 405 and the output interface 406 to complete the present invention. One or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the computer device.
[0163] The computer device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device may include, but is not limited to, the memory 401 and the processor 402. Those skilled in the art can understand that this embodiment is only an example of the computer device and does not constitute a limitation on the computer device. It may include more or fewer components, or combine certain components, or different components. For example, the computer device may also include an input device 407, a network access device, a bus, etc.
[0164] The processor 402 can be a Central Processing Unit (CPU), or it can also be other general-purpose processors 402, Digital Signal Processors (DSPs) 402, Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor 402 can be a microprocessor 402, or the processor 402 can also be any conventional processor 402, etc.
[0165] The memory 401 can be an internal storage unit of the computer device, such as the hard disk or memory of the computer device. The memory 401 can also be an external storage device of the computer device, such as a plug-in hard disk equipped on the computer device, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the memory 401 can also include both the internal storage unit and the external storage device of the computer device. The memory 401 is used to store computer programs and other programs and data required by the computer device. The memory 401 can also be used to temporarily store data in the output device 408, and the aforementioned storage media include various media that can store program codes, such as USB flash drives, mobile hard disks, Read-Only Memory (ROM) 403, Random Access Memory (RAM) 404, magnetic disks or optical discs.
[0166] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the appended claims.
Claims
1. A user management notification method for a graph database document site, characterized in that, The steps include: Obtain a set of pre-configured target notification group names in the identity access management service, where the target notifications are associated with the access rights of the graph database document site; Capture administrator events through the event listening mechanism of the identity access management service, and identify whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event; In response to identifying the associated creation event, parse the event data, extract the group identifier of the user group being operated on and the user identifier of the user being added, and query the group attribute information according to the group identifier to obtain the group name; If the obtained group name belongs to the set of target notification group names, query the user attribute information according to the user identifier to obtain the user name and user contact information; Construct a notification message containing the user name and the target notification group name they joined, and send the notification message to the user through the user contact information.
2. The user management notification method of a graph database document site according to claim 1, wherein The obtaining of the set of pre-configured target notification group names in the identity access management service includes: Initialize a static and immutable empty set for storing target notification group names; Read the notification group configuration parameters in the identity access management service environment variables; If the configuration parameter is a non-empty value, extract all the target notification group names with a comma as the delimiter, and add all the target notification group names to the set; When the environment variable is not set or is empty, record a warning log and skip the initialization.
3. The user management notification method of a graph database document site according to claim 2, wherein The identifying of whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event includes: Extract the operation type and resource type from the event object; When the operation type is a create operation and the resource type is a user group membership relationship, determine that the current event is an associated creation event of adding a user to a user group.
4. The user management notification method of a graph database document site according to claim 3, characterized in that The parsing of the event data, extracting the group identifier of the user group being operated on and the user identifier of the user being added, and querying the group attribute information according to the group identifier to obtain the group name includes: Extract the resource path from the event and verify whether the resource path conforms to a preset format; If it conforms, split the path string according to the path hierarchy structure to obtain the group identifier of the user group being operated on and the user identifier of the user being added; Obtain the group model object according to the group identifier, and extract the name attribute value from the group model object to obtain the group name.
5. The user management notification method of a graph database document site according to claim 4, characterized in that, The querying of the user attribute information according to the user identifier to obtain the user name and user contact information includes: Obtain the user model according to the user identifier, and extract the user name field and the email address field from the user model object to obtain the user name and the email address.
6. The user management notification method of a graph database document site according to claim 5, characterized in that, The constructing of the notification message containing the user name and the target notification group name they joined, and sending the notification message to the user through the user contact information includes: Build the email content in a structured text format, dynamically embed the user name and the list of target notification group names they joined, where the list contains at least one target notification group name; Package the email subject, email address, and email content to generate a notification email. Call the email service built in the identity access management service to send the notification email to the user's email box.
7. A user management notification method for a graph database document site according to claim 1, characterized in that, The method further includes: Set up a scheduled task scheduler to poll and add user join user group event cache queues at fixed time intervals; When the preset conditions are met, trigger the scheduler shutdown process; Before execution, check whether the scheduler has been initialized and is in a running state; If both are satisfied, initiate a shutdown request and set the maximum waiting time; If the task is not completed after the timeout, forcefully terminate the scheduler process.
8. A user management notification device for a graph database document site, characterized in that, Includes: An acquisition module for acquiring a set of target notification group names preconfigured in the identity access management service, where the target notification group is associated with the access permission of the graph database document site; An identification module for capturing administrator events through the event listening mechanism of the identity access management service, and identifying whether the current event is an associated creation event of adding a user to a user group based on the operation type and resource type in the event; A response module for, in response to identifying the associated creation event, parsing the event data, extracting the group identifier of the operated user group and the user identifier of the added user, and querying the group attribute information according to the group identifier to obtain the group name; A query module for, if the obtained group name belongs to the set of target notification group names, querying the user attribute information according to the user identifier to obtain the user name and user contact information; A notification module for constructing a notification message including the user name and the name of the target notification group to which the user belongs, and sending the notification message to the user through the user contact information.
9. An electronic device, characterized in that, Includes a memory and a processor, where the memory is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor to implement a user management notification method for a graph database document site as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a computer, it implements a user management notification method for a graph database document site as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Multi-strategy access control login method and device, computer equipment and storage medium
CN111800440A
Keylock-based k8s authority management system
CN118672732A
Mail early warning system based on cloud platform
CN119135505A
Event notification method and device, computer equipment and readable storage medium
CN119668895A
Implementation method for user authentication and nailing notification of graph database document site
CN120090882A
Cited By
User batch initialization method for graph database document authentication system
CN121351119A
A user batch initialization method for a graph database document authentication system
CN121351119B
Mailbox domain name verification and automatic authorization method oriented to graph database access
CN121486102A