Data authority control method and device, storage medium and electronic equipment
Through independent development of permission control logic and generation of permission configuration sets, the duplicate development problem of permission control in multi-tenant and multi-user scenarios is solved, the visual configuration and high reusability of permission rules are realized, and the development and maintenance costs are reduced.
Patent Information
- Application Number
- CN202410205060.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-23
- Publication Date
- 2025-08-26
AI Technical Summary
In the business scenario of multi-tenant and multi-user, the existing technology requires repeated permission control development for each business function module, resulting in high development costs and redundant authority control logic and business logic, which are highly invasive.
By independently developing permission control logic, permission rules are generated and permission configuration sets are formed. They are independent of application modules and are suitable for multiple application modules, reducing invasiveness to application modules, and visual configuration is carried out through the permission configuration interface.
The visual configuration of permission rules is realized, which reduces development and maintenance costs, improves the reusability and consistency of permission control, and reduces the intrusion of application modules.
Smart Images

Figure CN120540646A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data authority control, and in particular to a data authority control method, device, storage medium and electronic device. Background Art
[0002] In multi-tenant, multi-user business scenarios, a centralized data management approach combined with modularized business function development is recommended. With centralized data management, each business function module must restrict the data that users can operate and view. Currently, permission control is being developed for each business function module.
[0003] In the process of implementing the present invention, it was found that there are at least the following technical problems in the prior art: when there are multiple business function modules, permission control development needs to be repeated. When there are new permissions or modifications, redevelopment is required and the development cost is high. At the same time, the permission control logic and business logic are redundant, which is highly invasive to the business function modules. Summary of the Invention
[0004] The present invention provides a data permission control method, device, storage medium and electronic device. By independently developing permission control logic, it is independent of the application module, reducing the intrusion into the application module. At the same time, the permission control logic is applicable to multiple application modules, has strong reusability and low development and maintenance costs.
[0005] According to one aspect of the present invention, a data authority control method is provided, comprising:
[0006] Obtain permission details through the permission configuration interface, establish an association based on the permission details and user information, and generate permission rules;
[0007] forming a permission configuration set based on the permission rules, wherein the permission configuration set is connected to at least one application module;
[0008] In response to the data request of the application module, target permission rules are matched from the permission configuration set, and data is filtered based on the target permission rules to obtain a data display result.
[0009] Optionally, obtaining permission details through the permission configuration interface includes:
[0010] Display a permission configuration interface, which includes a field type configuration item and a data range configuration item; obtain the field type to be configured through the field type configuration item, and obtain the data range of each field type through the data range configuration item; receive the permission type for the setting of the field type and / or the data range.
[0011] Optionally, obtaining the field type to be configured through the field type configuration item includes:
[0012] Displaying a field selection control and a full field selection control for the field type configuration item in the permission configuration interface; in response to a triggering operation of the full field selection control, setting a plurality of pre-configured field types as field types to be configured; in response to a triggering operation of the field selection control, displaying a plurality of pre-configured field types, and determining the field type to be configured based on the field type selection operation;
[0013] Furthermore, obtaining the data range of each field type through the data range configuration item includes:
[0014] During the selection process of any level of data range, the range selection control and the full-range selection control of the field type configuration item are displayed; the data range of the field type includes at least one level of range; in response to the triggering operation of the full-range selection control, all data resources of the current level data resource item are determined as the data range of the field type; in response to the triggering operation of the range selection control, the next level of optional data resource items are displayed, and the data range of the field type at the current level is determined based on the selection operation of the optional data resource item.
[0015] Optionally, establishing an association based on the permission details information and user information to generate permission rules includes:
[0016] User information is obtained, and when the permission of the user information is not full data permission, permission details information is displayed; and an association relationship is established between the user information and the permission details information to obtain a permission rule.
[0017] Optionally, the permission configuration set is connected to at least one application module via a preset plug-in; or, the permission configuration set is connected to at least one application module based on permission annotation.
[0018] Optionally, in response to the data request of the application module, matching a target permission rule from the permission configuration set includes:
[0019] Extract the user information in the data request and read the permission configuration set; if the permission of the user information is not full data permission, match the permission configuration set based on the user information to determine the target permission rule.
[0020] Optionally, filtering data based on the target permission rule to obtain data display results includes:
[0021] Generate a filtering condition based on the target permission rule; and filter the data to be displayed corresponding to the data request based on the filtering condition to obtain a data display result.
[0022] According to another aspect of the present invention, a data authority control device is provided, comprising:
[0023] The permission rule generation module is used to obtain permission details information through the permission configuration interface, establish an association based on the permission details information and user information, and generate permission rules;
[0024] a permission configuration set generation module, configured to form a permission configuration set based on the permission rules, wherein the permission configuration set is connected to at least one application module;
[0025] The data permission control module is used to respond to the data request of the application module, match the target permission rules from the permission configuration set, and filter the data based on the target permission rules to obtain the data display result.
[0026] According to another aspect of the present invention, an electronic device is provided, comprising:
[0027] at least one processor; and
[0028] a memory communicatively connected to the at least one processor; wherein,
[0029] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data authority control method described in any embodiment of the present invention.
[0030] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data permission control method described in any embodiment of the present invention when executed.
[0031] The technical solution of the embodiment of the present invention obtains permission details through the permission configuration interface, realizes the visual configuration of permission rules, and makes the configuration process simple and convenient. By connecting the permission configuration set to multiple application modules, there is no need to embed the permission configuration set into the application module, thereby reducing the intrusion into the application module. The permission configuration set is adaptable to multiple application modules, and the permission control of multiple application modules is standardized, which improves the consistency of permission control of multiple application modules. The permission configuration set is highly reusable, which can reduce the development cost and maintenance cost of the permission configuration set.
[0032] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0034] Figure 1 This is a flow chart of a data authority control method provided by an embodiment of the present invention;
[0035] Figure 2 This is a flowchart of generating permission rules provided by an embodiment of the present invention;
[0036] Figure 3 Schematic diagram of a method for accessing permission details information and application modules provided by an embodiment of the present invention;
[0037] Figure 4 is a schematic diagram of a system structure provided by an embodiment of the present invention;
[0038] Figure 5 This is a structural diagram of a data authority control device provided by an embodiment of the present invention;
[0039] Figure 6 It is a structural diagram of an electronic device implementing an embodiment of the present invention. DETAILED DESCRIPTION
[0040] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0041] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0042] Figure 1 This is a flow chart of a data authority control method provided by an embodiment of the present invention. This embodiment is applicable to visually configuring data authority logic and accessing the configured data authority logic to multiple application modules with high reusability. This method can be executed by a data authority control device, which can be implemented in the form of hardware and / or software. The data authority control device can be configured in electronic devices such as computers, servers, mobile phones, etc. Figure 1 As shown, the method includes:
[0043] S110: Obtain permission details through the permission configuration interface, establish an association based on the permission details and user information, and generate permission rules.
[0044] S120: Form a permission configuration set based on the permission rule, and connect the permission configuration set to at least one application module.
[0045] S130 . In response to the data request of the application module, match target permission rules from the permission configuration set, and perform data filtering based on the target permission rules to obtain a data display result.
[0046] In response to the permission configuration operation, the permission configuration interface is displayed, which includes an information collection control and receives the permission details information entered by the user through the information collection control. The permission details information includes the field type, the data range of the field type and the permission type, wherein the field type and the data range are different dimensions for setting permissions. Taking the data as table data as an example, the field type can be the column dimension of the table data, and the data range can be the row dimension of the table data. There may be different data types for data of different businesses, and the data ranges of different data types may also be different. Taking the transaction scenario as an example, the data may be the table data of the transaction object, wherein the field type may include but is not limited to "product type", "price", "origin", etc. For the field type of "product type", its data range may include but is not limited to alcohol, dairy products, drinking water, etc. The permission type includes one or more of read permission and write permission.
[0047] The visual permission configuration interface allows you to obtain permission details such as the field type, field type data range, and permission type to generate permission rules. By calling the permission configuration interface, you can configure the visual permission details and display the configured permission details through the permission configuration interface, making it easier to intuitively determine the configured permission details and simplifying the permission configuration process.
[0048] Before configuring permissions through the permission configuration interface, define the basic field type and basic data range, wherein the basic field type is the field that needs to be subject to permission control, and the basic data range is the maximum data range of each basic field type. Optionally, the basic field type can be a collection of field types that need to be subject to permission control in the business data of multiple application modules, and the basic data range is the maximum data range of the basic field type in the business data of multiple application modules. The business data of each application model may include multiple table data, and the field type of each table data is extracted. The field types extracted from the business data of multiple application modules are deduplicated to obtain a field type set, i.e., the basic field type. For each basic field type, the data range of the basic field type is determined separately in the business data of the application model, and the collection of the data ranges of the basic field type in multiple application models is determined as the basic data range of the basic field type.
[0049] By integrating the business data of multiple application modules to define basic field types and basic data ranges, the permission details corresponding to each permission rule can be filtered from the basic field types and basic data ranges to generate permission rules suitable for multiple application modules, thereby improving the reuse rate of permission rules. There is no need to set permission rules for each application module separately, which improves the standardization and consistency of permission rules in multiple application models.
[0050] The permission configuration interface includes a field type configuration item and a data range configuration item. The field type configuration item and the data range configuration item can be information input controls, such as an input box, a selection control including a drop-down menu, or a selection control including a floating window or a pop-up window, etc., which are not limited here. The field type to be configured is obtained through the field type configuration item. For example, a trigger operation for the field type configuration item is received, and the basic field type is displayed through a drop-down menu, a floating window, or a pop-up window. Based on the selection operation of one or more basic field types, the field type to be configured is determined.
[0051] Optionally, the field type to be configured is obtained through the field type configuration item, including: displaying the field selection control and the full field selection control of the field type configuration item in the permission configuration interface; in response to the triggering operation of the full field selection control, setting the pre-configured multiple field types as the field types to be configured; by setting the full field selection control, all basic field types can be selected as the field types to be configured with one click, thereby simplifying the field type selection process.
[0052] In response to the triggering operation of the field selection control, multiple pre-configured field types are displayed, and the field type to be configured is determined based on the field type selection operation. Among them, the multiple pre-configured field types are basic field types, which can be displayed through a drop-down menu, a floating window or a pop-up window, which is not limited here. The selection operation of the multiple pre-configured field types can be achieved by clicking, dragging, circling, etc. The selected field type is displayed on the permission configuration interface to intuitively display the selected field type.
[0053] In response to a delete operation on a field type to be configured, the field type to be configured is deleted, thereby implementing a modification of the selected field type.
[0054] The data range of each field type is obtained through the data range configuration item. It can be understood that each field type to be configured corresponds to a data range configuration item, and the data range of each field type is determined by the data range configuration item. Similarly, when a trigger operation is received for the data range configuration item, the basic data range corresponding to the field type to be configured is displayed through a drop-down menu, floating window or pop-up window for user selection. According to the data range selection operation, the data range of the field type to be configured is determined.
[0055] The field type to be configured may include multiple levels of data ranges. Taking the field type "product type" as an example, the first-level data range of "product type" includes but is not limited to alcoholic beverages, dairy products, drinking water, etc. The next-level data range included in alcoholic beverages includes but is not limited to liquor, beer, red wine, etc., among which liquor can also include the next-level data range. It can be seen that each field type may include at least one level of data range. In the process of determining the data range corresponding to the field type to be configured, the data range of each level is determined one by one, and the data ranges of multiple levels constitute the data range corresponding to the field type to be configured.
[0056] Optionally, the data range of each field type is obtained through the data range configuration item, including: in the selection process of any level of data range, displaying the range selection control and the full range selection control of the field type configuration item; the data range of the field type includes at least one level of range; in response to the triggering operation of the full range selection control, all data resources of the current level data resource item are determined as the data range of the field type; in response to the triggering operation of the range selection control, the next level of optional data resource items are displayed, and the data range of the field type at the current level is determined based on the selection operation of the optional data resource item.
[0057] Select the data range of each set one by one. During the selection process of any level of data range, the range selection control and the full range selection control are displayed. The full range selection control is used to realize one-click selection of all data resources. For example, during the selection process of the data range at the "Product Type" level, if the full range selection control is triggered, all data resources included in the data resource item "Product Type" are determined as the data range of the field type "Product Type". For example, during the selection process of the data range at the "Product Type" level, select the data resource items "Alcohol" and "Drinking Water". During the selection process of the data range at the "Alcohol" level, if the full range selection control is triggered, all data resources included in the data resource item "Alcohol" are determined as the data range of "Alcohol". Accordingly, the data ranges of "Alcohol" and "Drinking Water" respectively constitute the data range of the field type "Product Type".
[0058] The range selection control is used to trigger the display of the next level of optional data resource items, for example, through a drop-down menu, floating window or pop-up window. During the selection process of any level of data range, when the range selection control is triggered, the next level of optional data resource items of the current level data resource items are displayed. The data range of the current level data resource items is determined based on the selection operation of the optional data resource items, and so on, until the selection of the last level of data resource items is completed.
[0059] Receive the permission type set for the field type and / or the data range, wherein the permission type can be batch-set for multiple determined field types and / or multiple data ranges to improve the efficiency of setting the permission type. The permission type can be an item or object of read permission and write permission. For example, read permission and write permission can be set for the field type of product type, that is, read permission and write permission are granted to all data ranges of the field type of product type; read permission can be set for the field type of price, that is, read permission is granted to all data ranges of the field type of price; write permission is set for the data range 0-m of the field type of price, that is, write permission is granted to data within the data range 0-m of the field type of price, and no write permission is granted to other data ranges outside 0-m.
[0060] Permission details are formed by setting the field type, field range, and permission type, and permission rules are formed by setting the associated user information of the permission details. Optionally, permission rules are generated based on the association between the permission details and user information. Each permission detail and associated user information generates a permission rule, and multiple permission rules form a permission configuration set.
[0061] Specifically, user information is obtained, and the user information can be a unique identifier of the user. Exemplarily, the unique identifier can be obtained by encoding information such as the user account and position. In some embodiments, the permission association module also includes a full data permission setting control, and the full data permission setting control is used to set full data permissions with one click. Full data permissions are to set read permissions and write permissions for all data ranges of all pre-set basic field types. Exemplarily, when any user information is selected, a trigger operation for the full data permission setting control is received, and full data permission rules for the user information are generated.
[0062] If the user information's permission is not full data permission, the permission details are displayed; the user information and the permission details are associated to obtain a permission rule. A permission association module displays user information and pre-set permission details, which may be multiple. An association control is used to associate the selected user information with the permission details to obtain a permission rule.
[0063] For example, see Figure 2 , Figure 2 This is a flowchart of generating a permission rule provided by an embodiment of the present invention. The attributes requiring permission control, namely, field type and data range, are set through data permission definition, wherein the data range type can be an enumeration type or a continuous data type.
[0064] Through the data permission details configuration, that is, displaying the permission configuration interface, the attribute data permissions are configured in the permission configuration interface, specifically, including the data permissions of the field type and the permissions of the data range. For the field type, all fields or selected local fields can be determined, and read permissions and / or write permissions can be set for all fields or selected local fields. For the data range, each field type can include multiple attribute fields (i.e., data resource items), and all data resources of all attribute fields can be determined as the data range of the field type; it is also possible to select an attribute field and obtain the resource value of the selected attribute field. When the resource value has the next level of data range, all data resources can be further selected or the layout resource value can be selected to set read permissions and / or write permissions to generate permission details information.
[0065] By associating user data permissions, user information is associated with permission details to obtain permission rules. The permission details can be set in the above manner or can be full data permission information, and can be associated according to the permission requirements of user information.
[0066] Based on the above embodiment, a permission configuration set is generated by generating multiple permission rules. The permission configuration set is suitable for multiple application modules. The application model can be a module that performs business functions in a business system. The application modules included in different business systems may be different. Taking the trading system as an example, the application modules include but are not limited to a prediction module, a timing module, a replenishment module, etc.
[0067] By integrating permission configuration sets into multiple application modules, there's no need to embed them within them, reducing intrusion into the modules. At the same time, permission configuration sets are adaptable to multiple application modules, enabling standardized permission control across them. This improves consistency across these modules, and the high reusability of permission configuration sets reduces development and maintenance costs, enabling unified permission updates across multiple application modules and ensuring timeliness.
[0068] Optionally, the permission configuration set is connected to at least one application module through a preset plug-in; or, the permission configuration set is connected to at least one application module based on permission annotations. Figure 3 , Figure 3 This is a schematic diagram of a method for accessing permission details information and application modules provided by an embodiment of the present invention.
[0069] Each application module can access the permission configuration set by introducing a preset plug-in dependency package. The preset plug-in can be a permission control plug-in. In some embodiments, the permission control plug-in can be a MyBatis plug-in. The application module can read the permission rules in the permission configuration set through the permission control plug-in to implement permission control over the data.
[0070] Accessing permission configuration sets through annotations is suitable for web application modules. Simply include the annotation parser dependency package in your web application module and add permission annotations to the object properties returned by the web interface. The annotation parser uses permission annotations to determine whether the object properties returned by the web interface contain data requiring permission control. If so, it reads the permission rules in the permission configuration set to implement permission control on the data.
[0071] Based on the above embodiment, when an application module accesses data, it can perform authentication processing by reading the permission rules in the permission configuration set, and control the data permissions based on the authentication results. The authentication processing can determine whether the user has read and write permissions to the data based on the permission rules matched from the permission configuration set.
[0072] Among them, the data access performed by the application module may be an access to a data storage space such as a database or a data cache, so as to read the data in the data storage space for display. The application module sends a data request to the data storage space, and the data request may contain user information. Accordingly, in response to the data request of the application module, the target permission rule is matched from the permission configuration set, including: extracting the user information in the data request and reading the permission configuration set; when the permission of the user information is not a full data permission, matching is performed in the permission configuration set based on the user information to determine the target permission rule.
[0073] The user information in the data request is matched against the permission configuration set to determine the target permission rule that matches the user information. The user information can first be determined for full data permission. If the user information has full data permission, there is no need to perform permission control on the data returned by the accessed data storage space; the data returned by the data storage space can be directly displayed. If the user information does not have full data permission, the target permission rule is further matched based on the user information.
[0074] Data is filtered based on the target permission rules to obtain data display results. The processed data is the data fed back by the accessed data storage space. Data filtering may include deleting or hiding data that does not have read permission, and setting data that does not have write permission to an uneditable state.
[0075] Generate filtering conditions based on the target permission rules; filter the data to be displayed corresponding to the data request based on the filtering conditions to obtain data display results. The target permission rules include field type, field range and permission type. The filtering conditions are generated based on the field type and field range, and the read and write status of the filtered data is set according to the permission type. Exemplarily, the target permission rules include read permission for the wine range of the product type field type. Accordingly, the generated filtering conditions are "field type = product type and data range = wine", and the filtered wine data is displayed and set to a non-editable state.
[0076] For example, see Figure 4 , Figure 4 It is a schematic diagram of a system structure provided by an embodiment of the present invention.
[0077] This embodiment also provides HTTP and RPC interfaces for use with modules developed in non-Java languages. The interface input requires the caller to specify user information and the attributes that require authentication. The interface returns specific SQL conditions to the caller. The interface input requires the caller to specify user information and the attributes that require authentication. The interface returns the configuration data corresponding to the user in the data permission module to the caller, which the caller can parse and use.
[0078] The technical solution of this embodiment obtains permission details through the permission configuration interface, enabling visual configuration of permission rules and simplifying the configuration process. By connecting permission configuration sets to multiple application modules, there is no need to embed the permission configuration sets within the application modules, reducing the intrusiveness of the application modules. The permission configuration sets are adaptable to multiple application modules, standardizing permission control across multiple application modules, improving the consistency of permission control across multiple application modules, and the high reusability of permission configuration sets, which can reduce the development and maintenance costs of permission configuration sets.
[0079] Figure 5 This is a structural diagram of a data authority control device provided by an embodiment of the present invention. Figure 5 As shown, the device includes:
[0080] The permission rule generation module 210 is used to obtain permission details information through the permission configuration interface, establish an association between the permission details information and user information, and generate permission rules;
[0081] A permission configuration set generating module 220 is configured to form a permission configuration set based on the permission rules, wherein the permission configuration set is connected to at least one application module;
[0082] The data permission control module 230 is configured to respond to the data request of the application module, match target permission rules from the permission configuration set, and perform data filtering based on the target permission rules to obtain data display results.
[0083] The technical solution of this embodiment obtains permission details through the permission configuration interface, enabling visual configuration of permission rules and simplifying the configuration process. By connecting permission configuration sets to multiple application modules, there is no need to embed the permission configuration sets within the application modules, reducing the intrusiveness of the application modules. The permission configuration sets are adaptable to multiple application modules, standardizing permission control across multiple application modules, improving the consistency of permission control across multiple application modules, and the high reusability of permission configuration sets, which can reduce the development and maintenance costs of permission configuration sets.
[0084] Based on the above embodiment, optionally, the permission rule generation module 210 is used to:
[0085] Display a permission configuration interface, which includes a field type configuration item and a data range configuration item; obtain the field type to be configured through the field type configuration item, and obtain the data range of each field type through the data range configuration item; receive the permission type for the setting of the field type and / or the data range.
[0086] Optionally, the permission rule generation module 210 is further configured to:
[0087] A field selection control and a full field selection control for the field type configuration item are displayed in the permission configuration interface; in response to a triggering operation of the full field selection control, multiple pre-configured field types are set as field types to be configured; in response to a triggering operation of the field selection control, multiple pre-configured field types are displayed, and the field type to be configured is determined based on the field type selection operation.
[0088] Optionally, the permission rule generation module 210 is further configured to:
[0089] During the selection of any level of data range, a range selection control and a full range selection control for the field type configuration item are displayed; the data range of the field type includes at least one level of range;
[0090] In response to the triggering operation of the full-range selection control, all data resources of the current-level data resource item are determined as the data range of the field type; in response to the triggering operation of the range selection control, the next-level optional data resource item is displayed, and the data range of the field type at the current level is determined based on the selection operation of the optional data resource item.
[0091] Optionally, the permission rule generation module 210 is further configured to:
[0092] User information is obtained, and when the permission of the user information is not full data permission, permission details information is displayed; and an association relationship is established between the user information and the permission details information to obtain a permission rule.
[0093] Based on the above embodiment, optionally, the permission configuration set is connected to at least one application module via a preset plug-in; or, the permission configuration set is connected to at least one application module based on permission annotation.
[0094] Based on the above embodiment, optionally, the data authority control module 230 is used to:
[0095] Extract the user information in the data request and read the permission configuration set; if the permission of the user information is not full data permission, match the permission configuration set based on the user information to determine the target permission rule.
[0096] Optionally, the data authority control module 230 is further configured to: generate a filtering condition based on the target authority rule; and filter the data to be displayed corresponding to the data request based on the filtering condition to obtain a data display result.
[0097] The data authority control device provided in the embodiment of the present invention can execute the data authority control method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0098] Figure 6 1 is a structural diagram of an electronic device provided in Embodiment 4 of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0099] like Figure 6As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0100] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0101] The processor 11 can be various general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data permission control method.
[0102] In some embodiments, the data permission control method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data permission control method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data permission control method in any other appropriate manner (for example, by means of firmware).
[0103] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0104] Computer programs for implementing the data access control method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data access control device, so that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0105] An embodiment of the present invention also provides a computer-readable storage medium, which stores computer instructions. The computer instructions are used to enable a processor to execute a data permission control method, which includes: obtaining permission details information through a permission configuration interface, establishing an association based on the permission details information and user information, and generating permission rules; forming a permission configuration set based on the permission rules, and connecting the permission configuration set to at least one application module; responding to a data request from the application module, matching target permission rules from the permission configuration set, and filtering data based on the target permission rules to obtain data display results.
[0106] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0107] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0108] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0109] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0110] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0111] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A data authority control method, characterized in that: include: Obtain permission details through the permission configuration interface, establish an association based on the permission details and user information, and generate permission rules; forming a permission configuration set based on the permission rules, wherein the permission configuration set is connected to at least one application module; In response to the data request of the application module, target permission rules are matched from the permission configuration set, and data is filtered based on the target permission rules to obtain a data display result.
2. The method according to claim 1, characterized in that The obtaining of permission details through the permission configuration interface includes: Display the permission configuration interface, which includes field type configuration items and data range configuration items; Get the field type to be configured through the field type configuration item, and get the data range of each field type through the data range configuration item; A permission type for setting the field type and / or the data range is received.
3. The method according to claim 2, characterized in that The method of obtaining the field type to be configured through the field type configuration item includes: Displaying a field selection control and a full field selection control for the field type configuration item in the permission configuration interface; in response to a triggering operation of the full field selection control, setting a plurality of pre-configured field types as field types to be configured; in response to a triggering operation of the field selection control, displaying a plurality of pre-configured field types, and determining the field type to be configured based on the field type selection operation; Furthermore, obtaining the data range of each field type through the data range configuration item includes: During the selection of any level of data range, a range selection control and a full range selection control for the field type configuration item are displayed; the data range of the field type includes at least one level of range; In response to the triggering operation of the full-range selection control, all data resources of the current-level data resource item are determined as the data range of the field type; in response to the triggering operation of the range selection control, the next-level optional data resource item is displayed, and the data range of the field type at the current level is determined based on the selection operation of the optional data resource item.
4. The method according to claim 1, wherein The establishing of an association based on the permission details information and the user information to generate permission rules includes: Obtain user information, and if the permission of the user information is not full data permission, display the permission details information; An association is established between the user information and the permission details information to obtain a permission rule.
5. The method according to claim 1, wherein The permission configuration set is connected to at least one application module via a preset plug-in; Alternatively, the permission configuration set is connected to at least one application module based on permission annotation.
6. The method according to claim 1, characterized in that The step of matching a target permission rule from the permission configuration set in response to the data request of the application module includes: Extracting user information from the data request and reading the permission configuration set; In the case where the permission of the user information is not full data permission, a target permission rule is determined based on matching the user information in the permission configuration set.
7. The method according to claim 1, characterized in that The data is filtered based on the target permission rules to obtain data display results, including: Generate a filtering condition based on the target permission rule; The data to be displayed corresponding to the data request is filtered based on the filtering condition to obtain a data display result.
8. A data authority control device, characterized in that: include: The permission rule generation module is used to obtain permission details information through the permission configuration interface, establish an association based on the permission details information and user information, and generate permission rules; a permission configuration set generation module, configured to form a permission configuration set based on the permission rules, wherein the permission configuration set is connected to at least one application module; The data permission control module is used to respond to the data request of the application module, match the target permission rules from the permission configuration set, and filter the data based on the target permission rules to obtain the data display result.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to execute the data authority control method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data authority control method according to any one of claims 1 to 7 when executed.
Citation Information
Cited By
Dynamic demand management panel generation method, system and device and storage medium
CN122286806A
Dynamic demand management panel generation method, system, device and storage medium
CN122286806B