Data Permission Processing Method, Apparatus and Computer Device
By obtaining user permission fingerprints and file display permission fingerprints on the data layer and comparing them, the data authorization information of the user to be authorized on the display file is solved, and the problem of cumbersome data permission application process and long approval cycle in the existing technology is solved, and efficient and secure data permission management is achieved.
Patent Information
- Application Number
- CN202111017035.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-31
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-08-31
AI Technical Summary
In the existing data management system, the process of applying for access to display files for users is cumbersome and the approval cycle is long, which increases the risk of data leakage and reduces user experience and data access efficiency.
By obtaining user permission fingerprints and file display permission fingerprints on the data layer and comparing them, the data authorization information of the user to be authorized on the display file is automatically obtained, and end-to-end fully automatic data permission management is realized.
The steps for applying for data permissions are simplified, the approval cycle is shortened, the risk of data leakage is reduced, the efficiency of data permissions is improved, and the workload of later operation and maintenance is reduced.
Smart Images

Figure CN113704746B_ABST
Abstract
Description
Technical Field
[0001] This application mainly relates to the field of permission management applications, and more specifically to a data permission processing method, apparatus, and computer device. Background Art
[0002] Business Intelligence (BI), also known as business wisdom or business intelligence, refers to using modern data warehouse technology, online analytical processing technology, data mining, and data presentation technology for data analysis to achieve business value, that is, converting the existing data in an enterprise into knowledge to help users make wise business operation decisions.
[0003] Based on this, in most current enterprise data management systems, during the process of a user applying for access permission to a certain display file (such as a report), it is usually necessary to apply for permissions separately at the data layer and the file display layer (such as the report layer), that is, to obtain the access permission to the corresponding file and the data permissions of several data sources on which the display file depends, so as to view the data of the corresponding data source through the display file.
[0004] It can be seen that this data permission processing method has a cumbersome process and a long approval cycle, which not only brings a poor user experience to users, but also increases the probability of data leakage caused by human errors and has a large amount of later maintenance work. Summary of the Invention
[0005] In view of this, this application provides a data permission processing method, and the method includes:
[0006] Obtain a data permission application request for the data layer;
[0007] Respond to the data permission application request, determine the first data source authorized by the user to be authorized at the data layer, and obtain the user permission fingerprint of the user to be authorized for the first data source;
[0008] Obtain the file display permission fingerprint of the display file to be authorized associated with the first data source; wherein, the file display permission fingerprint is constructed based on the second data source in the data layer authorized for the display file to be authorized during the publishing process of the display file to be authorized, and there is at least one same data source between the second data source and the first data source;
[0009] Compare the user permission fingerprint with the file display permission fingerprint, and obtain the data authorization information of the user to be authorized on the display file to be authorized according to the comparison result.
[0010] Optionally, comparing the user permission fingerprint with the file display permission fingerprint, and obtaining data authorization information of the user to be authorized for the file to be displayed according to the comparison result, including:
[0011] Performing a bitwise AND operation on the characters included in the user permission fingerprint and the file fingerprint respectively to obtain data authorization information of the user to be authorized for the file to be displayed.
[0012] Optionally, the method further includes:
[0013] Receiving a data access request sent by the terminal of the user to be authorized for a first display file;
[0014] Retrieving first data authorization information for the user to be authorized for the first display file;
[0015] Responding to the data access request, and obtaining first file display data that conforms to the first data authorization information;
[0016] Feeding back the first file display data to the terminal for display.
[0017] Optionally, the method further includes:
[0018] Receiving a display file query request sent by the terminal of the user to be authorized for a third data source;
[0019] Screening second data authorization information associated with the third data source from the data authorization information of the user to be authorized for different display files;
[0020] Responding to the display file query request, and obtaining third data source file display data that conforms to any of the second data authorization information;
[0021] Feeding back the third data source file display data to the terminal for display.
[0022] Optionally, the method further includes:
[0023] Obtaining a bitmap dictionary of the permission data structure of the data layer; wherein, the bitmap dictionary is a one-dimensional data structure composed of basic permission fields of different data sources in the permission data structure; the basic permission fields refer to leaf permission fields in the permission data structure;
[0024] The obtaining the user permission fingerprint of the user to be authorized for the first data source includes:
[0025] Detecting whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the first data source, and obtaining a first detection result of the corresponding permission fields;
[0026] Generate a user permission fingerprint for the to-be-authorized user for the first data source according to the first detection results of the respective permission fields included in the bitmap dictionary.
[0027] The construction process of the file display permission fingerprint includes:
[0028] Detect whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the second data source to obtain second detection results of the corresponding permission fields.
[0029] Generate a file display permission fingerprint for the to-be-authorized display file according to the second detection results of the respective permission fields included in the bitmap dictionary.
[0030] Optionally, obtaining the data authorization information of the to-be-authorized user on the to-be-authorized display file according to the comparison result includes:
[0031] Obtain the target permission fields corresponding to the data sources that are simultaneously represented in the user permission fingerprint and the file display permission fingerprint.
[0032] Generate a permission processing logic for the to-be-authorized user on the to-be-authorized display file according to the target permission fields.
[0033] Embed the permission processing logic into the file display processing logic of the to-be-authorized display file; the file display processing logic is used to implement the permission verification of the data access request or the display file query request, and in the case of successful verification, retrieve the corresponding file display data from the data layer.
[0034] Optionally, obtaining the data authorization information of the to-be-authorized user on the to-be-authorized display file according to the comparison result includes:
[0035] Obtain the target permission fields corresponding to the data sources that are simultaneously represented in the user permission fingerprint and the file display permission fingerprint.
[0036] Configure a permission processing proxy layer between the file display layer and the data layer according to the target permission fields; the permission proxy layer is used to implement the permission verification of the data access request or the file query request, and in the case of successful verification, retrieve the corresponding file display data from the data layer.
[0037] Optionally, the method further includes:
[0038] Detect whether there are multiple basic permission fields with the same name in the permission data structure of the data layer.
[0039] If any exist, obtain the permission fields on which multiple basic permission fields with the same name depend respectively, and the path information between the corresponding basic permission fields;
[0040] Construct a bitmap dictionary with a one-dimensional data structure based on the basic permission fields of each data source included in the data layer and the path information.
[0041] This application also proposes a data permission processing device, which includes:
[0042] A data permission application request acquisition module, configured to acquire a data permission application request for the data layer;
[0043] A user permission fingerprint acquisition module, configured to respond to the data permission application request, determine the first data source authorized by the user to be authorized on the data layer, and acquire the user permission fingerprint of the user to be authorized for the first data source;
[0044] A file display permission fingerprint acquisition module, configured to acquire the file display permission fingerprint of the file to be authorized for display associated with the first data source; wherein, the file display permission fingerprint is constructed based on the second data source in the data layer authorized for the file to be authorized for display during the publishing process of the file to be authorized for display, and there is at least one same data source between the second data source and the first data source;
[0045] A data authorization information acquisition module, configured to compare the user permission fingerprint with the file display permission fingerprint, and obtain the data authorization information of the user to be authorized on the file to be authorized for display according to the comparison result.
[0046] This application also proposes a computer device, which includes: at least one memory and at least one processor, wherein:
[0047] The memory is used to store the program of the data permission processing method as described above;
[0048] The processor is used to load and execute the program in the memory to implement the data permission processing method as described above.
[0049] It can be seen that the present application provides a data permission processing method, apparatus and computer device. When a user to be authorized applies for data permissions at the data layer, during the process of the server responding to the received data permission application request, in addition to obtaining the user permission fingerprint of the user to be authorized for the first data source, it will also obtain the file display permission fingerprint of the file to be authorized associated with the first data source, thereby indicating the data source for which the user to be authorized has permissions at the data layer, and the data source for which the file to be authorized has permissions at the data layer. Subsequently, based on the comparison result of these two permission fingerprints, the data authorization information of the user to be authorized for the file to be authorized can be obtained. It can be seen that the user only needs to apply for data permissions once at the data layer to obtain their data permissions for the display file, simplifying the data permission application steps, shortening the approval cycle, reducing the risk of data leakage caused by human errors, improving the data permission authorization efficiency, and reducing the later operation and maintenance workload. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on the provided drawings.
[0051] Figure 1 Schematic flowchart of an optional example of the data permission processing method proposed by the present application;
[0052] Figure 2 Schematic flowchart of another optional example of the data permission processing method proposed by the present application;
[0053] Figure 3 Schematic diagram of the permission data structure of the data layer in the data permission processing method proposed by the present application;
[0054] Figure 4 Schematic diagram of the structure of the bitmap dictionary in the data permission processing method proposed by the present application;
[0055] Figure 5 Schematic flowchart of an optional implementation method for obtaining the user permission fingerprint in the data permission processing method proposed by the present application;
[0056] Figure 6 Schematic flowchart of an optional implementation method for obtaining the file display permission fingerprint in the data permission processing method proposed by the present application;
[0057] Figure 7In the data permission processing method proposed in this application, it is a schematic flowchart of an optional method for obtaining a target permission field;
[0058] Figure 8 It is a schematic flowchart of another optional example of the data permission processing method proposed in this application;
[0059] Figure 9 It is a schematic flowchart of another optional example of the data permission processing method proposed in this application;
[0060] Figure 10 It is a schematic flowchart of another optional example of the data permission processing method proposed in this application;
[0061] Figure 11 It is a schematic diagram of an optional application scenario of the data permission processing method proposed in this application;
[0062] Figure 12 It is a schematic diagram of another optional application scenario of the data permission processing method proposed in this application;
[0063] Figure 13 It is a schematic structural diagram of an optional example of the data permission processing device proposed in this application;
[0064] Figure 14 It is a schematic hardware structure diagram of an optional example of a computer device applicable to the data permission processing method proposed in this application. Detailed implementation manners
[0065] Regarding the content described in the background art section, in the data management systems currently used by enterprises, due to the heterogeneity of the systems, the permission schemes and data are not interoperable. For example, data warehouses such as Hadoop (a distributed system infrastructure) and BI (Business Intelligence) tools such as Qliksense belong to products of different enterprises and need to apply for permissions separately to access or use the corresponding products. In addition, although BI tools have strong computing capabilities themselves, this also causes a break in data permissions. In BI tools, the full-volume data loaded through import is not controlled by the personal permissions of the data warehouse and requires secondary control. Users are required to apply for corresponding permissions for the data warehouse and BI tools separately. This implementation method of applying for data permissions twice will increase the risk of data leakage caused by human errors; the approval cycle is long, bringing a very poor experience to users, and there are redundant permissions, which will also reduce the subsequent data access efficiency.
[0066] To address the above problems, the present application proposes applying for permissions only once at the data layer, which can directly trigger the file display layer where the display file is located, obtaining the permission for the user to view the data of the required data source through the corresponding file display method, enabling the user to view the data within the permission scope in the corresponding display file, simplifying the data permission application steps, improving the user experience, and through this end-to-end fully automated data permission management method, improving the data permission application efficiency and the permission verification efficiency in subsequent data access applications.
[0067] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0068] It should be noted that for the convenience of description, only the parts related to the relevant invention are shown in the accompanying drawings. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other, and the present application does not list them all in detail.
[0069] Referring to Figure 1 , which is a schematic flowchart of an optional example of the data permission processing method proposed by the present application. This method can be applied to a computer device, which can be a server or a terminal with certain data processing capabilities. In the embodiments of the present application, the case where the server executes this data permission processing method is taken as an example for description. As Figure 1 shown, this method may include:
[0070] Step S11, obtaining a data permission application request for the data layer;
[0071] In practical applications, when a certain user hopes to apply for viewing the data of a certain data source in a certain display file (i.e., the display file to be authorized), the user can log in to the data permission management system through the business terminal, enter the permission application page of the data layer for operation, generate the corresponding data permission application request, and send the data permission application request to the server.
[0072] In some embodiments of the present application, such as in the scenario where the user browses or queries the relevant information of a certain data source or multiple data sources through the business terminal, the server verifies that the user does not have the corresponding access permission, prompts the user whether to apply for the corresponding data permission, and when the user clicks the "Apply" button, a corresponding data permission application request can be generated and sent to the server, etc. The present application does not limit the generation method of the above data permission application request, including but not limited to the implementation methods described above.
[0073] It can be understood that since the above data permission application request is generated for the data layer and sent to the server, such as when a user directly applies for data permissions in the data warehouse of the system and generates the data permission application request, etc., in order for the server to understand the user's permission application requirements, the data permission application request may include but is not limited to: the file type of the to-be-authorization display file for which the user hopes to apply permissions, the identifier of the data source (for the convenience of description, this type of data source is denoted as the first data source) from which the user hopes to receive authorized data, etc. Other information may also be included according to application needs, and this application does not list them one by one.
[0074] Among them, the above display file may include various types of visualization reports, such as columnar reports, tabular reports, graphic reports (such as bar charts, line charts, scatter plots, radar charts, GIS (Geographic Information System or Geo-Information system, geographic information system) maps, Gantt charts, etc. in various styles of charts), label reports, etc. This application does not limit the file category of the display file and can be determined according to the data visualization requirements of the application scenario.
[0075] Step S12, in response to the data permission application request, determine the first data source authorized by the to-be-authorization user at the data layer, and obtain the user permission fingerprint of the to-be-authorization user for the first data source;
[0076] For the system where the user applies for data permissions, the various data sources it can provide, that is, the multiple data sources corresponding to the data layer, and the permission management configurations for implementing each data source are often determined. Therefore, when the server (i.e., the service device supporting the operation of this system) parses the received data permission application request, it can understand the requirements of the to-be-authorization user for applying data permissions this time. First, it can first determine whether the to-be-authorization user is authorized for the first data source at this data layer (which can represent one or more data sources authorized to the to-be-authorization user, and this application does not limit the data source category).
[0077] In the case of determining the first data source authorized by the to-be-authorization user in the data layer, in order for the server to identify which first data sources corresponding to the data layer the to-be-authorization user has permissions for, the user permission fingerprint of the to-be-authorization user for the first data source can be obtained by combining the permission management structure of the system for the data source. In this way, the server can obtain which data sources in the system the to-be-authorization user has permissions for through this user permission fingerprint. This application does not limit the acquisition method and representation method of the user permission fingerprint and can be determined according to the situation.
[0078] Step S13, obtain the file display permission fingerprint of the to-be-authorization display file associated with the first data source;
[0079] In the embodiments of the present application, the file display permission fingerprint may be constructed based on the second data source in the authorized data layer of the file to be authorized for display during the release process of the corresponding file to be authorized for display, and it may indicate which data sources in the data layer the file to be authorized for display can display. Usually, the second data source relied on by the file to be authorized for display is determined during the file configuration phase. In this way, during the phase of constructing its file display permission fingerprint, it can be determined in combination with the system's permission management structure for the data source. The present application does not limit the construction method and representation method of this file display permission fingerprint, and it can be determined according to the situation.
[0080] It should be understood that the representation methods of the above-mentioned file display permission fingerprint and user permission fingerprint in the present application are the same, so as to perform operations on the two permission fingerprints subsequently to obtain the required data authorization information. For example, both of these permission fingerprints can adopt the binary number representation method. 1 can indicate that the user to be authorized / the file to be authorized for display has permission for the corresponding data source; conversely, 0 can indicate that the user to be authorized / the file to be authorized for display does not have permission for the corresponding data source, but it is not limited to this representation method.
[0081] In addition, the above-mentioned second data source and the first data source both represent a type of data source. Usually, each of them contains multiple data sources, and there is at least one identical data source between the second data source and the first data source. In this way, the user can view the corresponding data in the corresponding file to be authorized for display, such as viewing the authorized data of a certain data source in the form of a report.
[0082] Step S14: Compare the user permission fingerprint with the file display permission fingerprint, and obtain the data authorization information of the user to be authorized on the file to be authorized for display according to the comparison result.
[0083] Combined with the above descriptions of the respective contents represented by the user permission fingerprint and the file display permission fingerprint, by comparing the user permission fingerprint with the file display permission fingerprint, it can be determined which second data sources relied on by the file to be authorized for display the user to be authorized has permission for, that is, the data sources included in both the first data source and the second data source, and it can also be determined which second data sources relied on by the file to be authorized for display the user to be authorized does not have permission for. Subsequently, the user cannot view this type of data in the file to be authorized for display.
[0084] Based on this, in the scenario where a user requests to access data from a certain second data source of a file to be authorized for display, in order to conveniently, efficiently, and reliably verify whether the user has the processing permission for the data in the file to be authorized for display, this application can construct the data authorization information of the user to be authorized for the file to be authorized for display based on the comparison result of the user permission fingerprint and the file display permission fingerprint described above. The data authorization information indicates which second data source data on the file to be authorized for display the user to be authorized has the processing permission for. In this way, in the above data access scenario, permission verification can be performed based on this data authorization information.
[0085] In summary, in the embodiment of this application, in the case where a user to be authorized applies for data permissions at the data layer, during the process of the server responding to the received data permission application request, in addition to obtaining the user permission fingerprint of the user to be authorized for the first data source, the file display permission fingerprint of the file to be authorized for display associated with the first data source will also be obtained, thereby indicating the data sources for which the user to be authorized has permissions at the data layer, and the data sources for which the file to be authorized for display has permissions at the data layer. After that, based on the comparison result of these two permission fingerprints, the data authorization information of the user to be authorized for the file to be authorized for display can be obtained. It can be seen that the user only needs to apply for data permissions once at the data layer to obtain the data permissions for the display file, which simplifies the data permission application steps, shortens the approval cycle, reduces the risk of data leakage caused by human errors, improves the data permission authorization efficiency, and reduces the later operation and maintenance workload.
[0086] Refer to Figure 2 , which is a schematic flowchart of another optional example of the data permission processing method proposed in this application. This embodiment can be an optional refined implementation method of the data permission processing method described above, but is not limited to the refined implementation method described in this embodiment. Still taking the server executing this refined implementation method as an example for illustration. As Figure 2 shown, the data permission processing method may include:
[0087] Step S21, obtain a data permission application request for the data layer;
[0088] Step S22, respond to the data permission application request and determine the first data source authorized by the user to be authorized at the data layer;
[0089] Step S23, obtain the bitmap dictionary of the permission data structure for the data layer;
[0090] In the embodiments of the present application, the bitmap dictionary may be a one-dimensional data structure composed of basic permission fields of different data sources in the data permission structure of the data layer. Among them, the basic permission field may refer to the leaf permission field in the permission data structure of the data layer, that is, a type of permission field that does not depend on other permission fields. The data permission structure refers to a non-linear data structure constructed based on the dependency relationship between each permission field of each data source on the data layer.
[0091] Exemplarily, as Figure 3 shown in the tree structure, it is a complex application scenario of the UDS (Unified Diagnostic Services) data platform, which includes various scenarios of cross-granularity of fine and coarse permission granularities. For example, for individual fields under the UDS data platform, fine-grained control is configured for different scopes or departments, that is, the dependency relationship between permission fields at different levels is configured. For example, Figure 3 the higher the level (i.e., the closer to the root node), the larger the corresponding permission control scope, or the higher the permission control level, and it can implement the permission control of the next-level child nodes. Therefore, the permission control scope of the parent node can be reflected by the permission control scopes of its included child nodes, or it can be said that the parent node depends on the child nodes.
[0092] Based on the permission data structure as Figure 3 shown, after unfolding and flattening it, all the leaf nodes it contains can be extracted to construct a one-dimensional linear data structure bitmap dictionary, as Figure 4 shown. During the extraction of leaf nodes, tree traversal algorithms such as recursion can be used to determine whether each node in the permission data structure has leaf nodes. If it has leaf nodes, the leaf nodes it has can be extracted.
[0093] In some embodiments, the present application can implement the judgment of whether there are leaf nodes through but not limited to the following code, and can arrange and combine permission fields according to the time complexity, control the time complexity (which can quantitatively represent the running time of the algorithm) within O(n)–O(nlogn), and through verification, a time complexity of O(1) and a space complexity of O(n) can be obtained, improving the permission processing efficiency.
[0094] Flatten({
[0095] Key1:{
[0096] keyA:'valueⅠ'
[0097] },
[0098] Key2:{
[0099] keyB:'valueⅡ'
[0100] },
[0101] Key3: {a: {b: {c: 2}}}
[0102] )
[0103] It should be understood that in data management systems for different scenarios, the permission data structures corresponding to their data layers often vary. The content and quantity of each basic permission field included in the permission data structure will all have differences. For the one-dimensional data structure constructed based on these basic permission fields, that is, the content of the bitmap dictionary may be different, but the construction method of the bitmap dictionary is similar. This application does not limit the content and its construction method of the bitmap dictionary of the data permission structure corresponding to the data layer in different scenarios, and it can be determined according to the situation. This application takes Figure 4 the bitmap dictionary of the data warehouse shown as an example for illustration. And for the above permission data structure, it includes but is not limited to Figure 3 the tree structure shown.
[0104] In some other embodiments proposed by this application, the names of the leaf permission fields in the permission data structure may be the same, which will affect the reliability and accuracy of the constructed weight fingerprint. In this regard, during the construction of the bitmap dictionary in this application, it is possible to detect whether there are multiple basic permission fields with the same name in the permission data structure of the data layer; if not, the bitmap dictionary can be constructed in the manner described above; if so, it is possible to obtain the permission fields on which each of the multiple basic permission fields with the same name depends (that is, the parent permission field of this basic permission field), and the path information between them and the corresponding basic permission field; thus, based on the basic permission fields of each data source included in this data layer and this path information, a bitmap dictionary with a one-dimensional data structure is constructed. In this way, during the construction of the permission fingerprint, not only the basic permission fields need to be compared, but also their path information, that is, their parent permission fields, need to be compared simultaneously to determine whether the corresponding bit is 1 or 0. The implementation process is similar to the permission fingerprint construction process described above, and this application will not elaborate.
[0105] Step S24, detect whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the first data source, and obtain the first detection result of the corresponding permission fields;
[0106] Step S25, generate a user permission fingerprint for the user to be authorized for the first data source according to the first detection results of each permission field included in the bitmap dictionary;
[0107] Combined with the above description of the permission fingerprint, the present application can represent the user permission fingerprint using binary numbers, where 1 and 0 respectively represent that there is an authorization management relationship and no authorization management relationship between each permission field in the bitmap dictionary and the first data source, that is, it represents that the user to be authorized has permission and no permission for the data source corresponding to each permission field in the bitmap dictionary. Therefore, the above first detection result can include two types: having an authorization management relationship and not having an authorization management relationship. In this way, according to the sorting of each permission field in the bitmap dictionary, the sorting of the corresponding first detection result is determined, and the sorting result of the first detection result is represented by the corresponding character (1 or 0), and the user permission fingerprint of the user to be authorized for the first data source can be obtained.
[0108] Exemplarily, still taking the Figure 3 permission data structure and Figure 4 the bitmap dictionary shown above as an example for illustration. As Figure 3 shown in the data structure, the CEO can control each country and region; from the perspective of the control range of the space set Segment used by the database object, it can include Consumer, SMB, and Commercial; from the perspective of the enterprise BG scope, it can include the PCSD and DCG. The PCSD can be further divided into Laptop and Desktop. The Laptop can include models such as TP Yoga, TP X, and TP X1. The TP X1 model can include several models such as X1Fold, X1Gen8, and X1Gen9.
[0109] Assume that the permission fields having an authorization management relationship with the first data source include LA, JP, Consumer, TP Yoga, and X1Gen8. Referring to Figure 5 the leaf nodes with a gray background shown, compare them sequentially with Figure 4 each permission field included in the bitmap dictionary shown. If the permission field of the current bit does not belong to these several permission fields, the permission fingerprint of this bit can be recorded as 0; conversely, if the permission field of the current bit does not belong to these several permission fields, the permission fingerprint of this bit can be recorded as 1. After comparison, the user permission fingerprint can be obtained as "0101001001001000".
[0110] It can be understood that since the permission data structure and the content of its bitmap dictionary in other scenarios may be different, and the categories of the first data sources authorized by different users to be authorized may be different, according to the processing method described above, the content of the corresponding user permission fingerprint obtained may change, and the present application does not make an exhaustive description. And for the content of the permission data structure in the above scenario, including but not limited to the above Figure 3The content shown can be adaptively adjusted according to the actual scenario.
[0111] Step S26, detecting whether there is an authorization management relationship between the permission field included in the bitmap dictionary and the second data source, and obtaining a second detection result of the corresponding permission field;
[0112] Step S27, generating a file display permission fingerprint for the file to be authorized for display according to the second detection result of each permission field contained in the bitmap dictionary;
[0113] The process of obtaining the file display permission fingerprint is similar to the process of obtaining the user permission fingerprint mentioned above. Figure 6 As shown, it is assumed that the permission fields that have an authorization management relationship with the second data source include PRC, JP, SMB, TP Yoga, and X1Gen9. Figure 6 The leaf node with a gray background is shown. By comparing it with each permission field contained in the bitmap dictionary in sequence, it can be obtained that the file display permission fingerprint of the file to be authorized for display is "1001000101000100".
[0114] It should be noted that this application does not restrict the execution order of the user permission fingerprint construction process described in the above steps S24 and S25 and the file display permission fingerprint construction process described in steps S26 and S27, which can be determined according to the circumstances.
[0115] Moreover, the process of constructing the file display permission fingerprint described in step S26 and step S27 can be implemented in advance, such as obtaining and storing the corresponding file display permission fingerprint in the above manner at each display file release stage. In this way, when any user to be authorized initiates a data permission application request, the pre-constructed file display permission fingerprint of the file to be authorized for display can be directly retrieved.
[0116] Step S28, performing a bitwise AND operation on the characters contained in the user authority fingerprint and the file display authority fingerprint respectively, to obtain data authorization information of the user to be authorized on the file to be authorized to display.
[0117] Reference Figure 7 As shown in the flowchart, the user permission fingerprint and the file display permission fingerprint are bitwise ANDed, and then the fingerprint position where the operation result character is 1 is compared with the bitmap dictionary to determine that the permission field corresponding to the position is the target permission field, that is, the permission field to which the user to be authorized has permission under the file to be authorized for display. Based on this, the data source to which the user to be authorized has permission on the file to be authorized for display can be determined, thereby constituting the data authorization information of the user to be authorized on the file to be authorized for display. The present application does not limit the content of the data authorization information.
[0118] In some embodiments, if there are changes in the user, the authorized data source of the display file, the permission data structure, etc., such as the expansion of permission fields, the permission data structure can be directly updated. After that, the bitmap dictionary can be updated in the above manner, and the data authorization information can be updated to ensure the reliability and accuracy of data permission management.
[0119] In summary, in the scenario of the present application, the permission data structures of each data source included in the data layer are used to construct a bitmap dictionary with a linear one-dimensional structure, that is, a database bitmap dictionary. In this way, for any user to be authorized and any display file to be authorized, corresponding permission fingerprints can be automatically generated based on this bitmap dictionary, namely user permission fingerprints and file display permission fingerprints. After that, when the user applies for the processing permission of the first data source of a certain display file, the corresponding user permission fingerprint can be directly AND-operated with the file display permission fingerprint of the display file, and the bitmap dictionary can be queried to determine the target permission field of the user under the display file, thereby constituting the data authorization information of the user on the display file. In the entire permission application process, the user only needs to initiate a data permission application request once at the data layer to obtain the corresponding data authorization information, which improves the convenience and efficiency of data permission application.
[0120] Moreover, the bitmap dictionary constructed based on the permission data structure and the constructed permission fingerprints proposed in the present application are convenient for permission field expansion and maintenance, can reduce the error probability, and help improve the performance of complex nested and cross permissions. It can be open to all employees of the enterprise without additional manual configuration.
[0121] Refer to Figure 8 , which is a schematic flowchart of another optional example of the data permission processing method proposed in the present application. Based on the description of the process of obtaining the data authorization information of the user on any display file described in the above embodiments, the following embodiments will describe the process of obtaining the file display data of the display file according to the data authorization information, but it is not limited to the implementation manners described in the following embodiments. This method can still be executed by the server. As Figure 8 shown, this method may include:
[0122] Step S31, receiving a data access request sent by the user's terminal for a first display file;
[0123] In the embodiments of the present application, the user can complete the data permission application as a user to be authorized in the manner described in the above embodiments. After obtaining the data authorization of the first display file (that is, any type of visualization file, such as a sales data report of a certain product in a certain area), in a certain application scenario, if the user needs to view the data of the first display file, the user can send a data access request for the first display file to the server through the terminal.
[0124] Among them, the above data access request may carry the device identifier of the terminal, the user identifier, the file identifier of the first display file, the data source type to be accessed, etc. This application does not limit the content included in the data access request and can be determined according to the situation.
[0125] Step S32: Retrieve the first data authorization information for the user regarding the first display file.
[0126] Regarding the process of obtaining the first data authorization information for the user as the user to be authorized regarding the first display file, reference can be made to the description of the corresponding part of the above embodiment in this application, and details are not described herein. In practical applications, each data authorization information can be associated and stored with information such as the user identifier of the corresponding user and the file identifier of the display file to be authorized. In this way, during the process of retrieving the first data authorization information, the relevant data authorization information can be selected as the first data authorization information from the stored data authorization information according to the information such as the user identifier and file identifier included in the data access request, but it is not limited to this retrieval implementation method.
[0127] In some other embodiments proposed in this application, after the server obtains the data access request, it can also retrieve the user permission fingerprint corresponding to the authorized user and the file display permission fingerprint corresponding to the first display file, and perform an AND operation online to obtain the first data authorization information. This application does not limit the method of obtaining the first data authorization information.
[0128] Step S33: Respond to the data access request and obtain the first file display data that meets the first data authorization information.
[0129] Step S34: Feed back the first file display data to the terminal of the user for display.
[0130] Combined with the above description of the data authorization information, it can be known through the first data authorization information which data sources of the first display file the user has access rights to. The data of the data sources with access rights can be determined as the first file display data, or the first file display data can be constructed, such as the data in various report formats listed above, and sent to the terminal, which will be displayed in the format of the first display file. This application does not limit the display method of the first file display data and can be determined according to the situation.
[0131] It can be seen that in the embodiments of the present application, when a user needs to view the data in a certain display file, the data authorization information of the user under the display file pre-constructed can be directly used to verify which data source data the user has access rights to under the display file, determine the file display data with access rights, and feedback it to the user terminal for display, so that the user can view the data with access rights in the display file. For example, the user can obtain the report data with access rights in Report A, and the output Report A includes the report data with access rights. There is no need for the user to apply to the file display layer for the data processing permission of the display file again.
[0132] Referring to Figure 9 , which is a schematic flowchart of another optional example of the data permission processing method proposed in the present application. Based on the description of the process of obtaining the data authorization information of the user on any display file described in the above embodiments, this embodiment can illustrate the data permission processing method proposed in the present application for the scenario where the user queries the display file for a certain data source (denoted as the third data source). This method can still be executed by the server, such as Figure 9 shown, the method may include:
[0133] Step S41, receiving a display file query request sent by the user's terminal for the third data source;
[0134] Among them, the third data source can be any one or more data sources on the data layer, usually one or more data sources authorized to the user. The content of this data source is not limited in the present application, such as the sales data source of a certain product in a certain country or region.
[0135] In the embodiments of the present application, when the user does not know the display file corresponding to the third data source, a display file query request for the third data source can be directly sent to the server to request to view the data of the third data source in a visual display manner. The display file query request may include, but is not limited to, the user identification of the user, the third data source identification, and the like.
[0136] Step S42, screening out the second data authorization information associated with the third data source from the data authorization information of the user on different display files;
[0137] Regarding the process of obtaining the data authorization information of the user as the user to be authorized for the display file, reference can be made to the corresponding part of the above embodiments, and the present application will not elaborate here. After the server parses the display file query request to obtain request information such as the user identification and the third data source identification, the data authorization information associated with the request information can be screened out from the data authorization information on different display files, denoted as the second data authorization information. The specific screening implementation process is not limited in the present application.
[0138] Step S43: In response to the display file query request, obtain the third data source file display data that complies with any second data authorization information.
[0139] Step S44: Feed back the third data source file display data to the user's terminal for display.
[0140] In practical applications, for the third data sources authorized to the user, there may be one or more display files that also have the processing permission for the third data source. For different display files, there is a corresponding second data authorization information. Subsequently, in combination with the above-described method for obtaining file display data, the corresponding third data source data can be obtained according to each second data authorization information, and the display mode of this data is the same as that of the corresponding display file. Therefore, the multiple third data source file display data obtained in this application can have one or more display modes, and this application does not limit this, which can be determined according to the situation.
[0141] After that, when the server feeds back one or more third data source file display data obtained to the user terminal for display, the corresponding file display mode can be adopted to display the third data source file display data. For example, the same content data can be displayed in multiple display modes, and the display process is not described in detail in this application.
[0142] Based on the content described in the above embodiments, after the user completes the data permission application at the data layer and obtains the data authorization information of the data layer and the file display layer, it can be loaded to the file display layer so that in the data access or query scenarios of the above embodiments, the file display layer can accordingly retrieve the corresponding file display data, realizing non-invasive BI layer business code and realizing BI permission control without perception. Combining a large number of BI tool mechanisms, this application proposes but is not limited to the implementation methods described in the following embodiments.
[0143] Refer to Figure 10 , which is a schematic flowchart of another optional example of the data permission processing method proposed in this application. This method can be executed by the server, and for the process of obtaining the user permission fingerprint and the file display permission fingerprint, reference can be made to the corresponding part of the above embodiments, which will not be elaborated in this embodiment. As Figure 10 shown, this method may include:
[0144] Step S51: Obtain the target permission field corresponding to the authorized data source in both the user permission fingerprint and the file display permission fingerprint.
[0145] Step S52: Generate the permission processing logic for the user to be authorized on the display file to be authorized based on the target permission field.
[0146] Step S53: Embed the permission processing logic into the file display processing logic of the file to be authorized for display.
[0147] In the actual application of this application, for a system with a permission filtering function in the BI layer (i.e., the file display layer), the method of embedding scripts can be adopted, such as the DAX script of Power BI, and the data authorization information of each user for each display file obtained is embedded into the file display processing logic of the corresponding display file.
[0148] Therefore, after obtaining any data authorization information in the above manner, it can be converted into a permission processing logic that meets the system requirements according to the system requirements, and then, as a general SDK (Software Development Kit) code block, it is embedded into the corresponding display file logic, as Figure 11 shown. Therefore, the file display processing logic can be used to implement the permission verification for data access requests or display file query requests. When the verification is passed, the corresponding file display data is retrieved from the data layer. The process of data display implementation can refer to the description of the corresponding part of the above embodiment, and this embodiment will not be elaborated.
[0149] In some other embodiments proposed in this application, as Figure 12 shown, for a system directly implemented with programming languages such as SQL (Structured Query Language), this application can also use flow control statements or an abstract syntax tree AST to compile the code to ensure that the file display layer can implement permission verification based on data authorization information.
[0150] In this case, as Figure 12 shown, this application can add a permission proxy layer between the file display layer and the data layer to implement the permission verification for data access requests or file query requests. When the verification is passed, the corresponding file display data is retrieved from the data layer. Based on this, when the server obtains the user permission fingerprint and the file display permission fingerprint, and at the same time represents the target permission field corresponding to the authorized data source, it can configure the permission processing proxy layer located between the file display layer and the data layer according to the target permission field. Regarding the process of how the permission processing proxy layer implements permission verification, it can refer to the description of the corresponding part of the above embodiment, and this embodiment will not be elaborated.
[0151] Referring to Figure 13 , it is a schematic structural diagram of an optional example of the data permission processing device proposed in this application. The device may include:
[0152] A data permission application request acquisition module 11, configured to acquire a data permission application request for the data layer;
[0153] A user permission fingerprint obtaining module 12, which is configured to respond to the data permission application request, determine a first data source authorized by the user to be authorized on the data layer, and obtain a user permission fingerprint of the user to be authorized for the first data source;
[0154] A file display permission fingerprint obtaining module 13, which is configured to obtain a file display permission fingerprint of a file to be authorized for display associated with the first data source;
[0155] Wherein, the file display permission fingerprint is constructed based on a second data source in the data layer authorized for the file to be authorized for display during the publishing process of the file to be authorized for display, and there is at least one same data source between the second data source and the first data source;
[0156] A data authorization information obtaining module 14, which is configured to compare the user permission fingerprint with the file display permission fingerprint, and obtain data authorization information of the user to be authorized on the file to be authorized for display according to the comparison result.
[0157] Optionally, the above-mentioned data authorization information obtaining module 14 may include:
[0158] An AND operation unit, which is configured to perform a bitwise AND operation on the characters included in the user permission fingerprint and the file fingerprint respectively, and obtain data authorization information of the user to be authorized on the file to be authorized for display.
[0159] In some embodiments proposed in the present application, the above-mentioned data permission processing device may further include:
[0160] A bitmap dictionary obtaining module, which is configured to obtain a bitmap dictionary of the permission data structure of the data layer;
[0161] Wherein, the bitmap dictionary is a one-dimensional data structure composed of basic permission fields of different data sources in the permission data structure; the basic permission field refers to the leaf permission field in the permission data structure.
[0162] Optionally, the above-mentioned device may further include:
[0163] A detection module, which is configured to detect whether there are multiple basic permission fields with the same name in the permission data structure of the data layer;
[0164] A path information obtaining module, which is configured to obtain path information between each permission field on which multiple basic permission fields with the same name depend and the corresponding basic permission field when the detection result of the detection module is yes;
[0165] A bitmap dictionary construction module, which is used to construct a bitmap dictionary with a one-dimensional data structure according to the basic permission fields of each data source included in the data layer and the path information.
[0166] Based on this, the above user permission fingerprint obtaining module 12 may include:
[0167] A first detection unit, which is used to detect whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the first data source, and obtain a first detection result of the corresponding permission field;
[0168] A user permission fingerprint generation unit, which is used to generate a user permission fingerprint of the to-be-authorized user for the first data source according to the first detection results of the respective permission fields included in the bitmap dictionary;
[0169] The above file display permission fingerprint obtaining module 13 may include:
[0170] A second detection unit, which is used to detect whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the second data source, and obtain a second detection result of the corresponding permission field;
[0171] A file display permission fingerprint generation unit, which is used to generate a file display permission fingerprint for the to-be-authorized display file according to the second detection results of the respective permission fields included in the bitmap dictionary.
[0172] In some other embodiments proposed in this application, the above data permission processing device may further include:
[0173] A data access request receiving module, which is used to receive a data access request sent by the terminal of the to-be-authorized user for the first display file;
[0174] A first data authorization information retrieval module, which is used to retrieve first data authorization information for the to-be-authorized user for the first display file;
[0175] A first file display data acquisition module, which is used to respond to the data access request and acquire first file display data that conforms to the first data authorization information;
[0176] A first file display data transmission module, which is used to feed back the first file display data to the terminal for display.
[0177] In some other embodiments proposed in this application, the above data permission processing device may further include:
[0178] A display file query request receiving module, which is used to receive a display file query request sent by the terminal of the to-be-authorized user for the third data source;
[0179] The second data authorization information screening module is used to screen the second data authorization information associated with the third data source from the data authorization information of the to-be-authorized user on different display files;
[0180] The third data source file display data acquisition module is used to respond to the display file query request and acquire the third data source file display data that conforms to any of the second data authorization information;
[0181] The third data source file display data transmission module is used to feedback the third data source file display data to the terminal for display.
[0182] Based on the description of the above embodiments, the above data authorization information obtaining module 14 may include:
[0183] The first acquisition unit is used to acquire the target permission fields corresponding to the authorized data sources in both the user permission fingerprint and the file display permission fingerprint;
[0184] The permission processing logic generation unit is used to generate the permission processing logic for the to-be-authorized user on the to-be-authorized display file according to the target permission fields;
[0185] The permission processing logic embedding unit is used to embed the permission processing logic into the file display processing logic of the to-be-authorized display file;
[0186] Among them, the file display processing logic is used to implement the permission verification for the data access request or the display file query request, and in the case of successful verification, retrieve the corresponding file display data from the data layer.
[0187] In another possible implementation manner, the above data authorization information obtaining module 14 may also include:
[0188] The second acquisition unit is used to acquire the target permission fields corresponding to the authorized data sources in both the user permission fingerprint and the file display permission fingerprint;
[0189] The configuration unit is used to configure the permission processing proxy layer located between the file display layer and the data layer according to the target permission fields;
[0190] Among them, the permission proxy layer is used to implement the permission verification for the data access request or the file query request, and in the case of successful verification, retrieve the corresponding file display data from the data layer.
[0191] It should be noted that all kinds of modules, units, etc. in the above device embodiments can be stored in the memory as program modules, and the processor executes the above program modules stored in the memory to implement corresponding functions. For the functions implemented by each program module and its combination, and the achieved technical effects, reference can be made to the description of the corresponding parts of the above method embodiments, which will not be elaborated in this embodiment.
[0192] This application also provides a computer-readable storage medium on which a computer program can be stored. The computer program can be called and loaded by a processor to implement each step of the data permission processing method described in the above embodiments.
[0193] Referring to Figure 14 , it is a schematic hardware structure diagram of an optional example of a computer device applicable to the data permission processing method proposed in this application. The computer device can be a server, such as an independent physical server, a server cluster composed of multiple physical servers, or a cloud server capable of implementing cloud computing, etc. In some embodiments, the computer device can also be an electronic device with certain data processing capabilities, such as a desktop computer, a robot, etc. This application takes the computer device being a server as an example for illustration. As Figure 14 shown, the computer device can include: at least one memory 21 and at least one processor 22, where:
[0194] The memory 21 can be used to store the program for implementing the data permission processing method described in the above method embodiments; the processor 22 can load and execute the program stored in the memory to implement each step of the data permission processing method described in the above corresponding method embodiments. The specific implementation process can refer to the description of the corresponding parts of the above embodiments and will not be elaborated.
[0195] In practical applications, the memory 21 and the processor 22 can be connected to a communication bus, and data interaction between them and other structural components of the computer device can be achieved through this communication bus, which can be determined according to actual needs and will not be elaborated in this application.
[0196] In the embodiments of the present application, the memory 21 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device or other volatile solid-state storage devices. The processor 22 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, etc. The present application does not limit the structures and models of the above-mentioned memory 21 and processor 22, and can be flexibly adjusted according to actual needs.
[0197] It should be understood that Figure 14 the structure of the computer device shown does not constitute a limitation on the computer device in the embodiments of the present application. In actual applications, the computer device may include more Figure 14 components than those shown, or combine some components, which are not listed one by one in the present application.
[0198] Finally, it should be noted that in the above embodiments, unless the context clearly indicates an exception, the words "a", "one", "kind" and / or "the" do not specifically refer to the singular, but may also include the plural. Generally speaking, the terms "include" and "comprise" only indicate the inclusion of the clearly identified steps and elements, and these steps and elements do not constitute an exclusive list. The method or device may also include other steps or elements. An element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, commodity or device including the element.
[0199] Among them, in the description of the embodiments of the present application, unless otherwise specified, " / " means "or". For example, A / B may mean A or B; the "and / or" herein is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B may mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present application, "a plurality of" means two or more than two.
[0200] Terms involved in the present application, such as "first", "second", etc., are only used for descriptive purposes, to distinguish one operation, unit or module from another operation, unit or module, and do not necessarily require or imply any such actual relationship or order between these units, operations or modules. And it cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.
[0201] In addition, the various embodiments in this specification are described in a progressive or parallel manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the embodiments can be referred to each other. For the devices and computer equipment disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description in the method section.
[0202] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data permission processing method, the method comprises: obtaining a data permission application request for a data layer; responding to the data permission application request, determining a first data source authorized by a user to be authorized on the data layer, and obtaining a user permission fingerprint of the user to be authorized for the first data source; obtaining a file display permission fingerprint of a display file to be authorized associated with the first data source; wherein the file display permission fingerprint is constructed based on a second data source in the data layer authorized for the display file to be authorized during the publishing process of the display file to be authorized, and there is at least one identical data source between the second data source and the first data source; comparing the user permission fingerprint with the file display permission fingerprint, and obtaining data authorization information of the user to be authorized on the display file to be authorized according to the comparison result.
2. The method according to claim 1, wherein the comparing the user permission fingerprint with the file display permission fingerprint, and obtaining data authorization information of the user to be authorized on the display file to be authorized according to the comparison result comprises: performing a bitwise AND operation on the characters included in the user permission fingerprint and the file display permission fingerprint respectively to obtain data authorization information of the user to be authorized on the display file to be authorized.
3. The method according to claim 1, the method further comprises: receiving a data access request sent by a terminal of the user to be authorized for a first display file; retrieving first data authorization information for the user to be authorized for the first display file; responding to the data access request, and obtaining first file display data conforming to the first data authorization information; feeding back the first file display data to the terminal for display.
4. The method according to claim 1, the method further comprises: receiving a display file query request sent by a terminal of the user to be authorized for a third data source; screening second data authorization information associated with the third data source from the data authorization information of the user to be authorized on different display files; responding to the display file query request, and obtaining third data source file display data conforming to any of the second data authorization information; feeding back the third data source file display data to the terminal for display.
5. The method according to claim 1 or 2, the method further comprises: obtaining a bitmap dictionary of a permission data structure of the data layer; wherein the bitmap dictionary is a one-dimensional data structure composed of basic permission fields of different data sources in the permission data structure; the basic permission field refers to a leaf permission field in the permission data structure; the obtaining the user permission fingerprint of the user to be authorized for the first data source comprises: detecting whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the first data source, and obtaining a first detection result of the corresponding permission field; generating the user permission fingerprint of the user to be authorized for the first data source according to the first detection results of the respective permission fields included in the bitmap dictionary; the construction process of the file display permission fingerprint comprises: Detect whether there is an authorization management relationship between the permission fields included in the bitmap dictionary and the second data source, and obtain the second detection result of the corresponding permission field; Generate a file display permission fingerprint for the file to be authorized for display according to the second detection results of the respective permission fields included in the bitmap dictionary.
6. The method according to claim 3 or 4, wherein obtaining the data authorization information of the user to be authorized on the file to be authorized for display according to the comparison result comprises: Obtain the target permission fields corresponding to the authorized data sources simultaneously represented in the user permission fingerprint and the file display permission fingerprint; Generate a permission processing logic for the user to be authorized on the file to be authorized for display according to the target permission fields; Embed the permission processing logic into the file display processing logic of the file to be authorized for display; the file display processing logic is used to implement permission verification for a data access request or a display file query request, and in the case of successful verification, retrieve the corresponding file display data from the data layer.
7. The method according to claim 3 or 4, wherein obtaining the data authorization information of the user to be authorized on the file to be authorized for display according to the comparison result comprises: Obtain the target permission fields corresponding to the authorized data sources simultaneously represented in the user permission fingerprint and the file display permission fingerprint; Configure a permission processing proxy layer located between the file display layer and the data layer according to the target permission fields; the permission processing proxy layer is used to implement permission verification for a data access request or a display file query request, and in the case of successful verification, retrieve the corresponding file display data from the data layer.
8. The method according to claim 5, the method further comprises: Detect whether there are multiple basic permission fields with the same name in the permission data structure of the data layer; If so, obtain the path information between the respective dependent permission fields of the multiple basic permission fields with the same name and the corresponding basic permission fields; Construct a bitmap dictionary with a one-dimensional data structure according to the basic permission fields of each data source included in the data layer and the path information.
9. A data permission processing device, the device comprises: A data permission application request acquisition module, configured to acquire a data permission application request for the data layer; A user permission fingerprint acquisition module, configured to respond to the data permission application request, determine the first data source authorized by the user to be authorized on the data layer, and obtain the user permission fingerprint of the user to be authorized for the first data source; A file display permission fingerprint acquisition module, configured to acquire the file display permission fingerprint of the file to be authorized for display associated with the first data source; wherein, the file display permission fingerprint is constructed according to the second data source in the data layer authorized for the file to be authorized for display during the publishing process of the file to be authorized for display, and there is at least one same data source between the second data source and the first data source; A data authorization information obtaining module, configured to compare the user permission fingerprint with the file display permission fingerprint, and obtain the data authorization information of the to-be-authorized user on the to-be-authorized display file according to the comparison result.
10. A computer device, the computer device comprises: at least one memory and at least one processor, wherein: the memory is configured to store the program of the data permission processing method according to any one of claims 1 to 8; the processor is configured to load and execute the program in the memory to implement the data permission processing method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Processing method for index application, server, and storage medium
CN109146397A
Platform-based data processing method, system and device and storage medium
CN110619226A