A rights management method and device
By obtaining user login data and determining their permission data, the operation and maintenance resource management system realizes accurate permission control over users and resources, solving the problem that existing systems cannot achieve accurate permission management, and improving the security and standardization of the system.
Patent Information
- Application Number
- CN202111050683.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2041-09-08
AI Technical Summary
The operation and maintenance resource management system cannot achieve accurate authority control over users and operation and maintenance resource data, resulting in difficulty in ensuring security and standardization.
By obtaining user login data, the user's first permission data and the second permission data are determined. The first permission data includes the association relationship between roles, menus, and controls, and the second permission data includes the association relationship between applications, nodes, modules, and processes, thereby displaying the target interface and realizing accurate permission control.
It improves the security and standardization of the operation and maintenance resource management system, ensures that users' operation permissions on resources are more accurate, and reduces the security risks and the possibility of errors or non-compliant operations.
Smart Images

Figure CN113779551B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of Internet technology, and in particular, to a permission management method and device. Background Art
[0002] With the expansion of computer applications and the emergence of various needs, the background management of computer systems requires different permissions to be granted to different users to achieve permission management for users to view and operate data.
[0003] For example, in order to meet the requirements of security and standardization, user management and user rights management are indispensable parts of the operation and maintenance resource management system used by operation and maintenance personnel in the banking industry. The rights management of the operation and maintenance resource management system generally associates users with roles, roles with menus, and menus with buttons under the menus, thereby accurately controlling the rights of the operation and maintenance resource management system at the menu and button levels.
[0004] However, the above permission design results in different users who are matched to the same role having the same permissions for different resource data corresponding to the role classification. For example, suppose user A and user B log in to the operation and maintenance resource management system, and the system recognizes that both user A and user B can be matched to role 1. Among them, the system permissions of role 1 on the resource data management page include viewing and modifying the resource data on the page. Then, user A and user B both have the system permissions corresponding to role 1 on the resource data management page, and the operation and maintenance resource management system cannot achieve more precise permission control management. Summary of the invention
[0005] The present application provides a permission management method and device, which solves the problem that the operation and maintenance resource management system cannot accurately control and manage the permissions of users and operation and maintenance resource data.
[0006] In a first aspect, the present application provides a permission management method, the method comprising: obtaining user login data, and determining first permission data and second permission data corresponding to the user login data according to the user login data. The first permission data includes a first association relationship corresponding to a role, a menu, and a control; the second permission data includes a second association relationship corresponding to an application, a node, a module, and a process. Finally, according to the first permission data and the second permission data, a target interface is displayed.
[0007] In one possible implementation, the user login data corresponds to a first user, and the first association relationship includes: a first target association relationship between a first role corresponding to the first user and a first menu in which the first role has first operating permissions, and / or a second target association relationship between the first role and a first control in the first menu in which the first role has second operating permissions.
[0008] In one possible implementation, the user login data corresponds to the first user, and the second association relationship includes one or more of the following: a third target association relationship between the first user and a first application for which the first user has third operating permissions, a fourth target association relationship between the first user and a first node for which the first user has fourth operating permissions, a fifth target association relationship between the first user and a first module for which the first user has fifth operating permissions, and a sixth target association relationship between the first user and a first process for which the first user has sixth operating permissions.
[0009] In one possible implementation, the first operation permission, or the second operation permission, or the third operation permission, or the fourth operation permission, or the fifth operation permission, or the sixth operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission.
[0010] In a possible implementation manner, the method further includes: saving the first permission data and the second permission data in a preset saving location.
[0011] In a possible implementation, the method further includes: after detecting a first operation of the user on the first target interface, determining a second target interface corresponding to the first operation according to the first permission data and the second permission data, and displaying the second target interface.
[0012] In the above scheme, the electronic device obtains the user login data, and determines the first permission data and the second permission data corresponding to the user login data according to the user login data. Among them, the first permission data includes the first association relationship corresponding to the role, menu, and control; the second permission data includes the second association relationship corresponding to the application, node, module, and process. Finally, according to the first permission data and the second permission data, the target interface is displayed. In this way, the preset first permission data and the second permission data at the same time will have more accurate permission control over users and resources in the operation and maintenance resource management system, thereby preventing security risks, mistakes or non-compliant operations.
[0013] In a second aspect, the present application provides a permission management device, including: an acquisition module, a processing module and a display module. The acquisition module is used to acquire user login data. The processing module is used to determine the first permission data and the second permission data corresponding to the number of user logins according to the user login data. The first permission data includes the first association relationship corresponding to the role, menu, and control; the second permission data includes the second association relationship corresponding to the application, node, module, and process. The display module is used to display the first target interface according to the first permission data and the second permission data.
[0014] In one possible implementation, the user login data corresponds to a first user, and the first association relationship includes: a first target association relationship between a first role corresponding to the first user and a first menu in which the first role has first operating permissions, and / or a second target association relationship between the first role and a first control in the first menu in which the first role has second operating permissions.
[0015] In one possible implementation, the user login data corresponds to the first user, and the second association relationship includes one or more of the following: a third target association relationship between the first user and a first application for which the first user has third operating permissions, a fourth target association relationship between the first user and a first node for which the first user has fourth operating permissions, a fifth target association relationship between the first user and a first module for which the first user has fifth operating permissions, and a sixth target association relationship between the first user and a first process for which the first user has sixth operating permissions.
[0016] In one possible implementation, the first operation permission, or the second operation permission, or the third operation permission, or the fourth operation permission, or the fifth operation permission, or the sixth operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission.
[0017] In a possible implementation, the device further includes: a storage module, configured to store the first permission data and the second permission data in a preset storage location.
[0018] In a possible implementation, the acquisition module is further used to detect a first operation of a user on a first target interface. The processing module is further used to determine a second target interface corresponding to the first operation according to the first permission data and the second permission data. The display module is further used to display the second target interface.
[0019] In a third aspect, the present application provides a rights management device, including a processor. When the rights management device is running, the processor executes computer execution instructions to enable the rights management device to perform the rights management method as described in the first aspect above.
[0020] In a fourth aspect, the present application provides a computer-readable storage medium, comprising instructions, which, when executed on a computer, enable the computer to execute the permission management method of the first aspect described above.
[0021] In a fifth aspect, the present application provides a computer program product, the computer program product includes instruction codes, and the instruction codes are used to execute the permission management method as described in the first aspect above.
[0022] The beneficial effects of the second, third, fourth, fifth aspects and various implementations of the present application can be referred to the analysis of the beneficial effects of the first aspect and various implementations thereof, and will not be repeated here.
[0023] These and other aspects of the present application will become more apparent from the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0025] Figure 1 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application;
[0026] Figure 2 A flowchart of a permission management method provided in an embodiment of the present application;
[0027] Figure 3 A schematic diagram of module interaction provided for an embodiment of the present application;
[0028] Figure 4 A schematic diagram of a first association relationship provided in an embodiment of the present application;
[0029] Figure 5 A schematic diagram of a second association relationship provided in an embodiment of the present application;
[0030] Figure 6 Interface diagram provided for the embodiment of the present application Figure 1 ;
[0031] Figure 7 Interface diagram provided for the embodiment of the present application Figure 2 ;
[0032] Figure 8 Interface diagram provided for the embodiment of the present application Figure 3 ;
[0033] Fig. 9 Interface diagram provided for the embodiment of the present application Figure 4 ;
[0034] Fig.10 Interface diagram provided for the embodiment of the present application Figure 5 ;
[0035] Fig.11 Interface diagram provided for the embodiment of the present application Figure 6;
[0036] Fig.12 Interface diagram provided for the embodiment of the present application Figure 7 ;
[0037] Fig.13 Interface diagram provided for the embodiment of the present application Figure 8 ;
[0038] Fig.14 A schematic diagram of the structure of a rights management device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0039] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0040] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.
[0041] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present application, unless otherwise specified, "plurality" means two or more.
[0042] The embodiment of the present application provides a rights management method, which can be applied to a management device 100. The management device 100 can be an electronic device or a server.
[0043] Optionally, the management device 100 may be an electronic device with a display function, such as a personal computer, a tablet computer (Pad), a laptop computer, a mobile phone, an artificial intelligence (AI) terminal, etc. The present application does not limit the specific type of the electronic device.
[0044] Optionally, the management device 100 may be a server that provides a relevant human-computer interaction interface to collect login data input by the user and display the corresponding interface. The management device 100 may be a device or server with computing functions such as a cloud server or a network server. The management device 100 may be a server, a server cluster consisting of multiple servers, or a cloud computing service center.
[0045] like Figure 1 As shown, the electronic device in the embodiment of the present application may be a management device 100. The following takes the management device 100 as an example to specifically describe the embodiment. It should be understood that the management device 100 shown in the figure is only an example of the above electronic device, and the management device 100 may have more Figure 1 More or fewer components may be shown, two or more components may be combined, or there may be a different configuration of components.
[0046] Reference Figure 1 , the management device 100 can communicate with other electronic devices 104 and a server 106. The management device 100 may include a bus 110, a processor 120, a memory 130, a user input module 150, a display module 160, a communication interface 170, and other similar and / or suitable components.
[0047] The bus 110 may be a circuit that connects the above elements to each other and transfers communications (eg, control messages) between the above elements.
[0048] The processor 120 may receive commands from the other components described above (eg, the memory 130, the user input module 150, the display module 160, the communication interface 170, etc.) via the bus 110, may interpret the received commands, and may perform calculations or data processing according to the interpreted commands.
[0049] The memory 130 may store commands or data received from the processor 120 or other elements (eg, the user input module 150 , the display module 160 , the communication interface 170 , etc.) or commands or data generated by the processor 120 or other elements.
[0050] The memory 130 may include programming modules, such as a kernel 131, middleware 132, an application programming interface (API) 133, and an application 134. Each of the above programming modules may be implemented using software, firmware, hardware, or a combination of two or more thereof, which is not specifically limited in the embodiments of the present application.
[0051] The kernel 131 may control or manage system resources (e.g., bus 110, processor 120, memory 130, etc.) for executing operations or functions implemented by other programming modules (e.g., middleware 132, API 133, and application 134). In addition, the kernel 131 may provide an interface that can access and control or manage various elements of the management device 100 by using the middleware 132, API 133, or application 134.
[0052] The middleware 132 may be configured to operate between the API 133 or the application 134 and the kernel 131 in a manner in which the API 133 or the application 134 communicates with the kernel 131 and exchanges data therewith. For example, the middleware 132 may be configured as an intermediary for communicating between the API 133 or the application 134 and the kernel 131. In addition, for example, with respect to work requests received from one or more applications 134 and / or the middleware 132, load balancing of work requests may be performed by using a method of assigning a priority to at least one of the one or more applications 134 (wherein system resources (e.g., bus 110, processor 120, memory 130, etc.) of the management device 100 may be used according to the priority).
[0053] The API 133 is an interface through which the application 134 can control functions provided by the kernel 131 or the middleware 132 , and may include, for example, at least one interface or function for file control, window control, image processing, character control, and the like.
[0054] Applications 134 may include, for example, home page applications, multimedia message service (MMS) applications, instant messaging (IM) applications, browser applications, e-mail applications, calendar applications, media player applications, photo album applications, clock applications, and any other suitable and / or similar applications.
[0055] The user input module 150 may receive commands or data (such as login data, commands for editing data, etc.) input from a user via an input-output means (e.g., a keyboard, a mouse, etc.), and may transmit the received commands or data to the processor 120 or the memory 130 via the bus 110. The display module 160 may display videos, images, data, etc. to the user.
[0056] The display module 160 may display various information (eg, multimedia data, text data) received from the above elements.
[0057] The communication interface 170 may communicate with other electronic devices 104 , the server 106 , etc. through the network 162 . For example, the communication interface 170 may be operable to connect the management device 100 to the network 162 .
[0058] In order to achieve more accurate authority control of the operation and maintenance resources of the user by the operation and maintenance resource management system, the authority management method provided in the embodiment of the present application can determine the same or different authority data of each user based on the login data of different users obtained. Among them, the electronic device can grant the user the operation authority of the menu and controls in the operation and maintenance resource management system and the operation authority of specific resources according to the authority data, and display the corresponding interface. Thereby improving the security and standardization of the operation and maintenance resource management system and enhancing the user's experience.
[0059] Exemplarily, the following takes the management device 100 as an electronic device, an operation and maintenance resource management system installed in the management device 100, and the need to perform permission management on the user who logs in to the operation and maintenance resource management system as an example to illustrate the permission management method provided in the embodiment of the present application. It is understandable that the permission management method provided in the embodiment of the present application can also be applied to other systems that require permission management, which will not be described in detail in the embodiment of the present application.
[0060] Figure 2 A flowchart of a permission management method provided in an embodiment of the present application. Figure 2 As shown, the permission management method includes the following steps.
[0061] S201. The electronic device obtains user login data.
[0062] In some embodiments, the user login data includes, for example, the user's account and password. The electronic device receives the user login data input by the user, identifies the user's identity, and determines whether the user has system login authority. If the user account and the corresponding password are correct, it can be determined that the user has system login authority. Afterwards, the user's authority can be further determined. Figure 3 As shown, after the front-end computing framework receives the user login data input by the user in the display module, the user login data is sent to the back-end computing framework.
[0063] Among them, the display module can display the World Wide Web (Web) page to collect the login data entered by the user. The front-end computing framework can be, for example, a Vue framework. In order to improve development efficiency, from a development perspective, the system is divided into the front-end and the back-end, the front-end is responsible for page interaction and data display, and the back-end is responsible for processing data and returning data corresponding to the page. The front-end computing framework refers to a component set that can cooperate with the back-end to make visual functions such as page interaction and data display, and the back-end computing framework refers to a component set that can receive front-end page requests, process corresponding data and return functions.
[0064] For example, Figure 4 As shown in the login interface 401, the electronic device collects the user account and password input by the user on the login interface 401. For example, after the electronic device detects that the user account entered in the input field 402 is u1 and the password is 123, and detects that the user clicks the login control 41, it determines that the user has completed the input of the login data. After that, the electronic device determines whether the user has the system login permission based on the user login data.
[0065] S202: The electronic device determines, according to the user login data, first authority data and second authority data corresponding to the user login data.
[0066] In some embodiments, Figure 3 As shown, the backend computing framework obtains user login data, and determines corresponding first authority data and second authority data from a database according to the user login data.
[0067] Optionally, the first permission data includes, for example, a first association relationship corresponding to a role, a menu, and a control; the second permission data includes, for example, a second association relationship corresponding to an application, a node, a module, and a process.
[0068] Among them, the electronic device classifies and manages users with similar permissions through roles. For example, roles may include administrators, users, visitors, etc. Furthermore, the electronic device can also expand the number of roles as needed. Each interface displayed by the operation and maintenance resource management system of the electronic device may include one or more menus, and corresponding one or more controls, and the user can use the various functions provided by the operation and maintenance resource management system through menus and controls. For example, different users correspond to the same or different roles, and users with different roles can perform different operations on menus and controls in the operation and maintenance resource management system. Then the electronic device can determine the user's first permission data for roles, menus, and controls based on the acquired user login data.
[0069] Among them, the application includes, for example, an application managed by an operation and maintenance resource management system, such as a mobile banking application. Modules correspond to different functions in the application. For example, functions such as query, transfer, credit card, loan, etc. in a mobile banking application can correspond to different modules. A process is used to represent the execution process of a module to implement an application function. The number of processes corresponding to a single function implementation process is one or more. A node is used to represent a server that supports the operation of an application. Different servers can be distinguished by the Internet protocol address (IP) of the server. One or more applications can run on one server. For example, different users are preset to have different management permissions for different applications, nodes, modules, and processes. Then, the electronic device can determine the second permission data of the user for the application, node, module, and process based on the acquired user login data.
[0070] In some embodiments, a database is pre-established, and the database is used to store the first association relationship corresponding to the above-mentioned roles, menus, and controls, and the second association relationship corresponding to the application, node, module, and process. Optionally, the database can be a MySQL database. Among them, the database can be pre-configured in the electronic device. Alternatively, the database can also be configured on a cloud server, and when the electronic device needs to judge the user's authority, the database is obtained; or the electronic device interacts with the cloud server in the process of judging the user's authority, and the cloud server determines the corresponding authority data, and the electronic device obtains the authority data sent by the cloud server.
[0071] Optional, such as Figure 5 As shown in , the database includes at least three data tables, namely, a user table, a role table, and an operation table. Among them, the user table includes a user account field and a user name field, which are used to record the user account (such as u1) and the corresponding user name (such as user 1). The role table includes a role number field and a role name field, which are used to record the role number (such as role number 1) and the corresponding role name (such as role 1). The operation table includes an operation number field, an operation name field, and an operation function description field, which are used to record the operation number and the corresponding executable operation (such as the operation corresponding to operation number 1 is operation menu 1, and the operation authority for menu 1 is the content included in operation function description 1; the operation corresponding to operation number 2 is operation control 1, and the operation authority for control 1 is the content included in operation function description 2).
[0072] Optionally, the database may also include an association table for storing the association relationship between various data tables in the database. Figure 5 For example, Figure 5As shown in , the two association tables are association table 1 for storing the association relationship between the user table and the role table, and association table 2 for storing the association relationship between the role table and the operation table. Among them, association table 1 includes an association table number field, a user account field, and a role number field, so the user account and role number corresponding to the same association table number have an association relationship. Association table 2 includes an association table number field, a role number field, and an operation number field, so the role number and operation number corresponding to the same association table number have an association relationship.
[0073] In some embodiments, the user login data corresponds to a first user, and the first association relationship includes: a first target association relationship between a first role corresponding to the first user and a first menu in which the first role has first operating permissions, and / or a second target association relationship between the first role and a first control in the first menu in which the first role has second operating permissions.
[0074] For example, Figure 5 In the scenario shown, it is assumed that the user account of the first user is u1. The electronic device receives the user login data input by the first user and receives the user login data according to the following example: Figure 5 The association table 1 shown in FIG. 1 can determine that the role number corresponding to the user account u1 is role number 1. Then, the electronic device determines the corresponding operation number in the association table 2 according to the role number (for example, the operation numbers corresponding to the role number 1 are operation number 1 and operation number 2). Then, the electronic device determines the corresponding operation number according to the role number. Figure 5 The operation table shown in can determine the specific operation name corresponding to the operation number, that is, determine the user's operation authority in the operation and maintenance resource management system. Figure 5 , it is determined that the operation number 1 corresponds to the operation name menu 1, and it can be determined that the first user has the first operation permission for menu 1; the electronic device determines that the operation number 1 corresponds to the operation name menu 1; Figure 5 In the operation table shown in , it can also be determined that the operation name corresponding to the operation number 2 is control 1, and it can be determined that the first user has the second operation permission for control 2. That is, the first association relationship includes the first target association relationship between the first role corresponding to the first user (i.e., the role with the role number 1) and menu 1, and the second target association relationship between the first role and control 1. Control 1 can be a control in menu 1.
[0075] In some embodiments, the first operation permission or the second operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission. Optionally, the operation permission for menus and controls can be preset in the operation table preset in the database.
[0076] For example, Figure 5In the scenario shown, the electronic device can determine that the first user (u1) has the operation authority for menu 1 and control 1. The operation function description field in the operation table is used to define the same or different operation authorities for different operation names. For example, assuming that the specific operation authorities of menu 1 and control 1 are different, the operation authorities included in operation function description 1 include editing authority, and the operation authorities included in operation function description 2 include viewing authority. Then, the electronic device determines that the first user is allowed to edit menu 1 and view control 1 based on the operation table stored in the database.
[0077] Optional, such as Figure 6 As shown, the above-mentioned database can also include four data tables, namely a node table, an application table, a module table and a process table. Among them, the node table includes a node number field and a node name field, which are used to record the node number and the corresponding node name (such as the node name corresponding to node number 1 is node 1, and the node name corresponding to node number 2 is node 2). The application table includes an application number field and an application name field, which are used to record the application number and the corresponding application name (such as the application name corresponding to application number 1 is application 1, and the application name corresponding to application number 2 is application 2). The module table includes a module number field and a module name field, which are used to record the module number and the corresponding module name (such as the module name corresponding to module number 1 is module 1, and the module name corresponding to module number 2 is module 2). The process table includes a process number field and a process name field, which are used to record the process number and the corresponding process name (such as the process name corresponding to process number 1 is process 1, and the process name corresponding to process number 2 is process 2).
[0078] Optionally, the database may also include an association table for storing the association relationship between various data tables in the database. Figure 6 The four data tables shown and Figure 5 As shown in the user table. Figure 6As shown, the four association tables are respectively an association table 11 for storing the association relationship between the node table and the application table, an association table 22 for storing the association relationship between the application table and the module table, an association table 33 for storing the association relationship between the module table and the process table, and an association table 44 for storing the association relationship between the user table and the application table. Among them, the association table 11 includes an association table number field, a node number field, and an application number field, so the node number and the application number corresponding to the same association table number have an association relationship. The association table 22 includes an association table number field, an application number field, and a module number field, so the application number and the module number corresponding to the same association table number have an association relationship. The association table 33 includes an association table number field, a module number field, and a process number field, so the module number and the process number corresponding to the same association table number have an association relationship. The association table 44 includes an association table number field, a user account field, and an application number field, so the user account and the application number corresponding to the same association table number have an association relationship.
[0079] It should be noted that each of the above data tables contains at least two attributes (such as the node table includes the node number attribute and the node name attribute), and the attribute can be represented by a field. Then, the data table can also include fields for representing other attributes, such as fields for describing other related information. For example, the node table can also include a node host name field, a node deployment time field, etc.
[0080] In some embodiments, the user login data corresponds to the first user, and the second association relationship includes one or more of the following: a third target association relationship between the first user and a first application with third operating permissions for the first user, a fourth target association relationship between the first user and a first node with fourth operating permissions for the first user, a fifth target association relationship between the first user and a first module with fifth operating permissions for the first user, and a sixth target association relationship between the first user and a first process with sixth operating permissions for the first user.
[0081] For example, Figure 6 In the scenario shown, it is assumed that the user account of the first user is u1. The electronic device receives the user login data input by the first user and receives the user login data according to the following example: Figure 6 The association table 44 shown can determine that the user account u1 corresponds to application number 1 and application number 2. The electronic device determines the corresponding node number in the association table 11 according to the application number (e.g., the node number corresponding to application number 1 is 1, and the node number corresponding to application number 2 is 1). The electronic device can also determine the module number corresponding to the application number according to the association table 22 (e.g., application number 1 corresponds to module number 1 and module number 2), and the electronic device can also determine the process number corresponding to the module number according to the association table 33 (e.g., module number 1 corresponds to process number 1 and process number 2). Then, the electronic device determines the corresponding node number according to the association table 22. Figure 6The association table 44 including the association relationship between the user and the application, the association table 11 including the association relationship between the application and the node, the association table 22 including the association relationship between the application and the module, and the association table 33 including the association relationship between the module and the process shown in the figure determine the user's operation authority for resources in the operation and maintenance resource management system. The operation authority corresponds to the third operation authority corresponding to the user and the application, the fourth operation authority corresponding to the user and the node, the fifth operation authority corresponding to the user and the module, and the sixth operation authority corresponding to the user and the process. That is, the second association relationship includes one or more of the following contents: the third target association relationship between the first user and the first application with the third operation authority of the first user, the fourth target association relationship between the first user and the first node with the fourth operation authority of the first user, the fifth target association relationship between the first user and the first module with the fifth operation authority of the first user, and the sixth target association relationship between the first user and the first process with the sixth operation authority of the first user.
[0082] So, if Figure 6 As shown in the four association tables, a node can correspond to multiple applications, an application can correspond to multiple modules, a module can correspond to multiple processes, a user can correspond to multiple applications, and an application can correspond to multiple users. Therefore, the first permission data corresponding to user-role-operation and the second permission data corresponding to node-application-module-process are comprehensively applied to achieve refined management of the operation and maintenance resource management system.
[0083] In some embodiments, the third operation permission, or the fourth operation permission, or the fifth operation permission, or the sixth operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission.
[0084] For example, Figure 5 In the scenario shown, the electronic device can determine that the first user (ie, user u1) has the operation authority for menu 1 and control 1, assuming that the operation authority for control 1 is that the first user has the editing authority. Figure 6 As shown, the first user has operation permissions for application 1 and application 2, module 1 and module 2 corresponding to application 1, and process 1 and process 2 corresponding to module 1. Then, assuming that the display interface of application 1 includes control 1, control 1 corresponds to module 1 and process 1. Therefore, the electronic device can determine that the first user also has editing permissions for application 1, module 1, and process 1.
[0085] S203: The electronic device displays a first target interface according to the first permission data and the second permission data.
[0086] In some embodiments, the electronic device determines the user's operating authority for menus and controls based on the first permission data, and determines the user's operating authority for applications, nodes, modules, and processes based on the second permission data. Then, the electronic device determines whether the corresponding content can be displayed (i.e., the first target interface is displayed) based on whether the user has the viewing authority in the operating authority. And, after detecting the user's operation on the interface, the electronic device determines whether to execute the corresponding command based on whether the user has the corresponding operating authority.
[0087] For example, Figure 3 As shown, the back-end computing framework can determine the first permission data and the second permission data according to the user login data sent by the front-end computing framework, and send the first permission data and the second permission data to the front-end computing framework. Afterwards, the front-end computing framework can perform interface rendering according to the specific contents included in the first permission data and the second permission data, and send the rendered interface data to the display module for display, so that the electronic device can display the target interface according to the first permission data and the second permission data.
[0088] For example, Figure 7 As shown, after the electronic device receives the login data input by the first user and determines that the user has the login authority, the home page interface 701 is displayed, and the menu bar included in the operation and maintenance resource management system is displayed on the home page interface 701, such as the menu bar 702, including the asset management control 71, the node management control 72, the new asset control 73, the application management control 74, and the authority setting control 75. Afterwards, the electronic device determines the user's operation authority for the displayed content in the home page interface 701 according to the login data. For example, if the user has the authority to view the data corresponding to one or more controls, the corresponding data can be displayed in the data display bar after detecting that the user clicks on the control with viewing authority displayed in the menu bar 702. For another example, if the electronic device determines that the user does not have the viewing authority for the data corresponding to one or more controls, the control can be grayed out and the user cannot operate it; or after detecting that the user clicks on the control, a prompt message is displayed to prompt the user that the operation authority is not available.
[0089] As another example, the first permission data determined by the electronic device includes the user account u1, the role corresponding to u1 is a common user, and the operation permissions corresponding to the common user include the operation permissions for the asset management control 71 and the node management control 72. The second permission data includes the association relationship between user u1 and node 1, node 1 and application 1, the association relationship between user u1 and node 2, node 2 and application 2, and the association relationship between user u1 and node 2, node 2 and application 3. Then, if Figure 8As shown, after the electronic device detects that the first user (i.e., user u1) clicks the node management control 72, the display bar 703 displays the node related information corresponding to the second permission data, such as the corresponding association relationship between the above-mentioned node and the application. The node related information may also include the node host name corresponding to the node and the node deployment time.
[0090] For example, when the user role in the first permission data is an administrator, it is understood that the administrator's permissions should be greater than the permissions of ordinary users, so the content included in the second permission data corresponding to the administrator will also be more than the above Figure 8 The content shown. For example, the node corresponding to the user and the application corresponding to the node, the number of data items and the specific information of the data are changed. For example, Fig. 9 As shown, when the role is an administrator, after the electronic device detects that the user clicks the node management control 72, the corresponding content displayed on the display bar 703 includes 100 data items, which are more than Figure 8 The 3 pieces of data shown.
[0091] In this way, different users can correspond to the same or different roles, and the second permission data can perform permission control on the resources corresponding to different users, thereby achieving more accurate permission management of users and resources in the operation and maintenance resource management system.
[0092] In some embodiments, if the operating permissions include editing permissions and deleting permissions, corresponding editing controls and / or deleting controls can be displayed at the corresponding positions of data with editing permissions and / or deleting permissions, prompting the user to edit or delete the current data.
[0093] For example, Fig.10 As shown, after the electronic device detects that the first user (i.e., user u1) clicks the application management control 101, it determines that the second permission data includes the permission to view the data corresponding to the application management control, and can display two applications 1 and 2 corresponding to the second permission data in the display bar 703. Assuming that the second permission data also includes viewing the basic information corresponding to application 1 and the corresponding module permission, when the electronic device detects that user u1 clicks the application 1 control 102 again, as shown in FIG. Fig.11 The interface shown shows the data corresponding to application 1, such as basic information. The basic information includes the application name and the lead development team. The basic information can be the above Figure 6 The fields included in the application table are shown in Figure 1. In addition, Figure 6 As shown, according to the application table and the association table 22, the modules corresponding to application 1 are module 1 and module 2. Then, Fig.11 The interface shown can also display module 1 and module 2 corresponding to application 1. User u1 has operation permissions for application 1, module 1, and module 2. Figure 5As shown, it is assumed that the operation rights of menu 1 corresponding to user u1 in the operation table include editing rights, and the operation rights of control 1 include deletion rights. Assume that menu 1 includes Fig.11 The basic information menu and module menu corresponding to the application 1 shown in the figure, the control 1 includes the following Fig.11 The corresponding controls of module 1 and module 2 are shown. Fig.11 In the interface shown, corresponding edit controls and delete controls are displayed on the basic information menu and module menu of application 1, allowing user u1 to operate them.
[0094] In other embodiments, the electronic device detects a first operation of a user on a first target interface, determines a second target interface corresponding to the first operation based on the first permission data and the second permission data, and displays the second target interface.
[0095] For example, Fig.11 As shown, assuming that the current display interface of the electronic device is the first target interface, the first user has the editing operation permission and the deletion operation permission for module 1 and module 2. After detecting that the user clicks the editing control 111 corresponding to module 1, the following is displayed Fig.12 The interface shown in FIG. 1 prompts the user to edit the module name of module 1 (i.e., the first user has editing authority for module 1, such as editing the name of module 1). Afterwards, if it is detected that the first user enters the changed module name as module 10 in the input box 121 and clicks the confirmation control 122, the following is displayed: Fig.13 The interface shown. Fig.12 The interface shown is the second target interface, and the edited module name, such as module 10, is displayed on the second target interface. Fig.11 As shown, if the electronic device detects that the first user clicks the delete control 112 corresponding to module 2, the data of module 2 is deleted according to the operation authority of the first user, and module 2 will not be displayed on the displayed second target interface.
[0096] In other embodiments, the display screen of the electronic device is a touch screen, so the electronic device may not need to display controls such as edit controls and delete controls for indicating user operation permissions, but preset gestures, and execute corresponding commands after detecting the user's preset gesture operation on the touch screen. For example, after the electronic device detects that the user has long pressed a piece of data displayed on the interface, it displays a prompt box to prompt the user whether to delete the data.
[0097] Therefore, electronic devices can Figure 6 The association table in the Figure 5The association table in the management of the specific operation permissions of the resources corresponding to the user, thereby preventing security risks from causing accidental deletion or non-compliant operations. Further explanation: presetting the first permission data and the second permission data at the same time can more accurately control the permissions of users and resources in the operation and maintenance resource management system.
[0098] In some embodiments, the first permission data and the second permission data are saved in a preset saving location.
[0099] For example, Figure 3 As shown, after the electronic device backend computing framework determines the first permission data and the second permission data, and sends the determined first permission data and the second permission data to the frontend computing framework, the frontend computing framework can also send the first permission data and the second permission data to the storage module for caching. The frontend computing framework and the storage module are in a real-time data interaction state, and the frontend computing framework displays the target interface according to the first permission data and the second permission data corresponding to the user login data in the storage module. Figure 3 As shown, after the electronic device detects the user's operation on the display module, it sends the operation data to the front-end computing framework for processing. The front-end computing framework obtains the first permission data and the second permission data corresponding to the storage module according to the user operation, thereby determining the corresponding target interface, rendering the new target interface, and sending it to the display module for display.
[0100] Optionally, in order to ensure the uniformity of data, if a user has the authority to modify the operation authority of other users, the corresponding first authority data and second authority data in the storage module can be updated first, so that the front-end computing framework can realize real-time update and display of the user target interface. Furthermore, after the first authority data and the second authority data in the storage module are updated, the data in the database can also be updated synchronously. Therefore, the next time a user with the same authority logs in, he can obtain the latest updated data in the database.
[0101] For example, assume that user 1 is viewing data A in the operation and maintenance resource management system and has the right to delete data A, and user 2 has the right to modify other users' operation permissions. While user 1 is viewing the data, user 2 cancels user 1's right to delete data A. At this time, the storage module can quickly update user 2's modification of user 1's permission data, and the front-end framework updates user 1's display interface for the permission in real time, that is, user 1 no longer has the right to delete data A.
[0102] In the above scheme, the user login data is obtained, and the first permission data and the second permission data corresponding to the user login data are determined according to the user login data. Among them, the first permission data includes the first association relationship corresponding to the role, menu, and control; the second permission data includes the second association relationship corresponding to the application, node, module, and process. Finally, according to the first permission data and the second permission data, the target interface is displayed. In this way, the preset first permission data and the second permission data at the same time will have more accurate permission control over users and resources in the operation and maintenance resource management system, thereby preventing security risks, mistakes or non-compliant operations.
[0103] The embodiment of the present application can divide the functional modules of the automated permission resource measurement device according to the above-mentioned method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.
[0104] Combination of the above Figure 2 The method provided by the embodiment of the present application is described in detail. Fig.14 The rights management device provided by the embodiment of the present application is described in detail. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment, so the contents not described in detail can be referred to the method embodiment above, and for the sake of brevity, they will not be repeated here.
[0105] The embodiment of the present application provides a rights management device, which can be the above electronic device, or a chip or functional module of the electronic device. For example, taking the rights management device as the electronic device in the above method embodiment as an example, the rights management device can implement the corresponding steps or processes for the electronic device in the above method embodiment.
[0106] Fig.14 The schematic diagram of the structure of a rights management device is shown. The rights management device includes an acquisition module 141, a processing module 142 and a display module 143.
[0107] The acquisition module 141 is used to acquire login data. For example, refer to Figure 2 As shown, the acquisition module 141 is used to execute S201. The processing module 142 is used to determine the first permission data and the second permission data corresponding to the user login data according to the user login data acquired by the acquisition module 141. Figure 2 As shown, the processing module 142 is used to execute S202. The display module 143 is used to display the first target interface according to the first permission data and the second permission data. Figure 2 As shown, the display module 143 is used to execute S203.
[0108] Optionally, the user login data corresponds to a first user, and the first association relationship includes: a first target association relationship between a first role corresponding to the first user and a first menu in which the first role has first operating permissions, and / or a second target association relationship between the first role and a first control in the first menu in which the first role has second operating permissions.
[0109] Optionally, the user login data corresponds to the first user, and the second association relationship includes one or more of the following: a third target association relationship between the first user and the first application for which the first user has third operating authority, a fourth target association relationship between the first user and the first node for which the first user has fourth operating authority, a fifth target association relationship between the first user and the first module for which the first user has fifth operating authority, and a sixth target association relationship between the first user and the first process for which the first user has sixth operating authority.
[0110] Optionally, the first operation permission, or the second operation permission, or the third operation permission, or the fourth operation permission, or the fifth operation permission, or the sixth operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission.
[0111] Optionally, the authority management device may further include a storage module 144. The storage module 144 is configured to store the first authority data and the second authority data in a preset storage location.
[0112] Optionally, the acquisition module 141 is further used to detect a first operation performed by the user on the first target interface.
[0113] Optionally, the processing module 142 is further configured to determine a second target interface corresponding to the first operation according to the first permission data and the second permission data.
[0114] Optionally, the display module 143 displays a second target interface.
[0115] Another embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions. When the instructions are executed on a rights management device, the rights management device executes the following steps: Figure 2 The steps of the electronic device in the rights management method of the embodiment shown.
[0116] In another embodiment of the present application, a computer program product is further provided. The computer program product includes computer executable instructions, which are stored in a computer-readable storage medium; a processor of the rights management device can read the computer executable instructions from the computer-readable storage medium, and the processor executes the computer executable instructions so that the rights management device executes as follows: Figure 2 The steps of the electronic device in the rights management method of the embodiment shown.
[0117] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, and its role will not be repeated here.
[0118] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0119] Those of ordinary skill in the art will appreciate that the modules, units, and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0120] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0121] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not performed. Another point, the coupling or direct coupling or communication connection between each other shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0122] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0123] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0124] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (full name in English: read-only memory, English abbreviation: ROM), random access memory (full name in English: random access memory, English abbreviation: RAM), magnetic disk or optical disk and other media that can store program codes.
[0125] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A rights management method, characterized in that: include: Get user login data; Determining, according to the user login data, first authority data and second authority data corresponding to the user login data; The first permission data includes a first association relationship between roles, menus, and controls; the second permission data includes a second association relationship between applications, nodes, modules, and processes; the nodes are used to represent servers that support the running of applications, and the modules correspond to different functions in the applications; Determine the user's operation authority for the menu and the control according to the first authority data, and determine the user's operation authority for the application, the node, the module, and the process according to the second authority data, and display a first target interface; The user login data corresponds to a first user, and the first association relationship includes: a first target association relationship between a first role corresponding to the first user and a first menu having a first operation permission for the first role, and a second target association relationship between the first role and a first control in the first menu having a second operation permission for the first role; The user login data corresponds to the first user, and the second association relationship includes the following items: a third target association relationship between the first user and a first application with third operating permissions for the first user, a fourth target association relationship between the first user and a first node with fourth operating permissions for the first user, a fifth target association relationship between the first user and a first module with fifth operating permissions for the first user, and a sixth target association relationship between the first user and a first process with sixth operating permissions for the first user.
2. The rights management method according to claim 1, characterized in that: The first operation permission, or the second operation permission, or the third operation permission, or the fourth operation permission, or the fifth operation permission, or the sixth operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission.
3. The rights management method according to claim 1, characterized in that: The method further comprises: The first permission data and the second permission data are saved in a preset saving location.
4. The rights management method according to claim 1, characterized in that: The method further comprises: After detecting a first operation of the user on the first target interface, determining a second target interface corresponding to the first operation according to the first permission data and the second permission data; The second target interface is displayed.
5. A rights management device, characterized in that: include: Acquisition module, processing module and display module; The acquisition module is used to acquire user login data; The processing module is used to determine, according to the user login data, first permission data and second permission data corresponding to the user login data; the first permission data includes a first association relationship corresponding to a role, a menu, and a control; the second permission data includes a second association relationship corresponding to an application, a node, a module, and a process; the node is used to represent a server supporting the operation of an application, and the module corresponds to different functions in the application; The display module is used to determine the user's operation authority for the menu and the control according to the first authority data, and to determine the user's operation authority for the application, the node, the module, and the process according to the second authority data, and to display a first target interface; The user login data corresponds to a first user, and the first association relationship includes: a first target association relationship between a first role corresponding to the first user and a first menu having a first operation permission for the first role, and a second target association relationship between the first role and a first control in the first menu having a second operation permission for the first role; The user login data corresponds to the first user, and the second association relationship includes the following items: a third target association relationship between the first user and a first application with third operating permissions for the first user, a fourth target association relationship between the first user and a first node with fourth operating permissions for the first user, a fifth target association relationship between the first user and a first module with fifth operating permissions for the first user, and a sixth target association relationship between the first user and a first process with sixth operating permissions for the first user.
6. The rights management device according to claim 5, characterized in that: The first operation permission, or the second operation permission, or the third operation permission, or the fourth operation permission, or the fifth operation permission, or the sixth operation permission includes viewing permission and / or editing permission, and the editing permission includes one or more of the following: adding permission, deleting permission, and modifying permission.
7. The rights management device according to claim 5, characterized in that: The device also includes: a storage module; The storage module is used to save the first permission data and the second permission data in a preset saving location.
8. The rights management device according to claim 5, characterized in that: The acquisition module is further used to detect a first operation performed by a user on the first target interface; The processing module is further configured to determine a second target interface corresponding to the first operation according to the first permission data and the second permission data; The display module is also used to display the second target interface.
9. A rights management device, characterized in that: It includes a processor, and when the rights management device is running, the processor executes computer execution instructions to enable the rights management device to execute the rights management method as described in any one of claims 1-4.
10. A computer-readable storage medium comprising instructions, characterized in that: When the instruction is executed on a computer, the computer is enabled to execute the rights management method according to any one of claims 1 to 4.
11. A computer program product comprising instructions, characterized in that When the computer program product runs on a computer, the computer executes the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Enhanced organization and automatic navigation of display screens facilitating automation control
CN102819425A
Authority control method and device, equipment, storage medium and program product
CN113297550A