A method, device, equipment and storage medium for obtaining permission roles
By building permission role wrap containers and injecting permission and role data, the inefficiency problem caused by multiple interactions in the existing technology is solved, and the rapid acquisition of permission and role data is achieved.
Patent Information
- Application Number
- CN202010619715.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-30
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2040-06-30
AI Technical Summary
In the prior art, when obtaining permission data and its associated role data, it needs to interact with the database multiple times, resulting in low efficiency.
By building a permission role wrap container, use permission identification information to inject permission data and role data into the container, realizing unified storage and management of data, and obtaining permission and role data in just one interaction.
It improves the efficiency of obtaining permission data and role data, simplifies the data acquisition process, and realizes rapid acquisition of permissions and role information.
Smart Images

Figure CN113868316B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer application technologies, and particularly to a method, device, equipment, and storage medium for obtaining permission roles. Background Art
[0002] When obtaining certain permission data and its associated role data, the prior art first finds the permission data in the database, and then finds the role data associated with it in the database according to the permission data. This requires multiple interactions with the database, and the acquisition efficiency of the permission data and the role data is relatively low. Summary of the Invention
[0003] The embodiments of the present invention provide a method, device, equipment, and storage medium for obtaining permission roles, which solves the problem of relatively low acquisition efficiency of permission data and role data.
[0004] In a first aspect, the embodiments of the present invention provide a method for obtaining permission roles, which may include:
[0005] When a trigger event for obtaining permission roles is monitored, obtain a pre-constructed permission role package container and the permission identification information of the permission to be obtained corresponding to the trigger event; obtain the permission to be obtained corresponding to the permission identification information and the role to be obtained corresponding to the permission to be obtained from the permission role package container, where the role to be obtained is the role with the permission to be obtained.
[0006] Among them, the permission role package container is pre-constructed through the following steps:
[0007] Obtain a pre-constructed permission container and role container, and construct a permission role package container based on the permission container and the role container; based on the function SelectPrivilegeRoleList(PrivilegeIdentification), inject the permission data corresponding to PrivilegeIdentification and the role data corresponding to the permission data in the stored data stored in the database into the permission role package container respectively, where PrivilegeIdentification is the permission identification information.
[0008] Optionally, SelectPrivilegeRoleList(PrivilegeIdentification) can implement the data injection function through the following steps: obtain the privilege role mapping relationship between the privilege role package container and the stored data; obtain the privilege data corresponding to PrivilegeIdentification and the role data corresponding to the privilege data from the stored data; based on the privilege role mapping relationship, inject each privilege information in the privilege data into the corresponding privilege field of the privilege role package container, and inject each role information in the role data into the corresponding role field of the privilege role package container.
[0009] Optionally, obtaining the privilege data corresponding to PrivilegeIdentification and the role data corresponding to the privilege data from the stored data may include:
[0010] Obtain the privilege table, role table, and privilege role association table from the stored data; obtain the privilege data from the privilege table based on PrivilegeIdentification and obtain the role identification information from the privilege role association table; obtain the role data from the role table based on the role identification information.
[0011] Optionally, based on the privilege role mapping relationship, injecting each role information in the role data into the corresponding role field of the privilege role package container may include:
[0012] Respectively obtain the alias information and original name information of each role field in the privilege role package container; based on the naming mapping relationship between the alias information and the original name information and the privilege role mapping relationship, inject each role information in the role data into the corresponding role field corresponding to the alias information of the privilege role package container.
[0013] Optionally, the privilege role mapping relationship can be determined in advance through the following steps:
[0014] Obtain the privilege mapping relationship between each privilege field in the privilege container and each privilege information in the stored data, and inherit the privilege mapping relationship; set the role mapping relationship between the role field and each role information in the stored data in the inheritance result, and determine the privilege role mapping relationship according to the setting result.
[0015] Optionally, the privilege role package container is a description method of the privilege role package class, the privilege container is a description method of the privilege class, and the role container is a description method of the role class;
[0016] Correspondingly, constructing the privilege role package container based on the privilege container and the role container may include:
[0017] Inherit the permission class and add the role set in the role class to the inheritance result; construct a permission-role wrapper class based on the addition result and describe the permission-role wrapper class as a permission-role wrapper container.
[0018] Optionally, inheriting the permission class and adding the role set in the role class may include:
[0019] Inherit the permission class by calling class PrivilegeRoleWrapper:Privilege(), where PrivilegeRoleWrapper is the permission-role wrapper class and Privilege is the permission class;
[0020] By calling var roleList:MutableList <role>= mutableListOf() adds the role set in the role class to the inheritance result. Role is the role class and roleList is the role set.
[0021] In a second aspect, an embodiment of the present invention further provides a permission role acquisition device, which may include:
[0022] A permission identification information acquisition module, configured to acquire a constructed permission role package container and permission identification information of a to-be-acquired permission corresponding to a trigger event when detecting a trigger event for acquiring a permission role;
[0023] A permission role acquisition module, configured to acquire a to-be-acquired permission corresponding to the permission identification information and a to-be-acquired role corresponding to the to-be-acquired permission from the permission role package container, where the to-be-acquired role is a role with the to-be-acquired permission;
[0024] Among them, the permission role package container is pre-constructed through the following modules:
[0025] A container construction module, configured to acquire a constructed permission container and a role container, and construct a permission role package container based on the permission container and the role container;
[0026] A data injection module, configured to inject, based on the function SelectPrivilegeRoleList(PrivilegeIdentification), the permission data corresponding to PrivilegeIdentification in the stored data stored in the database and the role data corresponding to the permission data into the permission role package container respectively, where PrivilegeIdentification is the permission identification information.
[0027] In a third aspect, an embodiment of the present invention further provides a device, which may include:
[0028] One or more processors;
[0029] A memory, configured to store one or more programs;
[0030] When the one or more programs are executed by the one or more processors, the one or more processors implement the permission role acquisition method provided by any embodiment of the present invention.
[0031] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the permission role acquisition method provided by any embodiment of the present invention is implemented.
[0032] The technical solution of the embodiment of the present invention constructs a permission role package container through the obtained permission container and role container, and uses the permission identification information as the input parameter to call the constructed permission role injection function, so as to inject the permission data corresponding to the permission identification information and the role data corresponding to the permission data in the stored data stored in the database into the permission role package container respectively, achieving the effect of carrying both permission data and role data in the permission role package container; furthermore, when a trigger event for obtaining the permission role is detected, the to-be-obtained permission corresponding to the permission identification information corresponding to the trigger event and the to-be-obtained role corresponding to the to-be-obtained permission can be obtained from the permission role package container. The above technical solution achieves the effect of quickly obtaining permission data and role data by interacting with the database once and interacting with one container. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 is a flowchart of a method for obtaining permission roles in Embodiment 1 of the present invention;
[0034] Figure 2 is a flowchart of a method for obtaining permission roles in Embodiment 2 of the present invention;
[0035] Figure 3 is a flowchart of a method for obtaining permission roles in Embodiment 3 of the present invention;
[0036] Figure 4 is a structural block diagram of a device for obtaining permission roles in Embodiment 4 of the present invention;
[0037] Figure 5 is a structural schematic diagram of a device in Embodiment 5 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] The present invention will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. In addition, it should be noted that for the sake of description, only parts related to the present invention are shown in the drawings, not all structures.
[0039] Embodiment 1
[0040] Figure 1 is a flowchart of a method for obtaining permission roles provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of obtaining permission data and role data from a database. This method can be executed by the permission role obtaining device provided by the embodiment of the present invention. The device can be implemented in software and / or hardware, and can be integrated on various user terminals or servers.
[0041] See Figure 1 , the method of the embodiment of the present invention specifically includes the following steps:
[0042] S110. Obtain the constructed permission container and role container, and construct a permission-role package container based on the permission container and the role container.
[0043] Among them, the permission container is a container stored in the database for carrying permission data. Each permission data can have multiple permission information, such as permission identification information (i.e., permission ID), permission parent identification information (i.e., parent ID information), permission name, path information (i.e., URL information), type information, update time, creation time, operator information, and so on.
[0044] Similarly, the role container is a container stored in the database for carrying role data. Each role data can have multiple role information, such as role identification information (i.e., role ID), role name, role details, update time, creation time, operator information, and so on.
[0045] After obtaining the permission container and the role container, a permission-role package container can be constructed based on the obtained permission container and role container. The permission-role package container is a container for carrying both permission data and role data. According to the permission-role package container, information such as which roles have a certain permission and which permissions a certain role has can be determined.
[0046] It should be noted that, first of all, the advantage of setting the permission-role package container is that the permission-role package container realizes the unification of the permission container and the role container, or in other words, realizes the unification of permission data and role data. Therefore, when subsequently obtaining permission data and role data associated with the permission data, only one interaction with the database is required to obtain the permission data and role data from the permission-role package container stored in the database. The reduction in the number of database interactions improves the acquisition efficiency of permission data and role data; compared with the technical solution where permission data is stored in the permission container, role data is stored in the role container, and the association relationship between permission data and role data is stored in the association container, based on the permission package container, the data acquisition process only needs to interact with one container, and the simplification of the data acquisition process also improves the acquisition efficiency of permission data and role data.
[0047] Secondly, in practical applications, the permission container can be a description method of the permission class, which is a class used to carry permission data; similarly, the role container can be a description method of the role class, which can be a class used to carry role data. Thus, to better understand the specific forms of the above-mentioned permission container and role container, by way of example, the specific forms of the permission class Privilege and the role class Role are as follows, where Serializable is an interface provided by Java for general data saving and reading.
[0048]
[0049]
[0050]
[0051] S120. Based on the function SelectPrivilegeRoleList(PrivilegeIdentification), inject the permission data corresponding to PrivilegeIdentification and the role data corresponding to the permission data in the stored data stored in the database into the permission-role package container respectively. PrivilegeIdentification is the permission identification information corresponding to the detected trigger event for obtaining the permission role.
[0052] Among them, the permission-role package container constructed based on the permission container and the role container is an empty shell without any data stored in it. Therefore, after constructing the permission-role package container, the permission data and role data in the database can be injected into the permission-role package container so as to obtain the corresponding permission data and role data from the permission package container subsequently.
[0053] Taking the privilege identification information PrivilegeIdentification as the input parameter, call the privilege role injection function SelectPrivilegeRoleList(PrivilegeIdentification), where SelectPrivilegeRoleList is the function name of the privilege role injection function. Thus, the privilege identification information is passed to the constructed privilege role injection function, so that the privilege role injection function injects the privilege data corresponding to the privilege identification information and the role data corresponding to the privilege data from the stored data in the database into the privilege role wrapper container respectively. The stored data can be either privilege data or role data. In practical applications, optionally, the privilege role injection function can be set in a certain custom interface, and this custom interface can inherit from the BaseMapper interface, which is a base class interface, and the data in it can be defined as Privilege (privilege data). Exemplarily, the custom interface PrivilegeMapper is as follows. Here, interface is a keyword for interface operations in object-oriented programming languages, which can combine the required members to encapsulate a set with certain functions. selectPrivilegeRoleList is the function name of the privilege role injection function, and the return value of selectPrivilegeRoleList is a collection type of PrivilegeRoleWrapper.
[0054] interface PrivilegeMapper:BaseMapper <privilege>{
[0055] fun selectPrivilegeRoleList(): MutableList <privilegerolewrapper>
[0056] }
[0057] In practical applications, optionally, the above data injection process can be executed when the system starts, that is, when the system starts, the permission data corresponding to each permission identification information in the database and the role data associated with each permission data are all injected into the permission role package container. The permission identification information is the unique identification information of the permission data, and a certain permission data can be uniquely determined according to the permission identification information; it can be executed when a trigger event for obtaining the permission role is detected, that is, the permission data corresponding to the permission identification information and the role data associated with the permission data are injected into the permission role package container. The trigger event can be a trigger event when the user executes a certain operation, a trigger event when the timer arrives, etc.; it can also be executed at other times, which is not specifically limited here.
[0058] S130. When a trigger event for obtaining the permission role is detected, obtain the already constructed permission role package container and the permission identification information of the permission to be obtained corresponding to the trigger event.
[0059] Among them, the trigger event is an event triggered by the user for obtaining permission data and role data, such as an event triggered when the user clicks a certain button, an event triggered when the system starts, an event triggered when the timer in the system reaches the time, etc., which is not specifically limited here. The permission to be obtained is at least one permission data to be obtained corresponding to the permission identification information among the permission data. It can be the permission data that has been injected into the permission role package container, or the permission data that has not been injected into the permission role package container, which is not specifically limited here. If the permission to be obtained is the permission data that has not been injected into the permission role package container, the permission to be obtained and the role to be obtained associated with the permission to be obtained can be injected into the permission role package container based on the permission role injection function first, so as to obtain the permission to be obtained and the object to be obtained from the permission role package container later. The object to be obtained is the role data among the role data that is associated with the permission to be obtained and is the role with the permission to be obtained.
[0060] S140. Obtain the permission to be obtained corresponding to the permission identification information and the role to be obtained corresponding to the permission to be obtained from the permission role package container.
[0061] Among them, the to-be-obtained permission corresponding to it can be obtained from the permission role package container according to the permission identification information. Moreover, since the permission role package container is a container that bears both permission data and role data at the same time, information such as which roles have a certain permission and which permissions a certain role has can be determined according to this permission role package container. Then, the to-be-obtained role corresponding to the to-be-obtained permission can also be obtained from the permission role package container. One database interaction and one container interaction achieve the effect of quickly obtaining the to-be-obtained permission and the to-be-obtained object.
[0062] In the technical solution of the embodiment of the present invention, a permission role package container is constructed through the obtained permission container and role container, and the permission identification information is used as the input parameter to call the constructed permission role injection function, so as to inject the permission data corresponding to the permission identification information in the stored data stored in the database and the role data corresponding to the permission data into the permission role package container respectively, achieving the effect of bearing both permission data and role data in the permission role package container; furthermore, when a trigger event for obtaining a permission role is detected, the to-be-obtained permission corresponding to the permission identification information corresponding to the trigger event and the to-be-obtained role corresponding to the to-be-obtained permission can be obtained from the permission role package container. The above technical solution achieves the effect of quickly obtaining permission data and role data by interacting with the database once and interacting with one container.
[0063] Embodiment 2
[0064] Figure 2 It is a flowchart of a permission role obtaining method provided in Embodiment 2 of the present invention. This embodiment is optimized based on the above technical solutions. In this embodiment, optionally, the permission role package container is a description method of the permission role package class, the permission container is a description method of the permission class, and the role container is a description method of the role class; correspondingly, constructing a permission role package container based on the permission container and the role container may specifically include: inheriting the permission class and adding the role set in the role class to the inheritance result; constructing a permission role package class according to the addition result, and describing the permission role package class as the permission role package container. The explanations of the same or corresponding terms as those in the above embodiments are not repeated here.
[0065] See Figure 2 , the method of this embodiment may specifically include the following steps:
[0066] S210. Obtain the constructed permission class and role class, inherit the permission class, add the role set in the role class to the inheritance result, and construct a permission role package class according to the addition result, where the permission role package container is a description method of the permission role package class.
[0067] Among them, there are multiple implementation methods for constructing a privilege-role wrapper class based on privilege classes and role classes. To achieve the simplification of the privilege-role wrapper class and the association effect between privilege data and role data, an optional construction method is to first inherit the privilege class and add the role set in the role class to the inheritance result, that is, load the role set composed of the role data associated with a certain privilege class into the privilege class. Thus, subsequently, when obtaining privilege data and role data, when finding the corresponding privilege data from the privilege-role wrapper class according to the privilege identification information, the role set loaded under the privilege data is the corresponding role data.
[0068] Exemplarily, the specific form of the privilege-role wrapper class can be as follows:
[0069]
[0070] Among them, PrivilegeRoleWrapper is the privilege-role wrapper class, Privilege is the privilege class, Role is the role class, and roleList is the role set. Optionally, overriding the toString in the privilege-role wrapper class can facilitate and quickly view the detailed information of each data in the privilege-role wrapper class when obtaining data subsequently.
[0071] S220. Based on the function SelectPrivilegeRoleList(PrivilegeIdentification), inject the privilege data corresponding to PrivilegeIdentification in the stored data stored in the database and the role data corresponding to the privilege data into the privilege-role wrapper container respectively. PrivilegeIdentification is the privilege identification information corresponding to the detected trigger event for obtaining the privilege role.
[0072] S230. When detecting the trigger event for obtaining the privilege role, obtain the constructed privilege-role wrapper container and the privilege identification information of the privilege to be obtained corresponding to the trigger event.
[0073] S240. Obtain the privilege to be obtained corresponding to the privilege identification information and the role to be obtained corresponding to the privilege to be obtained from the privilege-role wrapper container.
[0074] The technical solution of the embodiment of the present invention, after obtaining the privilege class and the role class, can inherit the privilege class and add the role set in the role class to construct a privilege-role wrapper class, thereby achieving the simplification of the privilege-role wrapper class and the association effect between privilege data and role data.
[0075] Embodiment III
[0076] Figure 3 This is a flowchart of a method for obtaining privilege roles provided in the third embodiment of the present invention. This embodiment is optimized based on the above technical solutions. In this embodiment, optionally, SelectPrivilegeRoleList(PrivilegeIdentification) can implement the data injection function through the following steps: obtaining the privilege role mapping relationship between the privilege role package container and the stored data; obtaining the privilege data corresponding to PrivilegeIdentification and the role data corresponding to the privilege data from the stored data; based on the privilege role mapping relationship, injecting each privilege information in the privilege data into the corresponding privilege field of the privilege role package container, and injecting each role information in the role data into the corresponding role field of the privilege role package container. Among them, the explanations of the same or corresponding terms as those in the above embodiments are not repeated here. Refer to Figure 3 , the method of this embodiment can specifically include the following steps:
[0077] S310. Obtain the constructed privilege container and role container, and construct a privilege role package container based on the privilege container and the role container.
[0078] S320. Call the function SelectPrivilegeRoleList(PrivilegeIdentification) to enable the function SelectPrivilegeRoleList(PrivilegeIdentification) to execute S330 - S340 according to PrivilegeIdentification, where PrivilegeIdentification is the privilege identification information corresponding to the monitored trigger event for obtaining privilege roles.
[0079] S330. Obtain the privilege role mapping relationship between the privilege role package container and the stored data stored in the database, and obtain the privilege data corresponding to PrivilegeIdentification and the role data corresponding to the privilege data from the stored data.
[0080] Among them, the privilege role mapping relationship can be the mapping relationship between each privilege field in the privilege role package container and each privilege information of the privilege data stored in the database, or the mapping relationship between each role field in the privilege role package container and each role information of the role data stored in the database, etc., which is not specifically limited here. The above privilege data and role data are both types of stored data.
[0081] There are multiple ways to obtain the permission data corresponding to the permission identification information and the role data corresponding to the permission data from the stored data. An optional implementation method can be to obtain the permission table, role table, and permission-role association table from the stored data. Each permission data is stored in the permission table, each role data is stored in the role table, and the association relationship between the permission data and the role data is stored in the permission-role association table. According to this association relationship, information such as which roles have a certain permission and which permissions a certain role has can be determined; based on the permission identification information, the permission data corresponding to the permission identification information is obtained from the permission table, and the role identification information corresponding to the permission identification information is obtained from the permission-role association table. This role identification information is the unique identification information of the role data and is a type of role information among various role information; thus, based on the role identification information, the role data corresponding to the role identification information can be obtained from the role table. That is to say, three interactions with the database achieve the acquisition of permission data and role data. After these data are injected into the permission-role wrapper container, one interaction with the database can achieve the acquisition of permission data and role data.
[0082] S340. Based on the permission-role mapping relationship, inject each permission information in the permission data into the corresponding permission field of the permission-role wrapper container, and inject each role information in the role data into the corresponding role field of the permission-role wrapper container.
[0083] Among them, the permission-role mapping relationship can present the mapping relationship between the permission field and the permission information, or can present the mapping relationship between the role field and the role information. Thus, based on the permission-role mapping relationship, each permission information in the permission data can be respectively injected into the corresponding permission field of the permission-role wrapper container, and each role information in the role data can be respectively injected into the corresponding role field of the permission-role wrapper container, thereby realizing the injection function of the permission data and the role data. Optionally, this process of realizing data injection based on the permission-role mapping relationship can be realized based on the ORM framework.
[0084] S350. When a trigger event for obtaining the permission-role is detected, obtain the constructed permission-role wrapper container and the permission identification information of the permission to be obtained corresponding to the trigger event.
[0085] S360. Obtain the permission to be obtained corresponding to the permission identification information and the role to be obtained corresponding to the permission to be obtained from the permission-role wrapper container.
[0086] In the technical solution of the embodiment of the present invention, by obtaining the permission role mapping relationship between the permission role package container and the stored data, and obtaining the permission data corresponding to the permission identification information and the role data corresponding to the permission data from the stored data, thus, based on the permission role mapping relationship, each permission information in the permission data can be respectively injected into the corresponding permission fields of the permission role package container, and each role information in the role data can be respectively injected into the corresponding role fields of the permission role package container, achieving the effect of effective injection of permission data and role data.
[0087] An optional technical solution is that, in order to simplify the permission role mapping relationship and achieve the effect of field and information association, the permission role mapping relationship can be determined in advance through the following steps: obtaining the permission mapping relationship between each permission field in the permission container and each permission information in the stored data, and inheriting the permission mapping relationship; setting the role mapping relationship between the role field and each role information in the stored data in the inheritance result, and determining the permission role mapping relationship according to the setting result. In particular, when the permission role package class is implemented by inheriting the permission class and adding the role set in the role class in the inheritance result, the permission role mapping relationship and the permission role package class obtained by the above technical solution can maintain a high degree of complete consistency, which can accelerate the data injection speed.
[0088] To better understand the determination process of the above permission role mapping relationship, the following combines specific examples to exemplarily illustrate the determination process of the permission role mapping relationship in the permission role acquisition method of this embodiment. Exemplarily, the specific definition of the permission mapping relationship is as follows:
[0089]
[0090]
[0091] The mapping relationship between the permission container and the permission data in the database is described by defining the permission mapping relationship with the id of basePrivilegeResult, where property represents the permission field in the permission container, and column represents the permission information (i.e., column information) of the permission data in the database.
[0092] On this basis, the specific definition of the permission role mapping relationship is as follows:
[0093]
[0094]
[0095] The mapping relationship between the privilege container and the privilege data in the database, as well as the mapping relationship between the role container and the role data in the database, is described by defining the privilege role mapping relationship with the id of "privilegeRoleListResult". Since the privilege role mapping relationship inherits from the privilege mapping relationship in the way of "extends = \"basePrivilegeResult\"", all the privilege fields in the privilege mapping relationship are already included in the privilege role mapping relationship. At this time, only the additional role fields need to be described, that is, the role fields in the "roleList" mentioned above. In practical applications, a collection can be used to represent a set, where "property" represents the role fields in the role container, and "column" represents the role information of the role data in the database.
[0096] In the actual application scenario of the embodiments of the present invention, usually, privilege data is first injected into the privilege role wrapping container, and then role data is injected into the privilege role wrapping container, that is, the privilege data is the primary data and the role data is the secondary data. However, there may be duplicate situations between the privilege information in the privilege data and the role information in the role data. For example, both may have identification information, name, operator information, update time, creation time, etc. Therefore, when injecting the privilege information or role information in the database into the privilege role wrapping container, it is difficult to determine whether to inject it into the privilege field or the role field.
[0097] To solve this problem, an optional technical solution is to inject each role information in the role data into the corresponding role field of the privilege role wrapping container based on the privilege role mapping relationship. Specifically, it may include: respectively obtaining the alias information and original name information of each role field in the privilege role wrapping container. The original name information is the original naming of the role field, and the alias information is the temporary naming of the role field. Taking the role identification information as an example, its original name information can be "r.id", and its alias information can be "r_id"; based on the naming mapping relationship between the alias information and the original name information and the privilege role mapping relationship, inject each role information in the role data into the corresponding role field corresponding to the alias information. This is because the naming of the role information in the database is the original naming. At this time, through the intermediate bridge of the alias information and the original name information, the role information in the database can be injected into the corresponding role field.
[0098] To better understand the specific execution process of the above privilege role injection function, taking the above example as an example, the execution process of the privilege role injection function in the privilege role acquisition method of this embodiment will be described exemplarily. Exemplarily, the implementation logic of the privilege role injection function is as follows: <select id="selectPrivilegeRoleList" resultMap="privilegeRoleListResult">
[0099] Here, a select tag is defined. The id of this select tag is selectPrivilegeRoleList, which is associated with the privilege role injection function in name. resultMap="privilegeRoleListResult" indicates that the return value of the privilege role injection function is the result set with the defined id of privilegeRoleListResult. The data injection function is implemented by calling the following content inside the above select tag body:
[0100]
[0101]
[0102] Specifically, query the privilege table (privilege) and rename it as p, query the role table (role) and rename it as r, and at the same time query the privilege role association table (role_privilege) and rename it as rp. Querying p.* means querying all the privilege information in the p table, and r.id means querying the id in the r table. The id comes from the r_id column in the r table, and the r_id column is the data in the above set with the id of privilegeRoleListResult. The reason for defining it as r_id is to avoid naming conflicts with the id in the p table. When defining privilegeRoleListResult, the role information is defined as a temporary alias information, such as r_id. Then, in the query statement, the naming mapping relationship between r.id and r_id is constructed in the way of r.id r_id, so as to map r.id to the corresponding role field in the above privilegeRoleListResult. Correspondingly, the rest of the role information in the r table is mapped in a similar way, which will not be elaborated here.
[0103] The query condition is where p.id = rp.privilege_id and r.id = rp.role_id. Here, the id in the p table is equal to the privilege_id in the rp table, and the id in the r table is equal to the role_id in the rp table. The intersection of the two is the set of roles of the to-be-obtained roles corresponding to the to-be-obtained permissions.
[0104] Embodiment 4
[0105] Figure 4 The following is a structural block diagram of the permission role acquisition device provided in Embodiment 4 of the present invention. This device is used to execute the permission role acquisition method provided in any of the above embodiments. This device and the permission role acquisition methods of the above embodiments belong to the same inventive concept. For the details not described in detail in the embodiment of the permission role acquisition device, reference can be made to the embodiments of the above permission role acquisition methods. Refer to Figure 4 Specifically, this device may include: a container construction module 410, a data injection module 420, a permission identification information acquisition module 430, and a permission role acquisition module 440.
[0106] Among them, the container construction module 410 is used to obtain the constructed permission container and role container, and construct a permission role package container based on the permission container and the role container;
[0107] The data injection module 420 is used to inject the permission data corresponding to PrivilegeIdentification and the role data corresponding to the permission data stored in the database into the permission role package container respectively based on the function SelectPrivilegeRoleList(PrivilegeIdentification), where PrivilegeIdentification is the permission identification information;
[0108] The permission identification information acquisition module 430 is used to obtain the to-be-obtained permissions corresponding to the permission identification information and the to-be-obtained roles corresponding to the to-be-obtained permissions from the permission role package container, where the to-be-obtained roles are the roles with the to-be-obtained permissions;
[0109] The permission role acquisition module 440 is used to obtain the constructed permission role package container and the permission identification information of the to-be-obtained permissions corresponding to the trigger event when a trigger event for acquiring permission roles is detected.
[0110] Optionally, SelectPrivilegeRoleList(PrivilegeIdentification) can implement the data injection function through the following units: a privilege-role mapping relationship acquisition unit for acquiring the privilege-role mapping relationship between the privilege-role package container and the stored data; a privilege-role acquisition unit for acquiring the privilege data corresponding to PrivilegeIdentification and the role data corresponding to the privilege data from the stored data; and a data injection unit for injecting each privilege information in the privilege data into the corresponding privilege field of the privilege-role package container respectively based on the privilege-role mapping relationship, and injecting each role information in the role data into the corresponding role field of the privilege-role package container respectively.
[0111] Optionally, the privilege-role acquisition unit can specifically be used for:
[0112] acquiring a privilege table, a role table, and a privilege-role association table from the stored data; acquiring privilege data from the privilege table based on PrivilegeIdentification and acquiring role identification information from the privilege-role association table; and acquiring role data from the role table based on the role identification information.
[0113] Optionally, the data injection unit can specifically include:
[0114] a name information acquisition subunit for acquiring the alias information and the original name information of each role field in the privilege-role package container respectively; and a role data injection subunit for injecting each role information in the role data into the role field corresponding to the corresponding alias information of the privilege-role package container respectively based on the naming mapping relationship between the alias information and the original name information and the privilege-role mapping relationship.
[0115] Optionally, the privilege-role mapping relationship can be determined in advance through the following units:
[0116] a privilege mapping relationship inheritance unit for acquiring the privilege mapping relationship between each privilege field in the privilege container and each privilege information in the stored data and inheriting the privilege mapping relationship; and a privilege-role mapping relationship determination unit for setting the role mapping relationship between the role field and each role information in the stored data in the inheritance result and determining the privilege-role mapping relationship according to the setting result.
[0117] Optionally, the privilege-role package container is a description method of the privilege-role package class, the privilege container is a description method of the privilege class, and the role container is a description method of the role class; the container construction module 410 can include:
[0118] An adding unit, which is used to inherit a privilege class and add a role set in a role class to the inheritance result; a privilege role wrapping container building unit, which is used to build a privilege role wrapping class according to the adding result and describe the privilege role wrapping class as a privilege role wrapping container.
[0119] Optionally, the adding unit can be specifically used for:
[0120] Inherit the privilege class by calling class PrivilegeRoleWrapper:Privilege(), where PrivilegeRoleWrapper is the privilege role wrapping class and Privilege is the privilege class;
[0121] By calling var roleList: MutableList <role>= mutableListOf() adds the role set in the role class to the inheritance result. Role is the role class and roleList is the role set.
[0122] In the fourth embodiment of the present invention, the permission role acquisition device, the container construction module and the data injection module cooperate with each other to construct a permission role package container based on the acquired permission container and role container, and use the permission identification information as the input parameter to call the constructed permission role injection function to inject the permission data corresponding to the permission identification information and the role data corresponding to the permission data stored in the database into the permission role package container respectively, achieving the effect of simultaneously carrying permission data and role data in the permission role package container; furthermore, the permission identification information acquisition module and the permission role acquisition module cooperate with each other. When a trigger event for acquiring permission roles is detected, the to-be-acquired permission corresponding to the permission identification information corresponding to the trigger event and the to-be-acquired role corresponding to the to-be-acquired permission can be obtained from the permission role package container. The above device achieves the effect of quickly acquiring permission data and role data by interacting with the database once and interacting with one container.
[0123] The permission role acquisition device provided by the embodiment of the present invention can execute the permission role acquisition method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0124] It should be noted that in the embodiments of the above permission role acquisition device, the included units and modules are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for easy distinction from each other and do not limit the protection scope of the present invention.
[0125] Embodiment Five
[0126] Figure 5 It is a schematic structural diagram of a device provided by the fifth embodiment of the present invention. As Figure 5 shown, the device includes a memory 510, a processor 520, an input device 530 and an output device 540. The number of processors 520 in the device can be one or more. Figure 5 Here, one processor 520 is taken as an example; the memory 510, the processor 520, the input device 530 and the output device 540 in the device can be connected through a bus or other means. Figure 5 Here, it is taken as an example of being connected through a bus 550.
[0127] The memory 510, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the permission role acquisition method in the embodiments of the present invention (for example, the container construction module 410, the data injection module 420, the permission identification information acquisition module 430, and the permission role acquisition module 440 in the permission role acquisition device). The processor 520 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 510, that is, implements the above-mentioned permission role acquisition method.
[0128] The memory 510 may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the device, etc. In addition, the memory 510 may include high-speed random access memory, and may also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 510 may further include a memory remotely set relative to the processor 520, and these remote memories can be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0129] The input device 530 can be used to receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the device. The output device 540 may include a display device such as a display screen.
[0130] Embodiment Six
[0131] Embodiment Six of the present invention provides a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute a permission role acquisition method when executed by a computer processor, including:
[0132] When a trigger event for acquiring a permission role is detected, acquire the already constructed permission role package container and the permission identification information of the permission to be acquired corresponding to the trigger event; acquire the permission to be acquired corresponding to the permission identification information and the role to be acquired corresponding to the permission to be acquired from the permission role package container, where the role to be acquired is the role with the permission to be acquired;
[0133] Among them, the permission role package container is pre-constructed through the following steps:
[0134] Obtain the constructed privilege container and role container, and construct a privilege-role package container based on the privilege container and role container; based on the function SelectPrivilegeRoleList(PrivilegeIdentification), inject the privilege data corresponding to PrivilegeIdentification and the role data corresponding to the privilege data in the stored data stored in the database into the privilege-role package container respectively, where PrivilegeIdentification is privilege identification information.
[0135] Certainly, for a storage medium containing computer-executable instructions provided by an embodiment of the present invention, the computer-executable instructions are not limited to the method operations described above, and can also execute related operations in the privilege-role acquisition method provided by any embodiment of the present invention.
[0136] From the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software and necessary general-purpose hardware. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disc of a computer, etc., including several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0137] Note that the above is only a preferred embodiment of the present invention and the applied technical principle. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described here, and various obvious changes, re-adjustments and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, it can also include more other equivalent embodiments, and the scope of the present invention is determined by the scope of the appended claims.< / role> < / privilegerolewrapper> < / privilege> < / role>
Claims
1. A method for obtaining permission roles, characterized in that, Including: When a trigger event for obtaining a permission role is detected, obtain a constructed permission role package container and permission identification information of the permission to be obtained corresponding to the trigger event; Obtain the permission to be obtained corresponding to the permission identification information and the role to be obtained corresponding to the permission to be obtained from the permission role package container, where the role to be obtained is the role with the permission to be obtained; Wherein, the permission role package container is pre-constructed through the following steps: Obtain a constructed permission container and role container, and construct the permission role package container based on the permission container and the role container; Based on the function SelectPrivilegeRoleList(PrivilegeIdentification), inject the permission data corresponding to PrivilegeIdentification and the role data corresponding to the permission data in the stored data stored in the database into the permission role package container respectively, where PrivilegeIdentification is the permission identification information.
2. The method according to claim 1, wherein The function SelectPrivilegeRoleList(PrivilegeIdentification) realizes the data injection function through the following steps: Obtain the permission role mapping relationship between the permission role package container and the stored data; Obtain the permission data corresponding to PrivilegeIdentification and the role data corresponding to the permission data from the stored data; Based on the permission role mapping relationship, inject each permission information in the permission data into the corresponding permission field of the permission role package container respectively, and inject each role information in the role data into the corresponding role field of the permission role package container respectively.
3. The method according to claim 2, wherein The obtaining the permission data corresponding to PrivilegeIdentification and the role data corresponding to the permission data from the stored data includes: Obtain a permission table, a role table and a permission role association table from the stored data; Obtain the permission data from the permission table and obtain role identification information from the permission role association table based on PrivilegeIdentification; Obtain the role data from the role table based on the role identification information.
4. The method according to claim 2, wherein The injecting each role information in the role data into the corresponding role field of the permission role package container based on the permission role mapping relationship includes: Obtain the alias information and original name information of each role field in the permission role package container respectively; Based on the naming mapping relationship between the alias information and the original name information and the permission role mapping relationship, inject each role information in the role data into the corresponding role field corresponding to the alias information of the permission role package container respectively.
5. The method according to claim 2, characterized in that The permission-role mapping relationship is determined in advance through the following steps: Obtain the permission mapping relationship between each of the permission fields in the permission container and each of the permission information in the stored data, and inherit the permission mapping relationship; Set the role mapping relationship between the role field and each of the role information in the stored data in the inheritance result, and determine the permission-role mapping relationship according to the setting result.
6. The method according to claim 1, characterized in that, The permission-role wrapper container is a description method of the permission-role wrapper class, the permission container is a description method of the permission class, and the role container is a description method of the role class; correspondingly, constructing the permission-role wrapper container based on the permission container and the role container includes: Inherit the permission class, and add the role set in the role class to the inheritance result; Construct the permission-role wrapper class according to the addition result, and describe the permission-role wrapper class as the permission-role wrapper container.
7. The method according to claim 6, wherein The inheriting the permission class and adding the role set in the role class to the inheritance result includes: Inherit the permission class by calling class PrivilegeRoleWrapper:Privilege(), where PrivilegeRoleWrapper is the permission-role wrapper class and Privilege is the permission class; By calling var roleList: MutableList <role>= mutableListOf() Add the role set in the role class to the inheritance result, Role is the role class, and roleList is the role set.< / role> 8. An apparatus for obtaining permission roles, characterized in that, Including: A permission identification information acquisition module, configured to acquire the already constructed permission-role wrapper container and the permission identification information of the to-be-acquired permission corresponding to the trigger event when detecting a trigger event for acquiring a permission-role; A permission-role acquisition module, configured to acquire the to-be-acquired permission corresponding to the permission identification information and the to-be-acquired role corresponding to the to-be-acquired permission from the permission-role wrapper container, where the to-be-acquired role is the role having the to-be-acquired permission; Among them, the permission-role wrapper container is pre-constructed through the following modules: A container construction module, configured to acquire the already constructed permission container and role container, and construct the permission-role wrapper container based on the permission container and the role container; A data injection module, configured to respectively inject the permission data corresponding to PrivilegeIdentification stored in the stored data in the database and the role data corresponding to the permission data into the permission-role wrapper container based on the function SelectPrivilegeRoleList(PrivilegeIdentification), where PrivilegeIdentification is the permission identification information.
9. A device, characterized in that, Including: One or more processors; A memory, configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the permission role acquisition method according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the permission role acquisition method according to any one of claims 1-7.
Citation Information
Patent Citations
System for optimizing collection and / or delivery trips
CN103052965A
Authority control method and device, computer equipment and storage medium
CN110290112A