Data Permission Control Method, Device and Readable Storage Medium
Control data permissions through the detection results of user mapping tables, menu mapping tables and interface mapping tables, solving the problem that existing permission management methods need to reset the code, and achieving efficient data permission control and dynamic configuration.
Patent Information
- Application Number
- CN202210172637.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-24
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-02-24
AI Technical Summary
Existing permission management methods require resetting the code separately when facing new users or needs, resulting in high resource consumption and time-consuming and labor-intensive.
By obtaining configuration instructions, using user mapping tables, menu mapping tables and interface mapping tables for detection, controlling the attribute hiding of target data based on the detection results, and achieving unified data permission control.
It improves the efficiency of data permission control, facilitates later expansion and maintenance, reduces invasive operation of system code, and realizes pluggable access and dynamic configuration.
Smart Images

Figure CN114491500B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to a data permission control method, device, and readable storage medium. Background Art
[0002] With the development of information technology, the functions of systems are becoming more and more perfect, and at the same time, the audiences they face are also increasing. Therefore, for different audiences and different scenarios, the management of permissions has become a key issue. Currently, the commonly used permission management method is to add different codes for different users and different functions. However, this method requires separate re - setting of codes every time there are new requirements or new users, resulting in a large consumption of resources and being very time - consuming and laborious. Summary of the Invention
[0003] The present invention aims to solve at least one of the technical problems existing in the prior art. For this purpose, the present invention provides a data permission control method to improve the efficiency of data permission control.
[0004] The present invention also provides a data permission control device having the above - mentioned data permission control method.
[0005] The present invention also provides an electronic device having the above - mentioned data permission control method.
[0006] The present invention also provides a computer - readable storage medium having the above - mentioned data permission control method.
[0007] One aspect of the present invention provides a data permission control method, which includes the following steps:
[0008] Obtain a configuration instruction of a target attribute, where the types of the configuration instruction include a first instruction and a second instruction; in response to the configuration instruction, search for a user mapping item in the user mapping table, determine the corresponding menu mapping table of the user mapping item, search for a menu mapping item in the menu mapping table, determine whether the menu mapping item includes an interface mapping table operated by the configuration instruction, and obtain a first detection result according to the type of the configuration instruction; according to the first detection result, search for the interface mapping table pointed to by the menu mapping item, determine whether the interface mapping item includes the target data operated by the first instruction, and obtain a second detection result; control the hiding of the target attribute corresponding to the target data according to the first detection result and the second detection result.
[0009] The data permission control method according to the embodiments of the present invention has at least the following beneficial effects: in response to a configuration instruction of a target attribute, search for a user mapping entry in the user mapping table, determine the menu mapping table corresponding to the user mapping entry, then detect the menu mapping entries in the corresponding menu mapping table, and obtain a first detection result according to whether the menu mapping entries include the interface mapping table for the operation of the configuration instruction and in combination with the type of the configuration instruction; use the first detection result to detect the interface mapping table pointed to by the menu mapping entry, and determine whether the interface mapping entries in the interface mapping table include the target data for the operation of the first instruction, so as to obtain a second detection result. Combine the first detection result and the second detection result to screen the target data, so that the target attribute corresponding to the target data is hidden. According to different configuration requirements, determine whether the target data needs to be screened, so as to uniformly set the target attribute. At this time, the settings for different functions and users do not need to be added during the system coding process, which is convenient for later expansion and maintenance and improves efficiency.
[0010] According to some embodiments of the present invention, the detection method further includes the following steps:
[0011] In response to the configuration instruction, search for a menu mapping entry in the menu mapping table. The menu mapping entry includes: a first attribute and an address pointing to an interface mapping table. Obtain a first detection result by detecting whether the first attribute includes the interface mapping table for the operation of the configuration instruction; according to the first detection result, search for the interface mapping entry in the interface mapping table. The interface mapping entry includes: a second attribute and an address pointing to the target data. Obtain a second detection result by detecting whether the second attribute includes the target data for the operation of the first instruction.
[0012] According to some embodiments of the present invention, the method for obtaining the first detection result includes at least one of the following:
[0013] When the type of the configuration instruction is a second instruction, if it is determined that the menu mapping entry includes the interface mapping table for the operation of the second instruction, then the first detection result is to obtain configuration data; or, when the type of the configuration instruction is a second instruction, if it is determined that the menu mapping entry does not include the interface mapping table for the operation of the second instruction, then the first detection result is to return the menu mapping table and continue to detect the menu mapping entry in the menu mapping table.
[0014] According to some embodiments of the present invention, the method for obtaining the first detection result includes at least one of the following:
[0015] When the type of the configuration instruction is the first instruction, if it is determined that the menu mapping item includes the interface mapping table for the operation of the first instruction, the first detection result is to detect the corresponding interface mapping table; or, when the type of the configuration instruction is the first instruction and it is determined that the menu mapping item does not include the interface mapping table for the operation of the first instruction, the first detection result is to return the menu mapping table and continue to detect the menu mapping item from the menu mapping table.
[0016] According to some embodiments of the present invention, the method for obtaining the first detection result further includes at least one of the following:
[0017] When the first detection result is to detect the corresponding interface mapping table, if it is determined that the interface mapping item includes the target data for the operation of the first instruction, the second detection result is to obtain the configuration data; or, when the first detection result is to detect the corresponding interface mapping table and it is determined that the interface mapping item does not include the target data for the operation of the first instruction, the second detection result is to return the interface mapping table and continue to detect the interface mapping item from the interface mapping table.
[0018] According to some embodiments of the present invention, the step of hiding the target attribute corresponding to the target data according to the first detection result and the second detection result includes: determining that the detection of the corresponding menu mapping table in the user mapping item is completed, returning the user mapping table and continuing to detect the user mapping item; screening the obtained configuration data based on the first detection result and the second detection result according to the menu mapping table pointed to by the user mapping item that has been detected; and sending the target attribute corresponding to the un-screened target data to the front end for display based on the correspondence between the target data and the target attribute.
[0019] According to another embodiment of the present invention, a data permission control device includes: a configuration instruction module for obtaining a configuration instruction for a target attribute, where the type of the configuration instruction includes a first instruction and a second instruction; a first detection result module for responding to the configuration instruction, finding a user mapping item from a user mapping table, determining the menu mapping table corresponding to the user mapping item, finding a menu mapping item from the menu mapping table, determining whether the menu mapping item includes the interface mapping table for the operation of the configuration instruction, and obtaining a first detection result according to the type of the configuration instruction; a second detection result module for finding the interface mapping table pointed to by the menu mapping item according to the first detection result, determining whether the interface mapping item includes the target data for the operation of the first instruction, and obtaining a second detection result; and a hiding module for controlling the hiding of the target attribute corresponding to the target data according to the first detection result and the second detection result.
[0020] The data permission control device according to an embodiment of the present invention has at least the following beneficial effects: The configuration instruction module obtains the configuration instruction of the target attribute, where the types of instructions are divided into the first instruction and the second instruction. The first detection result module receives the configuration instruction, looks up the menu mapping item from the menu mapping table according to different configuration instruction types, determines whether it includes the interface mapping table for the configuration instruction operation, and obtains the first detection result; The second detection module receives the data of the first detection result, detects the interface mapping table pointed to by the menu mapping item, looks up the interface mapping item in the interface mapping table, and determines whether the interface mapping item includes the target data for the first configuration instruction operation, and obtains the second detection result; The hiding module inputs the first detection result and the second detection result to obtain the target data to be controlled, so as to hide the target attribute corresponding to the target data. Through the data permission control device, the control of attribute permissions can be uniformly operated, without having to modify the code corresponding to each functional attribute, improving the efficiency.
[0021] According to some embodiments of the present invention, the data permission control device further includes: a return module, configured to determine that the detection of the corresponding menu mapping table in the user mapping item is completed, and return the user mapping table to continue detecting the user mapping item; a screening module, configured to screen the obtained configuration data based on the first detection result and the second detection result according to the corresponding menu mapping table pointed to by the user mapping item that has been detected; a display module, configured to return the target attribute corresponding to the un-screened target data to the front end for display based on the correspondence between the target data and the target attribute.
[0022] Another aspect of the embodiments of the present invention provides an electronic device, including a processor and a memory;
[0023] The memory is used to store a program;
[0024] The processor executes the program to implement the method described above.
[0025] The embodiments of the present invention also disclose a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device can read the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the foregoing method.
[0026] The additional aspects and advantages of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of embodiments in conjunction with the accompanying drawings, in which:
[0028] Figure 1 is a flowchart of the data permission control method provided in the first embodiment of the present invention.
[0029] Figure 2 is Figure 1 a specific flowchart of step S400 of the data permission control method shown.
[0030] Figure 3 is a schematic diagram of internal modules of the data permission control device provided in the second embodiment of the present invention. Specific Embodiments
[0031] The embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.
[0032] In the description of the present invention, the meaning of "several" is one or more, the meaning of "multiple" is two or more, and understandings such as "greater than", "less than", "exceeding", etc. do not include the present number, and understandings such as "above", "below", "within", etc. include the present number. If there is a description of "first" and "second", it is only for the purpose of distinguishing technical features and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or implicitly indicating the sequence of the indicated technical features. In the description of the present invention, the step numbers are only identifiers made for the convenience of description or citation, and the magnitudes of the sequence numbers of each step do not mean the sequence of execution. The execution sequence of each process should be determined by its function and internal logic and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0033] Embodiment 1
[0034] Refer to Figure 1 , the method of the embodiments of the present invention includes the following steps:
[0035] Step S100, obtain a configuration instruction for a target attribute, and the types of the configuration instruction include a first instruction and a second instruction.
[0036] Specifically, the configuration instructions are closely related to the user's requirements. The configuration instructions include a first instruction and a second instruction. Since each menu includes different target attributes, different types of configuration instructions are used to express the user's different configuration requirements for the target attributes located in different menus. For example, for the target attribute of mobile phone number, the user's requirement is global hiding, that is, the relevant data of the mobile phone number target attribute cannot be displayed on all menus. At this time, the configuration instruction is the second instruction; for the target attribute of university attended, the user's requirement is local hiding, that is, the user can choose which menu to hide and which menu to display according to their own needs. At this time, the configuration instruction is the first instruction. It can be understood that among different users, due to different requirements and identities, the permissions they have are also different. Therefore, for different users, the types of configuration instructions configured for different target attributes are also different.
[0037] Step S200, in response to the configuration instruction, search for the user mapping entry in the user mapping table, determine the menu mapping table corresponding to the user mapping entry, search for the menu mapping entry in the menu mapping table, determine whether the menu mapping entry includes the interface mapping table for the configuration instruction operation, and obtain the first detection result according to the type of the configuration instruction;
[0038] Step S300, according to the first detection result, search for the interface mapping table pointed to by the menu mapping entry, and determine whether the interface mapping entry includes the target data for the first instruction operation to obtain the second detection result.
[0039] Specifically, in steps S200 and S300, the detection method further includes the following steps:
[0040] In response to the configuration instruction, search for the menu mapping entry in the menu mapping table. The menu mapping entry includes: the first attribute and the address pointing to the interface mapping table. By detecting whether the first attribute includes the interface mapping table for the configuration instruction operation, obtain the first detection result;
[0041] According to the first detection result, search for the interface mapping entry in the interface mapping table. The interface mapping entry includes: the second attribute and the address pointing to the target data. By detecting whether the second attribute includes the target data for the first instruction operation, obtain the second detection result.
[0042] Specifically, after responding to the configuration instruction, look up the user mapping entry in the user mapping table. The user mapping entries in the user mapping table include the addresses pointing to the menu mapping table. The user mapping entries are used to represent different users. Therefore, the number and type of menu mapping tables pointed to by different user mapping entries do not need to be the same, that is, the menu types and numbers owned by different users are set according to requirements. Look up the menu mapping entry according to the address of the menu mapping table pointed to by the user mapping entry. The menu mapping entry includes a first attribute and the address pointing to the interface mapping table. By detecting whether the first attribute includes the interface mapping table for the configuration instruction operation and according to the type of the configuration instruction, obtain the first detection result. According to the first detection result, use the address of the interface mapping table pointed to by the menu mapping entry to look up the interface mapping table including the configuration instruction operation, and detect the interface mapping entry therein. The interface mapping entry includes a second attribute and the address pointing to the target data. The second attribute indicates whether it includes the target data for the first instruction operation, and obtain the second detection result.
[0043] In another embodiment, the method for obtaining the first detection result in step S200 includes at least one of the following:
[0044] When the type of the configuration instruction is the first instruction and it is determined that the menu mapping entry includes the interface mapping table for the first instruction operation, the first detection result is to detect the corresponding interface mapping table;
[0045] Or, when the type of the configuration instruction is the first instruction and it is determined that the menu mapping entry does not include the interface mapping table for the first instruction operation, the first detection result is to return the menu mapping table and continue to detect the menu mapping entry from the menu mapping table.
[0046] In another embodiment, the method for obtaining the second detection result in step S300 includes at least one of the following:
[0047] When the first detection result is to detect the corresponding interface mapping table and it is determined that the interface mapping entry includes the target data for the first instruction operation, the second detection result is to obtain the configuration data;
[0048] Or, when the first detection result is to detect the corresponding interface mapping table and it is determined that the interface mapping entry does not include the target data for the first instruction operation, the second detection result is to return the interface mapping table and continue to detect the interface mapping entry from the interface mapping table.
[0049] Specifically, when the configuration instruction is the first instruction, determine that the menu mapping item includes the interface mapping table for the operation of the first instruction, and the first detection result is to detect the interface mapping table through the address pointed to by the menu mapping item. If it is determined that the menu mapping item does not include the interface mapping table for the operation of the first instruction, it means that all the interface mapping items in this interface mapping table have not been operated on by the first instruction. Therefore, directly return the menu mapping table to detect whether there is an interface mapping table operated on by the first instruction in other menu mapping items. When the first detection result is to detect the corresponding interface mapping table, continue to detect the corresponding interface mapping table through the address pointed to by the menu mapping item. If it is determined that the interface mapping item includes the target data for the operation of the first instruction, then the target data corresponding to this interface mapping item is the configuration data, and the second detection result is to obtain the configuration data; if it is determined that the interface mapping item does not include the target data for the operation of the first instruction, since there are many interface mapping items in the interface mapping table, return the interface mapping table to continue to detect the situation of other interface mapping items.
[0050] In another embodiment, the method for obtaining the first detection result in step S200 at least further includes one of the following:
[0051] When the type of the configuration instruction is the second instruction, if it is determined that the menu mapping item includes the interface mapping table for the operation of the second instruction, then the first detection result is to obtain the configuration data;
[0052] Or,
[0053] When the type of the configuration instruction is the second instruction, if it is determined that the menu mapping item does not include the interface mapping table for the operation of the second instruction, then the first detection result is to return the menu mapping table and continue to detect the menu mapping items from the menu mapping table.
[0054] Specifically, when the type of the configuration instruction is the second instruction, since the menu mapping items in the menu mapping table are analogous to different target attributes in the menu, and the first attribute for detecting the menu mapping item includes the interface mapping table operated by the second instruction, it indicates that the interface mapping table pointed to by the menu mapping item has been operated by the second instruction. Then, the first detection result is to obtain the configuration data, that is, the target data pointed to by all interface mapping items in the interface mapping table. It should be noted that the menu mapping items in different menu mapping tables may point to the same interface mapping table. For example, there is an attribute of mobile phone number in the membership management menu, and there is also an attribute of mobile phone number in the membership details. Putting this relationship into the mapping table, that is, one of the menu mapping items in the membership management menu mapping table points to the interface mapping table corresponding to the mobile phone number; one of the menu mapping items in the membership details menu mapping table also points to the interface mapping table corresponding to the mobile phone number; but they point to different interface mapping items in the same interface mapping table. Based on the second instruction, the target data corresponding to all interface mapping items in the entire pointed interface mapping table is the configuration data, that is, this attribute in all menus needs to be configured according to the second instruction. If the first attribute for detecting the menu mapping item does not include the interface mapping table operated by the second instruction, it means that all interface mapping items in the interface mapping table corresponding to the entire menu mapping item have not been operated by the second instruction. Therefore, continue to return to the menu mapping table to detect the situation of other menu mapping items.
[0055] It should be noted that the interface mapping items in the interface mapping table represent different data situations of the same target attribute in different menus. For example, the mobile phone number in member management and the mobile phone number in member details are the same target attribute, but the corresponding target data is different. Therefore, according to the screening of the target data, the mobile phone number in member management and the mobile phone number in member details can be configured independently. Therefore, the situations caused by different types of configuration instructions are different. When the configuration instruction is the first instruction and it is detected that the menu mapping item points to an interface mapping table containing the first instruction, further detection is required at this time. Because the first instruction is for configuring the unique target data of the target attribute, it is also necessary to continue to detect which specific interface mapping items in the interface mapping table including the first instruction point to the target data configured by the first instruction in order to obtain the final configuration data. The second instruction is for configuring all the target data of the target attribute. Therefore, when it is detected that the menu mapping item points to an interface mapping table containing the second instruction, since the interface mapping items in an interface mapping table represent different target data of the same target attribute, it means that all the interface mapping items in the interface mapping table pointed to by this menu mapping item have been operated on by the second instruction. At this time, there is no need to further detect the pointed interface mapping table. In this way, only the configuration situation of the target data corresponding to each target attribute needs to be determined, without the need for invasive operations on the system, that is, there is no need to add code related to hidden information to the functions of each corresponding attribute. Only by configuring the target data corresponding to the target attribute can the hidden attribute information be added through the configuration instruction. When users have different requirements, only the target data that meets the user's requirements needs to be configured for this user, without the need to add code or deploy the system again, which facilitates later maintenance and also improves efficiency. Because it realizes a non-invasive setting for the system code, realizes pluggable access, reduces the cost of the system, and realizes fine-grained permission control for dynamic configuration of the system; a filtering module, such as a permission filter, is added at the unified gateway, so that it is not necessary to add it during the system coding process, which is easy to expand and maintain; all the information that needs to be hidden is realized through configuration, which is convenient for users to operate and can also adapt to various functions.
[0056] Step S400, control the hiding of the target attribute corresponding to the target data according to the first detection result and the second detection result.
[0057] In another embodiment, step S400 further includes the following steps, referring to Figure 2 :
[0058] Step S410, determine that the detection of the corresponding menu mapping table in the user mapping item is completed, and return to the user mapping table to continue detecting the user mapping item;
[0059] Step S420: Based on the corresponding menu mapping table pointed to by the user mapping item for which the detection has been completed, and based on the first detection result and the second detection result, screen the obtained configuration data;
[0060] Step S430: Based on the correspondence between the target data and the target attribute, send the target attribute corresponding to the un-screened target data to the front end for display.
[0061] Specifically, it is determined that all the corresponding menu mapping tables in the user mapping item have been detected. At this time, it means that all the menu mapping items in the corresponding menu mapping table have been detected, that is, all the interface mapping tables pointed to by the menu mapping items have also been detected, and all the interface mapping items in the interface mapping table have also been detected. At this time, the target data corresponding to the attributes of the user represented by this user mapping item has completed all configurations, and then return to the user mapping table to continue the detection of other user mapping items. Obtain the first detection result and the second detection result in the menu mapping table pointed to by the user mapping item, obtain all the configuration data therein, and screen them. After screening, the target attribute corresponding to the configuration data cannot be returned to the interface for display. For this user, the target attribute corresponding to the configuration data is hidden and cannot be viewed. That is to say, after the configuration is completed, it is detected whether the target data has been configured. After determining that the configuration has been performed, it is judged that the configuration instruction is the first instruction to obtain the target attribute corresponding to the configuration data, and it is judged that the configuration instruction is the second instruction to obtain the target attribute corresponding to the configuration data. After screening all the target attributes corresponding to the configuration data, they are returned to the client.
[0062] Embodiment 2
[0063] The device of the embodiment of the present invention is used to execute as Figure 1 shown in the method, including the following modules, referring to Figure 3 :
[0064] The configuration instruction module 100 receives configuration instructions for target attributes. The configuration instructions include a first instruction and a second instruction. The first detection result module 200 responds to the configuration instructions, searches for user mapping entries in the user mapping table, determines the corresponding menu mapping table for the user mapping entries, searches for menu mapping entries in the menu mapping table, and determines the first detection result based on the type of the configuration instructions and whether the determined menu mapping entries include an interface mapping table for the operations of the configuration instructions. The first detection result is input to the second detection result module 200. The second detection result module 200 detects the interface mapping table pointed to by the menu mapping entry according to the first detection result, determines whether the interface mapping entry includes the target data for the operations of the first instruction, and obtains the second detection result. The hiding module 300 is respectively connected to the first detection module and the second detection module, and inputs the first detection result and the second detection result into the hiding module 300. The hiding module 300 sets the target data according to the first detection result and the second detection result, so as to hide the target attributes corresponding to the target data. Among them, the hiding module 300 further includes a return module 300, which is used to determine that all the menu mapping tables corresponding to the user mapping entries have been detected, return the user mapping table to continue detecting other user mapping entries. The screening module 300 screens the obtained configuration data based on the first detection result and the second detection result detected for the user mapping entries that have been detected. The display module 300 is connected to the screening module 300, and sends the target attributes corresponding to the un-screened target data to the front end for display. It should be noted that the screening module 300 is used to screen the configuration data. For example, a column data permission filter is used to filter data permissions. By determining whether the target data of the current request is configuration data, if so, the data of the corresponding target attributes is recorded, and the data of the target attributes is screened. When sent to the front end, the data of the screened target attributes will not be displayed on the client. Among them, before determining the target data operated by the configuration instructions, the configuration data can also be cached, that is, the configuration data is placed in a specified memory space. When other interfaces access, the configuration data can be obtained from this memory space of the instruction first, and at this time, there is no need to obtain the configuration data through various mapping tables. For example, different users also want to hide the mobile phone numbers under all menus. Because a user mapping entry has obtained the corresponding configuration data in different menu mapping tables before, at this time, the configuration data is cached. When other users perform similar configurations, they only need to obtain the configuration data from the specified memory space, and there is no need to retrieve each mapping table again. Through this method, the retrieval efficiency of the configuration data is accelerated. It can be understood that all interfaces are uniformly processed through the gateway and can be adapted to multiple clients, such as web browsers, mobile terminals, etc.
[0065] Embodiment III
[0066] An embodiment of the present invention further provides an electronic device, which includes a processor and a memory;
[0067] The memory stores a program;
[0068] The processor executes the program to execute the foregoing data permission control method; the electronic device has the function of carrying and running the software system for data permission control provided by the embodiment of the present invention. For example, a personal computer (PC), a mobile phone, a smart phone, a personal digital assistant (PDA), a wearable device, a pocket PC (PPC), a tablet computer, etc.
[0069] An embodiment of the present invention further provides a computer-readable storage medium, and the storage medium stores a program, and the program is executed by a processor to implement the data permission control method as described above.
[0070] In some alternative embodiments, the functions / operations mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the functions / operations involved, two consecutive blocks shown may actually be executed substantially simultaneously or the blocks can sometimes be executed in the reverse order. In addition, the embodiments presented and described in the flowcharts of the present invention are provided by way of example for the purpose of providing a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logical flows presented herein. Alternative embodiments are contemplated, in which the order of various operations is changed and sub-operations described as part of a larger operation are executed independently.
[0071] An embodiment of the present invention also discloses a computer program product or a computer program, which includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device can read the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the foregoing data permission control method.
[0072] In addition, although the present invention has been described in the context of functional modules, it should be understood that, unless otherwise stated to the contrary, one or more of the described functions and / or features may be integrated in a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It should also be understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present invention. Rather, given the attributes, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the modules will be understood within the ordinary skills of an engineer. Thus, those skilled in the art can implement the present invention as set forth in the claims without undue experimentation. It should also be understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.
[0073] If the described function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0074] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a predefined sequence of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in conjunction with such instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0075] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection (electronic device) having one or more wirings, a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which the program can be printed, as the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or, if necessary, other suitable processing, and then stored in a computer memory.
[0076] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0077] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0078] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the claims and their equivalents.
[0079] The above has specifically described the preferred embodiments of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art can also make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of this application.
Claims
1. A data permission control method, characterized in that It includes the following steps: Obtain a configuration instruction for a target attribute, where the types of the configuration instruction include a first instruction and a second instruction; wherein, the first instruction is a configuration instruction for locally hiding the target attribute, and the second instruction is a configuration instruction for globally hiding the target attribute; In response to the configuration instruction, look up a user mapping entry from the user mapping table, determine the corresponding menu mapping table of the user mapping entry, look up a menu mapping entry from the menu mapping table, determine whether the menu mapping entry includes an interface mapping table for the operation of the configuration instruction, and obtain a first detection result according to the type of the configuration instruction; According to the first detection result, look up the interface mapping table pointed to by the menu mapping entry, and determine whether the interface mapping entry includes the target data for the operation of the first instruction to obtain a second detection result; Control the hiding of the target attribute corresponding to the target data according to the first detection result and the second detection result; Wherein, when the type of the configuration instruction is the second instruction and it is determined that the menu mapping entry includes the interface mapping table for the operation of the second instruction, the first detection result is to obtain configuration data; at this time, the target data pointed to by all interface mapping entries in the interface mapping table is configuration data; Or, When the type of the configuration instruction is the second instruction and it is determined that the menu mapping entry does not include the interface mapping table for the operation of the second instruction, the first detection result is to return the menu mapping table and continue to detect the menu mapping entry from the menu mapping table; Or, When the type of the configuration instruction is the first instruction and it is determined that the menu mapping entry includes the interface mapping table for the operation of the first instruction, the first detection result is to detect the corresponding interface mapping table; when the first detection result is to detect the corresponding interface mapping table and it is determined that the interface mapping entry includes the target data for the operation of the first instruction, the second detection result is to obtain configuration data; Or, When the type of the configuration instruction is the first instruction and it is determined that the menu mapping entry does not include the interface mapping table for the operation of the first instruction, the first detection result is to return the menu mapping table and continue to detect the menu mapping entry from the menu mapping table.
2. The data permission control method according to claim 1, wherein The detection method further includes the following steps: In response to the configuration instruction, look up a menu mapping entry from the menu mapping table, where the menu mapping entry includes: a first attribute and an address pointing to an interface mapping table, and obtain a first detection result by detecting whether the first attribute includes the interface mapping table for the operation of the configuration instruction; Look up the interface mapping entry from the interface mapping table according to the first detection result, where the interface mapping entry includes: a second attribute and an address pointing to the target data, and obtain a second detection result by detecting whether the second attribute includes the target data for the operation of the first instruction.
3. The data permission control method according to claim 1, wherein The method for obtaining the second detection result further includes: When the first detection result is to detect the corresponding interface mapping table and it is determined that the interface mapping entry does not include the target data for the operation of the first instruction, the second detection result is to return the interface mapping table and continue to detect the interface mapping entry from the interface mapping table.
4. The data permission control method according to claim 1 or 3, characterized in that Controlling the hiding of the target attribute corresponding to the target data according to the first detection result and the second detection result includes: Determining that the detection of the corresponding menu mapping table in the user mapping item is completed, and returning to the user mapping table to continue detecting the user mapping item; According to the menu mapping table corresponding to the user mapping item for which the detection has been completed, filtering the obtained configuration data based on the first detection result and the second detection result; Based on the correspondence between the target data and the target attribute, sending the target attribute corresponding to the unfiltered target data to the front end for display.
5. A data permission control device, characterized in that, It includes: A configuration instruction module for obtaining a configuration instruction for a target attribute, where the types of the configuration instruction include a first instruction and a second instruction; wherein, the first instruction is a configuration instruction for locally hiding the target attribute, and the second instruction is a configuration instruction for globally hiding the target attribute; A first detection result module for responding to the configuration instruction, searching for a user mapping item in the user mapping table, determining the menu mapping table corresponding to the user mapping item, searching for a menu mapping item in the menu mapping table, determining whether the menu mapping item includes an interface mapping table for the operation of the configuration instruction, and obtaining a first detection result according to the type of the configuration instruction; A second detection result module for, according to the first detection result, searching for the interface mapping table pointed to by the menu mapping item, and determining whether the interface mapping item includes the target data for the operation of the first instruction, to obtain a second detection result; A hiding module for controlling the hiding of the target attribute corresponding to the target data according to the first detection result and the second detection result; Wherein, when the type of the configuration instruction is the second instruction and it is determined that the menu mapping item includes the interface mapping table for the operation of the second instruction, the first detection result is to obtain configuration data; at this time, the target data pointed to by all interface mapping items in the interface mapping table is configuration data; Or, When the type of the configuration instruction is the second instruction and it is determined that the menu mapping item does not include the interface mapping table for the operation of the second instruction, the first detection result is to return the menu mapping table and continue detecting the menu mapping item from the menu mapping table; Or, When the type of the configuration instruction is the first instruction and it is determined that the menu mapping item includes the interface mapping table for the operation of the first instruction, the first detection result is to detect the corresponding interface mapping table; when the first detection result is to detect the corresponding interface mapping table and it is determined that the interface mapping item includes the target data for the operation of the first instruction, the second detection result is to obtain configuration data; Or, When the type of the configuration instruction is the first instruction and it is determined that the menu mapping item does not include the interface mapping table for the operation of the first instruction, the first detection result is to return the menu mapping table and continue detecting the menu mapping item from the menu mapping table.
6. The data permission control device according to claim 5, characterized in that The hiding module further includes: A return module for determining that the detection of the corresponding menu mapping table in the user mapping item is completed, and returning to the user mapping table to continue detecting the user mapping item; A screening module, configured to screen the obtained configuration data based on a first detection result and a second detection result according to the corresponding menu mapping table pointed to by the user mapping item for which the detection has been completed; A display module, configured to send the target attribute corresponding to the un-screened target data to the front end for display based on the correspondence between the target data and the target attribute; 7. An electronic device, characterized in that, It includes a processor and a memory; The memory is used to store programs; The processor executes the program to implement the method according to any one of claims 1-4; 8. A computer-readable storage medium, characterized in that, The storage medium stores a program, and the program is executed by the processor to implement the method according to any one of claims 1-4.
Citation Information
Patent Citations
User operation authority control method and device, equipment and medium
CN110287709A