A permission management method, device, electronic device and storage medium
By obtaining page hierarchical structure data based on the routing table and generating permission data files with hierarchical relationships, the performance problems caused by cumbersome permission configuration operations and flat data structures in the prior art are solved, and more efficient permission management is achieved.
Patent Information
- Application Number
- CN202210435056.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-04-24
AI Technical Summary
In the prior art, the permission configuration method is cumbersome and prone to misconfiguration. Due to the flat data structure, the empowerment operation requires traversing a large amount of data, which affects the system performance.
By obtaining page hierarchical structure data based on the routing table, obtaining the first feature data of the operable elements in the page and the second feature data of the operable elements in the module, generating a permission data file with hierarchical relationships, and optimizing the data structure of the permission data.
It reduces the number of times the permission data is traversed during the page and module empowerment process, reduces the data collection workload, avoids errors caused by manual data collection, and improves system performance.
Smart Images

Figure CN114741730B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a permission management method, device, electronic device and storage medium. Background Art
[0002] A page is a window that displays system resources to users. It determines whether a user has the right to use system resources and which system resources the user has the right to use by pre-configuring permissions based on the user's role.
[0003] Currently, the commonly used permission configuration methods include: manually configuring permission data in the database. Or, manually adding permissions for each routing table and module operation permissions through the permission management system. Then, adding role-related menus and modules based on user roles, and finally associating personnel IDs with user roles to complete permission configuration.
[0004] However, the permission configuration method in the related art is cumbersome and prone to misconfiguration when there are many system menus or modules. In addition, most of the permission data is a flat data structure. When granting permissions to pages and functional modules, it is necessary to traverse the entire permission data multiple times. The large amount of data that needs to be traversed in the authorization operation may affect the system performance due to the traversal algorithm, and even cause the system to crash. Summary of the invention
[0005] The embodiments of the present invention provide a permission management method, device, electronic device and storage medium, which can optimize the data structure of permission data and solve the problem that the flat data structure of the current permission data causes a large amount of data to be traversed in the authorization operation.
[0006] According to one aspect of the present invention, a method for managing permissions is provided, comprising:
[0007] Acquire page hierarchical structure data based on the routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path;
[0008] Acquire the first characteristic data of the operable element in the page according to the page reference path, and acquire the module introduction path of the module introduced in the page;
[0009] Determine a module introduction path according to the module introduction file, and obtain second characteristic data of an operability element in the module according to the module introduction path;
[0010] Generate a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure.
[0011] According to another aspect of the present invention, there is provided a permission management device, comprising:
[0012] A structure data acquisition module, used for acquiring page hierarchical structure data based on a routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path;
[0013] A first feature data acquisition module, used to acquire first feature data of operable elements in the page according to the page reference path, and to acquire a module introduction path of an introduced module in the page;
[0014] A second characteristic data acquisition module, used to determine the module introduction path according to the module introduction file, and acquire the second characteristic data of the operability element in the module according to the module introduction path;
[0015] The file generation module is used to generate a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure.
[0016] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0017] at least one processor; and
[0018] a memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the permission management method described in any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the permission management method described in any embodiment of the present invention when executed.
[0021] The technical solution of the embodiment of the present invention obtains the page hierarchy structure through a routing table, obtains the first characteristic data of the operable elements in the page and the second characteristic data of the operable elements in the module, and generates a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure, which solves the problem that the current flat data structure of the permission data causes a large amount of data to be traversed in the authorization operation, optimizes the data structure of the permission data, and reduces the number of times the permission data is traversed during the page and module authorization process; in addition, by automatically collecting the first characteristic data and the second characteristic data and generating a permission data file, automatic collection of permission data is achieved, the workload of data collection is reduced, and errors caused by manual data collection are avoided.
[0022] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 A flowchart of a method for managing permissions provided by an embodiment of the present invention;
[0025] Figure 2 A structural diagram of a data structure tree in a method for managing permissions provided by an embodiment of the present invention;
[0026] Figure 3 A flowchart of another permission management method provided by an embodiment of the present invention;
[0027] Figure 4 A schematic diagram of the structure of a permission management device provided by an embodiment of the present invention;
[0028] Figure 5 FIG. 1 is a schematic diagram of the structure of an electronic device that can be used to implement an embodiment of the present invention. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprises" and "comprising" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] Figure 1 This is a flowchart of a permission management method provided by an embodiment of the present invention. This embodiment can be applied to the situation of managing access rights and operation rights of pages and modules during the development of a web application (Web APP). The method can be executed by a permission management device, which can be implemented in the form of hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method includes:
[0032] S110 . Acquire page hierarchical structure data based on the routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path.
[0033] Among them, the routing table realizes the correspondence between URLs and components by managing URLs, and switches between components through URLs. For example, when a button is clicked, the jump path from the button to the page to be jumped is determined by the routing table. The routing hierarchy structure represents the hierarchical relationship between pages with nested relationships. The routing hierarchy is determined based on the jump path in the routing table. References between pages of different levels are realized through routing. For example: A and B belong to pages of different levels in the menu, and there is a route from A to B, then the route is used to jump from page A to page B.
[0034] The page hierarchy data is the page feature data within pages of different levels that are associated through routing. The page hierarchy can be determined based on the routing hierarchy of the page. For example, for the route A→B→C→E, the routing hierarchy is page A jumps to page B, page B is transferred to page C, and page C jumps to page E. The corresponding page hierarchy is that E is the next level page of C, C is the next level page of B, and B is the next level page of A. The page reference path indicates the file location of the page file. For example, the page reference path can be a URL, etc.
[0035] Exemplarily, any page in the system is taken as the current page, the page hierarchy structure is determined based on the routing hierarchy structure of the current page in the routing table, and the page feature data of each level managed by the current page is obtained based on the page hierarchy structure. The page hierarchy structure data is determined according to the page hierarchy structure and the page reference path in the page feature data. For example, based on the routing hierarchy structure of page A in the routing table, the page feature data of each level page in the corresponding routing parameter is captured. Specifically, the page feature data can be the name of the page and the page reference path attribute.
[0036] S120, acquiring first characteristic data of operable elements in the page according to the page reference path, and acquiring a module introduction path of an introduced module in the page.
[0037] The operable elements in the page are elements in the page that can be operated by the user, for example, the operable elements include buttons, text boxes or links, etc. The first characteristic data is the characteristic attribute data of the operable elements in the page. For example, the first characteristic data includes identification parameters of the elements and operation-related parameters, etc. Specifically, the operation-related parameters can be configuration parameters related to the operation of the operable elements in the page.
[0038] The imported module is a component module that is introduced into the page to implement a specific function. A page can import a module, a module can import a submodule, and a submodule can import a submodule. The module import path represents the hierarchical relationship and file directory between pages and modules, or between modules and submodules, or between submodules and submodules with a nested relationship. The module import path can be determined by the instruction method of module import.
[0039] The modules introduced in the pages of users with different roles may be different. For example, the approval module will be introduced in the page of users with approval roles, but it will not be introduced in the page of users with ordinary roles.
[0040] Exemplarily, the directory where the page file is located is determined according to the page reference path, and the page file is obtained from the directory where the page file is located. The page file includes the first element name of the operable element in the page, the first operation information, the introduced module and the module introduction path, etc. For example, through the page reference path, use Node.js to read the directory where the file is located, and read the page file from the directory where the file is located. Get the element name name of the operable element in the page file and the operation-related parameters. Get the first element name and the first operation information of the operable element in the page in the page file of the current page, and use the first element name and the first operation information as the first feature data. Before obtaining the feature data of the introduced module, use Node.js to read the module introduction path of the introduced module in the current page.
[0041] Specifically, based on the routing hierarchy structure, crawlers and other technologies are used to capture the page hierarchy data of each level in the routing table, and the first characteristic data of the operable elements in the page are obtained layer by layer. For example, based on the routing hierarchy structure, the page name name and page reference path path attributes of the first-level page are captured from the routing table. Then, through the page reference path, Node.js is used to read the directory where the corresponding page file is located. The file content is read from the directory where the page file is located, and the element name name and operation-related parameters of the first operable element that needs permission control contained in the first-level page are read from the file content.
[0042] In one case, if the first-level page has a sub-page, the routing hierarchy of the current sub-page is determined according to the routing of the sub-page, and the page hierarchy data of the sub-page is captured by crawler technology based on the routing hierarchy of the current sub-page. The data capture method is the same as that of the first-level page, and will not be repeated here. If there is a sub-page at a lower level, the above operation is repeated until there is no sub-page at a lower level.
[0043] S130. Acquire second characteristic data of operability elements in the module according to the module introduction path.
[0044] The second characteristic data is characteristic attribute data of the operable elements in the module. For example, the second characteristic data includes identification parameters of the elements and operation-related parameters, etc. Specifically, the operation-related parameters may be configuration parameters related to the operation of the operable elements in the module.
[0045] Exemplarily, the directory where the module file is located is determined according to the module import path, and the module file is obtained from the directory where the module file is located. The module file includes the second element name and the second operation information of the operable element in the module. The second element name and the second operation information of the operable element in the module in the module file are obtained, and the second element name and the second operation information are used as the second feature data.
[0046] Specifically, for a first-level page, the module import path of each import module imported by the page is obtained. For the first-level import module, the corresponding module file is obtained according to the module import path, and the element name name and operation-related parameters of the second operable element that needs permission control in the import module in the module file are read.
[0047] In one case, if there is a second-level import module (i.e., a submodule imported by an import module), the corresponding first-level submodule file is obtained according to the module import path of the second-level import module, and the element name name and operation-related information of the second operable element requiring permission control in the submodule in the first-level submodule file are read. If there is a third-level import module (i.e., a submodule imported by a submodule), the above operation is repeated until there is no import module at the next level.
[0048] S140: Generate a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure.
[0049] The permission data file is a collection of first characteristic data and second characteristic data in a hierarchical relationship, and the data structure in the permission data file is a vertical data structure. Specifically, the permission data file includes the element names and operation-related parameters of the operable elements in the page, and also includes the element names and operation-related parameters of the operable elements in the module, and these data are distributed vertically.
[0050] Exemplarily, the first characteristic data and / or the second characteristic data belonging to the same level are determined based on the page hierarchy structure. In a manner that the first characteristic data and / or the second characteristic data belonging to the same level are used as the same layer of the data structure tree, a data structure tree is generated based on the first characteristic data and the second characteristic data, and a permission data file containing the data structure tree is generated. Wherein, the node of the data structure tree is the first characteristic data or the second characteristic data.
[0051] Specifically, the distribution rules of feature data are as follows:
[0052] In one case, feature data belonging to the same level is determined based on the page hierarchy structure. If the feature data of a certain level are all first feature data, the first feature data of the level are taken as the same layer of the data structure tree.
[0053] In one case, feature data belonging to the same level is determined based on the page hierarchy structure. If the feature data of a certain level are all second feature data, the second feature data of the level are taken as the same layer of the data structure tree.
[0054] In one case, feature data belonging to the same level is determined based on the page hierarchy structure. If the feature data of a certain level includes first feature data and second feature data, the first feature data and second feature data of the level are taken as the same layer of the data structure tree.
[0055] A data structure tree is generated according to the distribution rule of the characteristic data, and a permission data file including the data structure tree is generated based on the data structure tree. Figure 2The structure diagram of the data structure tree in the permission management method provided by the embodiment of the present invention is as follows. Figure 2 As shown, the menu is the root node, and its child nodes include the first characteristic data of the operable elements in the first-level page 11, the first-level page 12 and the first-level page 13 respectively. Since the page levels of the first-level pages are the same, the corresponding first characteristic data are located at the same level of the data structure tree. In one case, if the first-level page 11 includes a module 21 and a second-level page 21, the child node of the first characteristic data of the first-level page includes the second characteristic data of the module 21 and the first characteristic data of the second-level page 21. The second characteristic data of the module 21 and the first characteristic data of the second-level page 21 are located at the same level of the data structure tree. In another case, if the first-level page 22 includes a module 22 and a module 23, the child node of the first characteristic data of the first-level page includes the second characteristic data of the module 22, and also includes the second characteristic data of the module 23. The second characteristic data of the module 22 and the second characteristic data of the module 23 are located at the same level of the data structure tree. If the module also includes a sub-module, or the second-level page also includes a sub-page, the level of the second characteristic data corresponding to the sub-module and the first characteristic data corresponding to the sub-page in the data structure tree is determined in the above manner.
[0056] The embodiment of the present invention obtains the page hierarchy structure through a routing table, obtains the first characteristic data of the operable elements in the page and the second characteristic data of the operable elements in the module, and generates a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure, thereby solving the problem that the current flat data structure of the permission data causes a large amount of data to be traversed in the authorization operation, optimizes the data structure of the permission data, and reduces the number of times the permission data is traversed during the page and module authorization process; in addition, by automatically collecting the first characteristic data and the second characteristic data and generating a permission data file, automatic collection of permission data is achieved, the workload of data collection is reduced, and errors caused by manual data collection are avoided.
[0057] Figure 3 This is a flowchart of another permission management method provided by an embodiment of the present invention. This embodiment grants access rights and operation rights to pages and modules based on the permission data file generated in the above embodiment. Figure 3 As shown, the method includes:
[0058] S301 , determining the page hierarchical structure based on the routing hierarchical structure of the page in the routing table, and acquiring page feature data of each level associated with the page.
[0059] S302: Determine page hierarchical structure data according to the page hierarchical structure and the page reference path in the page feature data.
[0060] S303: Determine the directory where the page file is located according to the page reference path, and obtain the page file from the directory where the page file is located.
[0061] S304: Obtain a first element name and first operation information of an operable element in the page in the page file, and use the first element name and first operation information as the first feature data.
[0062] S305: Obtain a module import path of the module imported into the page in the page file.
[0063] S306: Determine the directory where the module file is located according to the module import path, and obtain the module file from the directory where the module file is located.
[0064] S307: Obtain a second element name and second operation information of an operable element in the module in the module file, and use the second element name and second operation information as the second feature data.
[0065] S308: Determine first characteristic data and / or second characteristic data belonging to the same level based on the page hierarchical structure.
[0066] S309: Generate a data structure tree based on the first characteristic data and the second characteristic data, taking the first characteristic data and / or the second characteristic data of the same level as the same layer of the data structure tree, and generate a permission data file including the data structure tree.
[0067] S310: Obtain permission configuration information of users with different roles.
[0068] The permission configuration information is the information related to the access rights and operation rights of the pages and modules configured by the user. The permission configuration information is based on the user role configuration. Before the system goes online, the access rights and operation rights of the pages and modules of users with different roles can be configured. Since the feature data in the permission data file is distributed in a structure tree, the child nodes are subject to the parent node permissions, and the grandchild nodes are subject to the child node permissions. Therefore, you only need to set the parent node permissions, and all child nodes belonging to the parent node will automatically obtain the corresponding permissions.
[0069] S311, traverse the data structure tree in the permission data file layer by layer, obtain the first characteristic data of each level, for each level, match the permission configuration information with the first characteristic data, and register the pages corresponding to the matched target first characteristic data to the routing table and menu component one by one.
[0070] The menu component is used to display the loading entry of the subpage. According to different page hierarchical structures, a page can include multiple levels of menus such as primary menu, secondary menu and tertiary menu, and the first feature data of the page corresponding to each level of menu is registered to the menu component step by step.
[0071] Exemplarily, for the permission configuration information of each role, the first characteristic data of the first-level page corresponding to the first-level menu in the permission data file is traversed, and the first characteristic data of the first-level page is matched with the permission configuration information. The target first characteristic data in the first characteristic data that matches the permission configuration information is registered one by one to the routing table and the menu component. Specifically, the element name in the first characteristic data is matched with the element name in the permission configuration information. If there is a second-level menu under the above-mentioned first-level menu, the first characteristic data of the second-level page corresponding to the second-level menu under the first-level menu is traversed in the permission data file, and the first characteristic data of the second-level page is matched with the permission configuration information. The target first characteristic data in the first characteristic data that matches the permission configuration information is registered one by one to the routing table and the menu component. If there is a third-level menu under the second-level menu, a similar method is adopted to register the target first characteristic data in the third-level menu to the routing table and the menu component until the dynamic registration of all hierarchical menus is completed.
[0072] For example, based on the configuration information, it is shown that a certain role user can only access 3 pages out of the 10 pages corresponding to the first-level menu, and the first feature data of the 3 matching pages will be registered to the routing table and menu component. For each page corresponding to the first-level menu, if there is a second-level menu, and based on the configuration information, it is shown that the role user can only access 5 pages out of the 8 pages corresponding to the second-level menu, the first feature data of the 5 matching pages will be registered to the routing table and menu component. If there is also a third-level menu, the target first feature data corresponding to the third-level menu will be registered to the routing table and menu component in the same way until the dynamic registration of all levels of menus is completed. It should be noted that for the pages registered to the routing table and menu components, the corresponding role user has the corresponding permissions.
[0073] S312: Obtain target second characteristic data corresponding to the target first characteristic data in the second characteristic data, and add the target second characteristic data to the routing metadata of the routing table.
[0074] Routing metadata, also called meta data, is the information carried in each routing table.
[0075] Exemplarily, for each target first characteristic data, the target second characteristic data having a parent-child node relationship with the current target first characteristic data is obtained from the second characteristic data of the permission data file, and the target second characteristic data is added to the routing metadata of the routing table. If the introduction module in a certain page also introduces a sub-module, the second characteristic data of the sub-module having a parent-child node relationship with the target second characteristic data is added to the routing metadata of the routing table, and so on, until the second characteristic data corresponding to the leaf node of the data structure tree is added to the routing metadata of the routing table. Therefore, the second characteristic data has a hierarchical relationship in the routing metadata, and the second characteristic data of the parent node is at a higher level than the second characteristic data of the child node. It can be understood that for the introduction module mounted in the routing metadata, it has the same permission configuration information as the page to which it belongs.
[0076] S313: For each page corresponding to the target first characteristic data, obtain the target second characteristic data in the routing metadata of the routing table, and compare the target second characteristic data with the characteristic attributes of the introduction module of the corresponding level.
[0077] The page corresponding to each target first characteristic data is the page registered to the routing table and the menu component. The characteristic attribute is an attribute that can uniquely identify the operable element introduced into the module. For example, the characteristic attribute can be the element name of the operable element in the module.
[0078] Exemplarily, each registered page is used as the current page, and the target second characteristic data in the routing metadata of the routing table is obtained according to the hierarchical relationship. Since the module introduction path reflects the introduction level of the introduced module, the second characteristic data of the introduced module in the current page can be obtained layer by layer based on the module introduction path. The target second characteristic data is compared with the second characteristic data of the corresponding level. Specifically, the element name in the target second characteristic data of the same level is compared with the element name in the second characteristic data of the introduced module to determine whether the element name is consistent.
[0079] S314. Determine the operation authority of the corresponding introduced module according to the comparison result of the characteristic attribute at the same level with the target second characteristic data.
[0080] The operation authority includes authorized operation or unauthorized operation. For the imported modules that are unauthorized to operate, the authority control can be deleted, hidden or disabled.
[0081] Exemplarily, if the element name of the imported module data at the same level is consistent with the element name of the target second characteristic data, the corresponding imported module is granted the same authority as the target second characteristic data. If the element name of the target second characteristic data at the same level is found to be consistent with the imported module data, it is determined that the role user has no right to operate the corresponding imported module.
[0082] The embodiment of the present invention traverses the permission data file, registers the page to the routing table and the menu component layer by layer, and adds the second characteristic data of the imported module in the page to the routing metadata of the routing table. Therefore, when empowering the imported module, the target second characteristic data can be obtained from the routing metadata, avoiding traversing the entire permission data file again, reducing the number of times the permission data file is traversed during the empowerment process of the page and the imported module, and reducing the impact of permission changes on system performance; since the data in the permission data file is distributed in a structure tree, the difficulty of permission management and permission adjustment caused by role adjustment is reduced; in addition, the present embodiment realizes automatic permission control of the page and the imported module, reduces the workload of manually embedding each imported module in turn, and reduces the problem of permission control failure caused by wrong embedding and missing embedding.
[0083] Figure 4 A schematic diagram of the structure of a permission management device provided by an embodiment of the present invention. Figure 4 As shown, the device includes: a structure data acquisition module 410, a first feature data acquisition module 420, a second feature data acquisition module 430 and a file generation module 440.
[0084] The structure data acquisition module 410 is used to acquire page hierarchical structure data based on the routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path;
[0085] A first feature data acquisition module 420, configured to acquire first feature data of operable elements in a page according to the page reference path, and to acquire a module introduction path of an introduced module in the page;
[0086] A second characteristic data acquisition module 430, configured to determine a module introduction path according to a module introduction file, and acquire second characteristic data of an operability element in the module according to the module introduction path;
[0087] The file generation module 440 is used to generate a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure.
[0088] Optionally, the structure data acquisition module 410 is specifically configured to execute:
[0089] Determine the page hierarchy structure based on the routing hierarchy structure of the page in the routing table, and obtain page feature data of each hierarchy associated with the page;
[0090] The page hierarchical structure data is determined according to the page hierarchical structure and the page reference path in the page characteristic data.
[0091] Optionally, the first feature data acquisition module 420 is specifically configured to execute:
[0092] Determine the directory where the page file is located according to the page reference path, and obtain the page file from the directory where the page file is located;
[0093] Acquire a first element name and first operation information of an operable element in the page in the page file, and use the first element name and the first operation information as the first feature data;
[0094] Get the module import path of the module imported into the page in the page file.
[0095] Optionally, the second feature data acquisition module 430 is specifically configured to execute:
[0096] Determine the directory where the module file is located according to the module import path, and obtain the module file from the directory where the module file is located;
[0097] The second element name and the second operation information of the operable element in the module in the module file are obtained, and the second element name and the second operation information are used as the second feature data.
[0098] Optionally, the file generation module 440 is specifically used for:
[0099] Determine first characteristic data and / or second characteristic data belonging to the same level based on the page hierarchical structure;
[0100] A data structure tree is generated based on the first characteristic data and the second characteristic data in a manner that the first characteristic data and / or the second characteristic data belonging to the same level are used as the same layer of the data structure tree, and a permission data file including the data structure tree is generated.
[0101] Optionally, the device further comprises:
[0102] A page registration module 450 is used to obtain permission configuration information of users of different roles after generating the permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure;
[0103] Traversing the data structure tree in the permission data file layer by layer, obtaining the first characteristic data of each layer, matching the permission configuration information with the first characteristic data for each layer, and registering the pages corresponding to the matched target first characteristic data to the routing table and menu component one by one;
[0104] The target second characteristic data corresponding to the target first characteristic data in the second characteristic data is obtained, and the target second characteristic data is added to the routing metadata of the routing table.
[0105] Optionally, the device further comprises:
[0106] A module weighting module 460 is used to execute, after adding the target second characteristic data to the routing metadata of the routing table, for each page corresponding to the target first characteristic data, obtaining the target second characteristic data in the routing metadata of the routing table, and comparing the target second characteristic data with the characteristic attributes of the introduction module of the corresponding level;
[0107] The operation authority of the corresponding introduced module is determined according to the comparison result of the characteristic attribute at the same level and the target second characteristic data.
[0108] The permission management device provided in the embodiment of the present invention can execute the permission management method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0109] Figure 5 1 is a block diagram of an electronic device 10 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as smart phones and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0110] like Figure 5 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0111] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0112] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a method for managing permissions.
[0113] In some embodiments, the permission management method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the permission management method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the following permission management method by any other appropriate means (e.g., by means of firmware):
[0114] Acquire page hierarchical structure data based on the routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path;
[0115] Acquire the first characteristic data of the operable element in the page according to the page reference path, and acquire the module introduction path of the module introduced in the page;
[0116] Acquire second characteristic data of operability elements in the module according to the module introduction path;
[0117] Generate a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure.
[0118] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0119] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0120] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0121] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0122] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0123] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for managing permissions, characterized in that: include: Acquire page hierarchical structure data based on the routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path, the page hierarchical structure is a routing hierarchical structure of a current page in the routing table, and the page reference path is a file location of a page file; Acquire first characteristic data of an operable element in the page according to the page reference path, and acquire a module introduction path of an introduced module in the page; Acquire second characteristic data of operability elements in the module according to the module introduction path; Generate a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure; The obtaining of page hierarchical structure data based on the routing table includes: Determine the page hierarchy structure based on the routing hierarchy structure of the page in the routing table, and obtain page feature data of each hierarchy associated with the page; Determine page hierarchical structure data according to the page hierarchical structure and the page reference path in the page characteristic data; The acquiring the first characteristic data of the operable element in the page according to the page reference path, and acquiring the module introduction path of the module introduced in the page, comprises: Determine the directory where the page file is located according to the page reference path, and obtain the page file from the directory where the page file is located; Acquire a first element name and first operation information of an operable element in the page in the page file, and use the first element name and the first operation information as the first feature data; Obtain a module import path of the module imported into the page in the page file; The step of acquiring the second characteristic data of the operability element in the module according to the module introduction path includes: Determine the directory where the module file is located according to the module import path, and obtain the module file from the directory where the module file is located; Acquire a second element name and a second operation information of an operable element in a module in the module file, and use the second element name and the second operation information as the second feature data; The generating the permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure includes: Determine first characteristic data and / or second characteristic data belonging to the same level based on the page hierarchical structure; A data structure tree is generated based on the first characteristic data and the second characteristic data in a manner that the first characteristic data and / or the second characteristic data belonging to the same level are used as the same layer of the data structure tree, and a permission data file including the data structure tree is generated.
2. The method according to claim 1, characterized in that After generating the permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure, the method further includes: Get permission configuration information for users with different roles; Traversing the data structure tree in the permission data file layer by layer, obtaining the first characteristic data of each layer, matching the permission configuration information with the first characteristic data for each layer, and registering the pages corresponding to the matched target first characteristic data to the routing table and menu component one by one; Obtain target second characteristic data corresponding to the target first characteristic data in the second characteristic data, and add the target second characteristic data to the routing metadata of the routing table.
3. The method according to claim 2, characterized in that After adding the target second characteristic data to the routing metadata of the routing table, the method further includes: For each page corresponding to the first target characteristic data, obtaining the second target characteristic data in the routing metadata of the routing table, and comparing the second target characteristic data with the characteristic attributes of the introduction module of the corresponding level; The operation authority of the corresponding introduced module is determined according to the comparison result of the characteristic attribute at the same level and the target second characteristic data.
4. A permission management device, characterized in that: include: A structure data acquisition module, used to acquire page hierarchical structure data based on a routing table, wherein the page hierarchical structure data includes a page hierarchical structure and a page reference path, the page hierarchical structure is a routing hierarchical structure of a current page in the routing table, and the page reference path is a file location of a page file; A first feature data acquisition module, used to acquire first feature data of operable elements in the page according to the page reference path, and to acquire a module introduction path of an introduced module in the page; A second characteristic data acquisition module, used for acquiring the second characteristic data of the operability elements in the module according to the path introduced by the module; A file generation module, used for generating a permission data file based on the first characteristic data and the second characteristic data according to the page hierarchy structure; The structure data acquisition module is specifically used to execute: Determine the page hierarchy structure based on the routing hierarchy structure of the page in the routing table, and obtain page feature data of each hierarchy associated with the page; Determine page hierarchical structure data according to the page hierarchical structure and the page reference path in the page characteristic data; The first feature data acquisition module is specifically used to execute: Determine the directory where the page file is located according to the page reference path, and obtain the page file from the directory where the page file is located; Acquire a first element name and first operation information of an operable element in the page in the page file, and use the first element name and the first operation information as the first feature data; Obtain a module import path of the module imported into the page in the page file; The second feature data acquisition module is specifically used to execute: Determine the directory where the module file is located according to the module import path, and obtain the module file from the directory where the module file is located; Acquire a second element name and a second operation information of an operable element in a module in the module file, and use the second element name and the second operation information as the second feature data; The file generation module is specifically used for: Determine first characteristic data and / or second characteristic data belonging to the same level based on the page hierarchical structure; A data structure tree is generated based on the first characteristic data and the second characteristic data in a manner that the first characteristic data and / or the second characteristic data belonging to the same level are used as the same layer of the data structure tree, and a permission data file including the data structure tree is generated.
5. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for managing rights according to any one of claims 1 to 3.
6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the permission management method according to any one of claims 1 to 3 when executed.
Citation Information
Patent Citations
Permission management method and system
CN111988337A
Vue development method and device based on CRUD and permission management
CN112016128A