A permission control method, device, equipment and storage medium

By obtaining the operation permissions of the parent object of the target object and restricting the operation permissions of the target object, the information security problem during information sharing is solved and the security of information is ensured.

CN115146317BActive Publication Date: 2025-05-16BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210907326.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-29
Publication Date
2025-05-16
Estimated Expiration
2042-07-29

AI Technical Summary

Technical Problem

During the information sharing process, how to effectively ensure information security and prevent security risks caused by excessive information permissions.

Method used

By obtaining the first operation permission of the target operation of the parent object of the target object, and determining based on this, the target operation permission of the target object allows the set operation permission to make it less than or equal to the first operation permission, thereby limiting the operation permission of the target object.

Benefits of technology

It effectively avoids information security issues caused by excessive target operation permissions of target objects and ensures information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115146317B_ABST
    Figure CN115146317B_ABST
Patent Text Reader

Abstract

The present application discloses a permission control method, comprising: obtaining a first operation permission of a target operation of a parent object of a target object, and determining the operation permission that is allowed to be set for the target operation of the target object based on the first operation permission, wherein the operation permission that is allowed to be set is less than or equal to the first operation permission. It can be seen that in an embodiment of the present application, for the target operation of the target object, the operation permission that can be set is constrained by the first operation permission of the target operation of the parent object of the target object, and the operation permission of the target operation of the target object cannot be greater than the first operation permission. In this way, it is possible to avoid information security problems caused by excessive operation permission of the target operation of the target object. Therefore, using this solution can effectively ensure information security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a permission control method, device, equipment and storage medium. Background Art

[0002] With the development of computer technology, information can be shared through the network. For example, documents can be shared through the network.

[0003] However, in the process of information sharing, information security issues may arise. Therefore, how to ensure information security is a problem that has yet to be solved. Summary of the invention

[0004] In order to solve or partially solve the above technical problems, the embodiments of the present application provide a permission control method, apparatus, device and storage medium.

[0005] In a first aspect, an embodiment of the present application provides a permission control method, the method comprising:

[0006] Get the first operation permission of the target operation of the parent object of the target object;

[0007] Based on the first operation authority, an operation authority that is allowed to be set for the target operation of the target object is determined, wherein the operation authority that is allowed to be set is less than or equal to the first operation authority.

[0008] Optionally, the method further includes:

[0009] In a case where the operation authority of the target operation of the target object is determined to be a second operation authority, a correspondence between the second operation authority and the target operation of the target object is saved, wherein the operation authority allowed to be set includes the second operation authority.

[0010] Optional,

[0011] The second operation authority inherits the first operation authority; or,

[0012] The second operation permission is an operation permission set by a user.

[0013] Optionally, the method further includes:

[0014] A prompt message is sent, where the prompt message is used to prompt that a target operation permission for the target object cannot be set, and the target operation permission is an operation permission greater than the first operation permission.

[0015] Optionally, the method further includes:

[0016] In response to the modification operation on the first operation permission, obtaining a third operation permission for the target operation of the parent object;

[0017] Based on the third operation authority, the operation authority of the target operation of the target object is updated.

[0018] Optionally, updating the operation permission of the target operation of the target object based on the third operation permission includes:

[0019] If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority.

[0020] Optionally, updating the operation permission of the target operation of the target object based on the third operation permission includes:

[0021] If the third operation authority is smaller than the second operation authority, the operation authority of the target operation of the target object is modified from the second operation authority to the third operation authority.

[0022] Optionally, the target object includes any one of the following:

[0023] Files, folders, and knowledge spaces.

[0024] Optional,

[0025] When the target object is a file, the parent object of the target object is a file or a folder;

[0026] When the target object is a folder, the parent object of the target object is a folder or a knowledge space;

[0027] When the target object is a knowledge space, the parent object of the target object is a tenant space.

[0028] Optionally, the target operation includes any one or more of the following:

[0029] Add collaborators for the target object, download the target object, and comment on the target object.

[0030] In a second aspect, an embodiment of the present application provides a permission control method, the method comprising:

[0031] Receive permission setting operation for target operation on target object;

[0032] In response to the permission setting operation, displaying a permission setting page, the permission setting page including a plurality of operation permissions for the target object, the plurality of operation permissions including an operation permission that is allowed to be set, the operation permission that is allowed to be set is less than or equal to a first operation permission, the first operation permission being the operation permission of the target operation of a parent object of the target object;

[0033] In response to a user's selection operation on a second operation permission among the operation permissions allowed to be set, the operation permission of the target operation of the target object is set as the second operation permission.

[0034] Optionally, the multiple operation permissions also include a target operation permission, and the permission setting page also includes prompt information of the target operation permission, the target operation permission is an operation permission greater than the first operation permission, and the prompt information is used to prompt that the target operation permission cannot be set.

[0035] Optionally, the method further includes:

[0036] In response to the modification operation on the first operation permission, obtaining a third operation permission for the target operation of the parent object;

[0037] Based on the third operation authority, the operation authority of the target operation of the target object is updated.

[0038] Optionally, updating the operation permission of the target operation of the target object based on the third operation permission includes:

[0039] If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority.

[0040] Optionally, updating the operation permission of the target operation of the target object based on the third operation permission includes:

[0041] If the third operation authority is smaller than the second operation authority, the operation authority of the target operation of the target object is modified from the second operation authority to the third operation authority.

[0042] Optionally, the target object includes any one of the following:

[0043] Files, folders, and knowledge spaces.

[0044] Optional,

[0045] When the target object is a file, the parent object of the target object is a file or a folder;

[0046] When the target object is a folder, the parent object of the target object is a folder or a knowledge space;

[0047] When the target object is a knowledge space, the parent object of the target object is a tenant space.

[0048] Optionally, the target operation includes any one or more of the following:

[0049] Add collaborators for the target object, download the target object, and comment on the target object.

[0050] In a third aspect, an embodiment of the present application provides a permission control device, the device comprising:

[0051] A first acquisition unit, used to acquire a first operation permission for a target operation of a parent object of the target object;

[0052] A determining unit is configured to determine, based on the first operating authority, an operating authority that is allowed to be set for the target operation of the target object, wherein the operating authority that is allowed to be set is less than or equal to the first operating authority.

[0053] Optionally, the device further comprises:

[0054] A saving unit is used to save the correspondence between the second operation permission and the target operation of the target object when the operation permission of the target operation of the target object is determined to be the second operation permission, wherein the operation permission allowed to be set includes the second operation permission.

[0055] Optional,

[0056] The second operation authority inherits the first operation authority; or,

[0057] The second operation permission is an operation permission set by a user.

[0058] Optionally, the device further comprises:

[0059] The sending unit is used to send a prompt message, wherein the prompt message is used to prompt that the target operation permission for the target object cannot be set, and the target operation permission is an operation permission greater than the first operation permission.

[0060] Optionally, the device further comprises:

[0061] A second acquisition unit, configured to acquire a third operation permission of a target operation of the parent object in response to a modification operation on the first operation permission;

[0062] An updating unit is used to update the operation permission of the target operation of the target object based on the third operation permission.

[0063] Optionally, the updating unit is used to:

[0064] If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority.

[0065] Optionally, the updating unit is used to:

[0066] If the third operation authority is smaller than the second operation authority, the operation authority of the target operation of the target object is modified from the second operation authority to the third operation authority.

[0067] Optionally, the target object includes any one of the following:

[0068] Files, folders, and knowledge spaces.

[0069] Optional,

[0070] When the target object is a file, the parent object of the target object is a file or a folder;

[0071] When the target object is a folder, the parent object of the target object is a folder or a knowledge space;

[0072] When the target object is a knowledge space, the parent object of the target object is a tenant space.

[0073] Optionally, the target operation includes any one or more of the following:

[0074] Add collaborators for the target object, download the target object, and comment on the target object.

[0075] In a fourth aspect, an embodiment of the present application provides a permission control device, the device comprising:

[0076] A receiving unit, used to receive a permission setting operation for a target operation on a target object;

[0077] a display unit, configured to display a permission setting page in response to the permission setting operation, wherein the permission setting page includes a plurality of operation permissions for the target object, wherein the plurality of operation permissions include an operation permission that is allowed to be set, wherein the operation permission that is allowed to be set is less than or equal to a first operation permission, and wherein the first operation permission is an operation permission for the target operation of a parent object of the target object;

[0078] The setting unit is configured to set the operation permission of the target operation of the target object as the second operation permission in response to a user's selection operation on a second operation permission among the operation permissions allowed to be set.

[0079] Optionally, the multiple operation permissions also include a target operation permission, and the permission setting page also includes prompt information of the target operation permission, the target operation permission is an operation permission greater than the first operation permission, and the prompt information is used to prompt that the target operation permission cannot be set.

[0080] Optionally, the device further comprises:

[0081] an acquisition unit, configured to acquire a third operation permission of a target operation of the parent object in response to a modification operation on the first operation permission;

[0082] An updating unit is used to update the operation permission of the target operation of the target object based on the third operation permission.

[0083] Optionally, the updating unit is used to:

[0084] If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority.

[0085] Optionally, the updating unit is used to:

[0086] If the third operation authority is smaller than the second operation authority, the operation authority of the target operation of the target object is modified from the second operation authority to the third operation authority.

[0087] Optionally, the target object includes any one of the following:

[0088] Files, folders, and knowledge spaces.

[0089] Optional,

[0090] When the target object is a file, the parent object of the target object is a file or a folder;

[0091] When the target object is a folder, the parent object of the target object is a folder or a knowledge space;

[0092] When the target object is a knowledge space, the parent object of the target object is a tenant space.

[0093] Optionally, the target operation includes any one or more of the following:

[0094] Add collaborators for the target object, download the target object, and comment on the target object.

[0095] In a fifth aspect, an embodiment of the present application provides a device, the device comprising a processor and a memory;

[0096] The processor is used to execute instructions stored in the memory so that the device executes the method described in any one of the first aspects above, or so that the device executes the method described in any one of the second aspects above.

[0097] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, comprising instructions, wherein the instructions instruct a device to execute any method described in the first aspect above, or the instructions instruct a device to execute any method described in the second aspect above.

[0098] In the seventh aspect, an embodiment of the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the method described in any one of the first aspect above, or enables the computer to execute the method described in any one of the second aspect above.

[0099] Compared with the prior art, the embodiments of the present application have the following advantages:

[0100] The embodiment of the present application provides a permission control method, including: obtaining a first operation permission of a target operation of a parent object of a target object, and based on the first operation permission, determining the operation permission that is allowed to be set for the target operation of the target object, wherein the operation permission that is allowed to be set is less than or equal to the first operation permission. It can be seen that in the embodiment of the present application, for the target operation of the target object, the operation permission that can be set is constrained by the first operation permission of the target operation of the parent object of the target object, and the operation permission of the target operation of the target object cannot be greater than the first operation permission. In this way, it is possible to avoid information security problems caused by excessive operation permission of the target operation of the target object. Therefore, using this solution, information security can be effectively guaranteed.

[0101] The embodiment of the present application provides a permission control method, including: after a user triggers a permission setting operation for a target operation of a target object, after receiving the permission setting operation, and in response to the permission setting operation, a permission setting page is displayed. The permission setting page includes multiple operation permissions for the target object, the multiple operation permissions include an operation permission that is allowed to be set, the operation permission that is allowed to be set is less than or equal to a first operation permission, and the first operation permission is the operation permission of the target operation of the parent object of the target object. Further, the user can trigger a selection operation for one of the operation permissions that are allowed to be set. After the user triggers a selection operation for a second operation permission in the operation permission that is allowed to be set, the operation permission of the target operation of the target object can be set to the second operation permission in response to the selection operation. It can be seen from this that in the embodiment of the present application, when setting the target operation of the target object, the operation permission that can be set is constrained by the first operation permission of the target operation of the parent object of the target object, and the operation permission of the target operation of the target object cannot be greater than the first operation permission, so that the operation permission of the target operation of the target object is too large and brings information security problems. Therefore, using this solution, information security can be effectively guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0102] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0103] Figure 1 A flowchart of a permission control method provided in an embodiment of the present application;

[0104] Figure 2 A flowchart of a permission setting method provided in an embodiment of the present application;

[0105] Figure 3 A schematic diagram of the structure of a permission control device provided in an embodiment of the present application;

[0106] Figure 4 A schematic diagram of the structure of another permission control device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0107] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0108] The inventor of the present application has found through research that information may face information security issues during the sharing process. For example, for a target object, a user (e.g., a shared party) can trigger corresponding operations for the target object. For some operations, it may bring about greater information security issues, such as adding a collaboration group, downloading, and commenting. In order to avoid information security risks caused by the above improper operations, the permissions for such operations can be controlled to ensure information security.

[0109] In view of this, embodiments of the present application provide a permission control method, apparatus, device and storage medium.

[0110] Various non-limiting implementations of the present application are described in detail below in conjunction with the accompanying drawings.

[0111] Exemplary Methods

[0112] See also Figure 1 , which is a flowchart of a permission control method provided in an embodiment of the present application. In this embodiment, Figure 1 The permission control method shown can be executed by the server or by the client, and is not specifically limited in the embodiments of the present application.

[0113] In an example, the method may include the following steps: S101 - S102 .

[0114] S101: Obtain a first operation permission for a target operation of a parent object of a target object.

[0115] In an embodiment of the present application, the target object may be any object shared through a network. In one example, the target object may be a file, such as a document. In another example, the target object may be a folder. In another example, the target object may also be a knowledge space, which may be understood as a space that carries knowledge (or content). In the knowledge space, a file may be used as a carrier of knowledge (or content).

[0116] In the embodiment of the present application, the parent object of the target object refers to the object corresponding to the parent node of the corresponding node of the target object after the object is abstracted into a node. In the embodiment of the present application, similar to the target object, the parent object of the target object can also be any object shared through the network.

[0117] In one example, when the target object is a file, considering that a file may include multiple child files, the parent object may also be a file. In addition, considering that a folder may include multiple files, when the target object is a file, the parent object of the target object may be a folder.

[0118] In another example, when the target object is a folder, the folder may include other folders, so the parent object of the target object may also be a folder. In addition, considering that a knowledge space may include multiple folders, the parent object of the target object may be a knowledge space.

[0119] In another example, when the target object is a knowledge space, considering that the tenant space may include the knowledge space, the parent object of the target object may be the tenant space. The tenant space mentioned here refers to a space provided for tenants to carry knowledge (or content), wherein the tenant refers to an individual user or user organization using the technical solution involved in this application.

[0120] In the embodiment of the present application, the target operation may be an operation supported by the target object. In some examples, the target operation may be an operation that has a greater impact on information security. In some examples, considering that adding collaborators to the target object, downloading the target object, and commenting on the target object may all bring about greater information security issues, the target operation may be one or more of adding collaborators to the target object, downloading the target object, and commenting on the target object.

[0121] The embodiment of the present application does not specifically limit the first operation permission, and the first operation permission may be the current operation permission of the target operation of the parent object. For example, if the target operation is downloading, the first operation permission may be, for example, that readers can download.

[0122] S102: Based on the first operation authority, determine the operation authority that is allowed to be set for the target operation of the target object, wherein the operation authority that is allowed to be set is less than or equal to the first operation authority.

[0123] In an embodiment of the present application, in order to avoid information security problems caused by improper operations being performed on the target object, in an embodiment of the present application, the operation authority of the target operation of the target object can be controlled. Specifically, the operation authority that the target operation of the target object is allowed to be set can be determined based on the first operation authority of the parent object. For the target operation of the target object, the operation authority that can be set is constrained by the first operation authority of the target operation of the parent object of the target object. The reason for doing so is that the parent object can accommodate more content, and among the many contents it accommodates, its requirements for information security are different. Therefore, the operation authority of the target operation of the parent object can be set more loosely. Correspondingly, the operation authority of the target operation of the target object cannot be greater than the first operation authority. In this way, it can avoid the operation authority of the target operation of the target object being too large and causing information security problems.

[0124] In one example, when the operation permission of the target operation of the target object is determined to be the second operation permission, the correspondence between the second operation permission and the target operation of the target object can be saved. The second operation permission can be one of the operation permissions that the target operation of the target object is allowed to be set.

[0125] Regarding the second operation permission, it should be noted that, in one example, if the user actively sets the operation permission of the target operation of the target object, the second operation permission may be the operation permission set by the user. In another example, if the user does not actively set the operation permission of the target operation of the target object, the second operation permission may inherit the first operation permission by default. In this case, the second operation permission may be the same as the first operation permission.

[0126] In one example, if the target object has stricter requirements on the operation authority of the target operation than its parent object, the user can actively set the operation authority of the target operation of the target object, for example, setting the operation authority of the target operation of the target object to a second operation authority that is smaller than the first operation authority. If the target object has similar requirements on the operation authority of the target operation than its parent object, the user may not actively set the operation authority of the target operation of the target object. In this case, the operation authority of the target operation of the target object may inherit the first operation authority.

[0127] Next, combine Figure 2 , describes how users can set the operation permissions for target operations on target objects. Figure 2 , which is a flow chart of a permission setting method provided in an embodiment of the present application. Figure 2The method shown can be executed by the client or by the server, and is not specifically limited in the embodiments of the present application.

[0128] In a specific example, Figure 1 The method shown can be executed by the server. Figure 2 The method shown can be executed by a client corresponding to the server.

[0129] Figure 2 The method shown may include the following S201-S203.

[0130] S201: Receive a permission setting operation for a target operation on a target object.

[0131] In one example, the user may trigger a permission setting operation for a target operation of the target object through the first control. After the user triggers the permission setting operation for the target operation of the target object, the permission setting operation may be received.

[0132] S202: In response to the permission setting operation, a permission setting page is displayed, wherein the permission setting page includes multiple operation permissions for the target object, wherein the multiple operation permissions include an operation permission that is allowed to be set, wherein the operation permission that is allowed to be set is less than or equal to a first operation permission, and the first operation permission is the operation permission for the target operation of the parent object of the target object.

[0133] In one example, after receiving the permission setting operation, a permission setting page may be displayed, and the permission setting page may include multiple operation permissions for the target object. The multiple operation permissions include the operation permission that the target operation of the target object allows to be set.

[0134] It is not difficult to understand that, for multiple operation permissions of the target operation of the target object, based on the first operation permission, the multiple operation permissions can be divided into two parts, one part is the operation permission that the target operation of the target object is allowed to be set, and the other part is the target operation permission, and the target operation permission is the operation permission that the target operation of the target object is not allowed to be set. In one example, after determining the operation permission that the target operation of the target object is allowed to be set, a prompt message can be sent. For example, when the method is executed by the server, the server can send the prompt message to the client, and the prompt message is used to prompt that the target operation permission for the target object cannot be set, and the target operation permission is an operation permission greater than the first operation permission. In one example, for this case, the permission setting page can also include the target operation permission and the prompt information of the target operation permission. Accordingly, the user can determine that the target operation permission cannot be set based on the prompt message.

[0135] In one example, the multiple operation permissions may be displayed in a drop-down menu, wherein the display style of the target operation permission is different from the display style of the operation permissions allowed to be set. For example, the target operation permission is grayed out, and the operation permissions allowed to be set are displayed normally.

[0136] S203: In response to a user selecting a second operation permission among the operation permissions allowed to be set, setting the operation permission of the target operation of the target object as the second operation permission.

[0137] In one example, a user can trigger a selection operation for a second operation permission in the operation permissions allowed to be set displayed in the permission setting page. Accordingly, after receiving the trigger selection operation for the second operation permission, the operation permission for the target operation of the target object can be set to the second operation permission in response to the selection operation. Here, "setting the operation permission for the target operation of the target object to the second operation permission" can, for example, be saving the corresponding relationship between the second operation permission and the target operation of the target object.

[0138] In another example, in order to avoid the user triggering a selection operation for the target operation permission when setting the operation permission for the target operation of the target object, in an embodiment of the present application, the target operation permission does not support being selected, or in other words, after the user triggers a selection operation for any one of the target operation permissions, the selection operation may not be responded to.

[0139] In one example, considering that the operation permissions of the target operation of the parent object of the target object may change, for example, the user modifies the operation permissions of the target operation of the parent object, and changes the operation permissions of the target operation of the parent object from the first operation permissions to the third operation permissions, in this case, in an embodiment of the present application, the third operation permissions can be obtained, and based on the third operation permissions, the operation permissions of the target operation of the target object can be updated, thereby avoiding information security issues caused by the mismatch between the aforementioned second operation permissions and the third operation permissions.

[0140] In one example, if the third operating permission is greater than or equal to the second operating permission, it means that the second operating permission does not exceed the permission scope limited by the third operating permission. In this case, the operating permission of the target operation of the target object is the second operating permission, which theoretically will not cause major information security problems. Therefore, in this case, the operating permission of the target operation of the target object can be maintained as the second operating permission unchanged.

[0141] In another example, if the third operation permission is less than the second operation permission, it means that the second operation permission exceeds the permission range defined by the third operation permission. In this case, the operation permission of the target operation of the target object is the second operation permission, which may bring information security problems. Therefore, in this case, the operation permission of the target operation of the target object can be modified from the second operation permission to the third operation permission. Of course, the user can also modify the operation permission of the target operation of the target object to a fourth operation permission that is less than the third operation permission, which is not specifically limited in the embodiment of the present application.

[0142] Exemplary Devices

[0143] Based on the method provided in the above embodiment, the embodiment of the present application further provides a device, which is described below in conjunction with the accompanying drawings.

[0144] See also Figure 3 , which is a structural diagram of a permission control device provided in an embodiment of the present application. Figure 3 The authority control device 300 shown may specifically include, for example: a first obtaining unit 301 and a determining unit 302 .

[0145] A first acquisition unit 301 is used to acquire a first operation permission for a target operation of a parent object of a target object;

[0146] The determining unit 302 is configured to determine, based on the first operating authority, an operating authority that is allowed to be set for the target operation of the target object, wherein the operating authority that is allowed to be set is less than or equal to the first operating authority.

[0147] Optionally, the device further comprises:

[0148] A saving unit is used to save the correspondence between the second operation permission and the target operation of the target object when the operation permission of the target operation of the target object is determined to be the second operation permission, wherein the operation permission allowed to be set includes the second operation permission.

[0149] Optional,

[0150] The second operation authority inherits the first operation authority; or,

[0151] The second operation permission is an operation permission set by a user.

[0152] Optionally, the device further comprises:

[0153] The sending unit is used to send a prompt message, wherein the prompt message is used to prompt that the target operation permission for the target object cannot be set, and the target operation permission is an operation permission greater than the first operation permission.

[0154] Optionally, the device further comprises:

[0155] A second acquisition unit, configured to acquire a third operation permission of a target operation of the parent object in response to a modification operation on the first operation permission;

[0156] An updating unit is used to update the operation permission of the target operation of the target object based on the third operation permission.

[0157] Optionally, the updating unit is used to:

[0158] If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority.

[0159] Optionally, the updating unit is used to:

[0160] If the third operation authority is smaller than the second operation authority, the operation authority of the target operation of the target object is modified from the second operation authority to the third operation authority.

[0161] Optionally, the target object includes any one of the following:

[0162] Files, folders, and knowledge spaces.

[0163] Optional,

[0164] When the target object is a file, the parent object of the target object is a file or a folder;

[0165] When the target object is a folder, the parent object of the target object is a folder or a knowledge space;

[0166] When the target object is a knowledge space, the parent object of the target object is a tenant space.

[0167] Optionally, the target operation includes any one or more of the following:

[0168] Add collaborators for the target object, download the target object, and comment on the target object.

[0169] Since the device 300 is provided by the above method embodiment, Figure 1The device corresponding to the corresponding permission control method and the specific implementation of each unit of the device 300 are all based on the same concept as the above method embodiment. Therefore, for the specific implementation of each unit of the device 300, please refer to the relevant description part of the above method embodiment, which will not be repeated here.

[0170] See also Figure 4 , which is a structural diagram of another permission control device provided in an embodiment of the present application. Figure 4 The authority control device 400 shown may specifically include, for example: a receiving unit 401 , a display unit 402 , and a setting unit 403 .

[0171] The receiving unit 401 is used to receive a permission setting operation for a target operation on a target object;

[0172] A display unit 402 is used to display a permission setting page in response to the permission setting operation, wherein the permission setting page includes multiple operation permissions for the target object, the multiple operation permissions include an operation permission that is allowed to be set, the operation permission that is allowed to be set is less than or equal to a first operation permission, and the first operation permission is the operation permission of the target operation of a parent object of the target object;

[0173] The setting unit 403 is configured to set the operation permission of the target operation of the target object as the second operation permission in response to a user selecting the second operation permission among the operation permissions allowed to be set.

[0174] Optionally, the multiple operation permissions also include a target operation permission, and the permission setting page also includes prompt information of the target operation permission, the target operation permission is an operation permission greater than the first operation permission, and the prompt information is used to prompt that the target operation permission cannot be set.

[0175] Optionally, the device further comprises:

[0176] an acquisition unit, configured to acquire a third operation permission of a target operation of the parent object in response to a modification operation on the first operation permission;

[0177] An updating unit is used to update the operation permission of the target operation of the target object based on the third operation permission.

[0178] Optionally, the updating unit is used to:

[0179] If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority.

[0180] Optionally, the updating unit is used to:

[0181] If the third operation authority is smaller than the second operation authority, the operation authority of the target operation of the target object is modified from the second operation authority to the third operation authority.

[0182] Optionally, the target object includes any one of the following:

[0183] Files, folders, and knowledge spaces.

[0184] Optional,

[0185] When the target object is a file, the parent object of the target object is a file or a folder;

[0186] When the target object is a folder, the parent object of the target object is a folder or a knowledge space;

[0187] When the target object is a knowledge space, the parent object of the target object is a tenant space.

[0188] Optionally, the target operation includes any one or more of the following:

[0189] Add collaborators for the target object, download the target object, and comment on the target object.

[0190] Since the device 400 is provided with the above method embodiment Figure 2 The device corresponding to the corresponding permission control method and the specific implementation of each unit of the device 400 are all based on the same concept as the above method embodiment. Therefore, for the specific implementation of each unit of the device 400, please refer to the relevant description part of the above method embodiment, which will not be repeated here.

[0191] The embodiment of the present application also provides a device, the device comprising a processor and a memory;

[0192] The processor is used to execute instructions stored in the memory so that the device executes the permission control method described in any one of the above method embodiments.

[0193] An embodiment of the present application provides a computer-readable storage medium, including instructions, wherein the instructions instruct a device to execute the permission control method described in any one of the above method embodiments.

[0194] An embodiment of the present application provides a computer program product. When the computer program product is run on a computer, the computer is enabled to execute the permission control method described in any one of the above method embodiments.

[0195] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0196] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

[0197] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the protection scope of the present application.

Claims

1. A permission control method, characterized in that: The method comprises: Get the first operation permission of the target operation of the parent object of the target object; Based on the first operation authority, determining an operation authority that is allowed to be set for the target operation of the target object, wherein the operation authority that is allowed to be set is less than or equal to the first operation authority; When the operation permission of the target operation of the target object is determined to be a second operation permission, saving a correspondence between the second operation permission and the target operation of the target object, wherein the operation permission allowed to be set includes the second operation permission; In response to the modification operation on the first operation permission, obtaining a third operation permission for the target operation of the parent object; If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained at the second operation authority; or, if the third operation authority is less than the second operation authority, the operation authority of the target operation of the target object is changed from the second operation authority to the third operation authority.

2. The method according to claim 1, characterized in that The second operation authority inherits the first operation authority; or, The second operation permission is an operation permission set by a user.

3. The method according to claim 1, characterized in that The method further comprises: A prompt message is sent, where the prompt message is used to prompt that a target operation permission for the target object cannot be set, and the target operation permission is an operation permission greater than the first operation permission.

4. The method according to claim 1, characterized in that: The target object includes any of the following: Files, folders, and knowledge spaces.

5. The method according to claim 4, characterized in that When the target object is a file, the parent object of the target object is a file or a folder; When the target object is a folder, the parent object of the target object is a folder or a knowledge space; When the target object is a knowledge space, the parent object of the target object is a tenant space.

6. The method according to claim 1, characterized in that The target operation includes any one or more of the following: Add collaborators for the target object, download the target object, and comment on the target object.

7. A permission control method, characterized in that: The method comprises: Receive permission setting operation for target operation on target object; In response to the permission setting operation, displaying a permission setting page, the permission setting page including a plurality of operation permissions for the target object, the plurality of operation permissions including an operation permission that is allowed to be set, the operation permission that is allowed to be set is less than or equal to a first operation permission, the first operation permission being the operation permission of the target operation of a parent object of the target object; In response to a user selecting a second operation permission among the operation permissions allowed to be set, setting the operation permission of the target operation of the target object to the second operation permission; In response to the modification operation on the first operation permission, obtaining a third operation permission for the target operation of the parent object; If the third operation authority is greater than or equal to the second operation authority, the operation authority of the target operation of the target object is maintained as the second operation authority; or, if the third operation authority is less than the second operation authority, the operation authority of the target operation of the target object is changed from the second operation authority to the third operation authority.

8. The method according to claim 7, characterized in that The multiple operation permissions also include a target operation permission, and the permission setting page also includes prompt information of the target operation permission. The target operation permission is an operation permission greater than the first operation permission, and the prompt information is used to prompt that the target operation permission cannot be set.

9. The method according to claim 7, characterized in that: The target object includes any of the following: Files, folders, and knowledge spaces.

10. The method according to claim 9, characterized in that When the target object is a file, the parent object of the target object is a file or a folder; When the target object is a folder, the parent object of the target object is a folder or a knowledge space; When the target object is a knowledge space, the parent object of the target object is a tenant space.

11. The method according to claim 7, characterized in that The target operation includes any one or more of the following: Add collaborators for the target object, download the target object, and comment on the target object.

12. A permission control device, characterized in that: The device comprises: A first acquisition unit, used to acquire a first operation permission for a target operation of a parent object of the target object; a determining unit, configured to determine, based on the first operation permission, an operation permission that is allowed to be set for the target operation of the target object, wherein the operation permission that is allowed to be set is less than or equal to the first operation permission; a saving unit, configured to save, when the operation permission of the target operation of the target object is determined to be a second operation permission, a corresponding relationship between the second operation permission and the target operation of the target object, wherein the operation permission allowed to be set includes the second operation permission; A second acquisition unit, configured to acquire a third operation permission of a target operation of the parent object in response to a modification operation on the first operation permission; An updating unit is used to: if the third operation authority is greater than or equal to the second operation authority, maintain the operation authority of the target operation of the target object as the second operation authority; or, if the third operation authority is less than the second operation authority, change the operation authority of the target operation of the target object from the second operation authority to the third operation authority.

13. A permission control device, characterized in that: The device comprises: A receiving unit, used to receive a permission setting operation for a target operation on a target object; a display unit, configured to display a permission setting page in response to the permission setting operation, wherein the permission setting page includes a plurality of operation permissions for the target object, wherein the plurality of operation permissions include an operation permission that is allowed to be set, wherein the operation permission that is allowed to be set is less than or equal to a first operation permission, and wherein the first operation permission is an operation permission for the target operation of a parent object of the target object; A setting unit, configured to set the operation permission of the target operation of the target object to the second operation permission in response to a user's selection operation on the second operation permission among the operation permissions allowed to be set; an acquisition unit, configured to acquire a third operation permission of a target operation of the parent object in response to a modification operation on the first operation permission; An updating unit is used to: if the third operation authority is greater than or equal to the second operation authority, maintain the operation authority of the target operation of the target object as the second operation authority; or, if the third operation authority is less than the second operation authority, change the operation authority of the target operation of the target object from the second operation authority to the third operation authority.

14. A device, characterized in that The device comprises a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the device performs the method according to any one of claims 1 to 11.

15. A computer-readable storage medium, characterized in that: The method comprises instructions for instructing a device to execute the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Decentralized management method and system

    CN106302483A