Method and apparatus for controlling permissions, computing device, and storage medium
By introducing a permission control module and verification interface into the Linux operating system, and generating a menu page to control the permissions of applications and third-party application modules, the security and ease of operation issues of the gsetting permission management method are solved, and secure and stable permission management is achieved.
Patent Information
- Application Number
- CN202210693247.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-17
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2042-06-17
AI Technical Summary
In existing Linux operating systems, the permission management method based on gsetting is easily tampered with, which is inconvenient and insecure for users, resulting in unstable permission management.
This invention provides an access control method that displays a verification interface through an access control module. After verifying user permissions, a menu page is generated. Users can operate on target menu items on the menu page to enable or disable the corresponding modules, including access control for modules of third-party applications.
It achieves secure and stable access control for applications and third-party application modules, reduces user errors, and improves system stability and security.
Smart Images

Figure CN115186239B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, and in particular, to a permission control method, a permission control device, a computing device and a storage medium. BACKGROUND
[0002] At present, in the Linux operating system, the opening or closing (display or hiding) of some application modules is generally in the form of gsetting. Third-party manufacturers and software developers need to use gsetting to configure the information of the modules that need to be opened or closed for permission control, so as to realize the permission management function of the module opening or closing operation. The permission management mode based on gsetting has the disadvantages of being easy to tamper with, being available only after user login, and being difficult for users to operate. Therefore, the existing permission management scheme is not safe and is not easy to operate.
[0003] Therefore, a permission control method is needed to solve the problems in the above scheme. SUMMARY
[0004] Therefore, the present application provides a permission control method and a permission control device to solve or at least alleviate the above problems.
[0005] According to one aspect of the present application, a permission control method is provided, which is executed in an operating system of a computing device, and the operating system includes a permission control module. The method includes the following steps: the permission control module displays a verification interface in response to a request of an opening management program; the permission control module obtains user permission information input in the verification interface, verifies the user permission information, and opens the management program after verification; the management program reads an application configuration file, generates a menu page according to the application configuration file and displays it, and the menu page includes one or more menu items; and the management program responds to a trigger operation on a target menu item in the menu page, opens or closes the target menu item according to the trigger operation, so as to control the opening or closing of a target module corresponding to the target menu item.
[0006] Optionally, in the permission control method according to the present application, the application configuration file contains one or more application names corresponding to one or more applications, and the step of generating a menu page according to the application configuration file includes: generating a first-level menu item according to the file name of the application configuration file; generating one or more second-level menu items corresponding to one or more application names according to the one or more application names in the application configuration file; and for each second-level menu item corresponding to an application name, generating one or more third-level menu items corresponding to the second-level menu item according to one or more key values corresponding to the application name, wherein each third-level menu item corresponds to a module.
[0007] Optionally, in the permission control method according to the present application, the management program reads the application configuration file comprises: the management program reads the application configuration file from a predetermined directory.
[0008] Optionally, in the permission control method according to the present application, the method further comprises the steps of: the management program monitors the predetermined directory; in response to monitoring that a third-party application configuration file is added to the predetermined directory, reading the third-party application configuration file, generating one or more third-party menu items corresponding to the third-party application according to the third-party application configuration file, and displaying the third-party menu items on the menu page, so as to open or close the third-party menu items to control the opening or closing of the modules corresponding to the third-party menu items.
[0009] Optionally, in the permission control method according to the present application, the method further comprises the steps of: the management program receives the permission control application of the third-party application to open or close one or more modules, generates third-party menu items corresponding to one or more modules of the third-party application, and displays the third-party menu items on the menu page; the management program responds to the triggering operation of the third-party menu items on the menu page, and opens or closes the third-party menu items according to the triggering operation.
[0010] Optionally, in the permission control method according to the present application, the step of opening or closing the third-party menu items according to the triggering operation further comprises: sending a corresponding change signal to the third-party application according to the triggering operation, so that the third-party application opens or closes the modules corresponding to the third-party menu items according to the change signal, to control the opening or closing of the modules corresponding to the third-party menu items.
[0011] Optionally, in the permission control method according to the present application, the management program is adapted to provide a dynamic library, and the step of receiving the permission control application of the third-party application to open or close one or more modules comprises: receiving the permission control application of the third-party application to open or close one or more modules sent by calling one or more interfaces in the dynamic library.
[0012] According to an aspect of the present application, there is provided an authority control apparatus residing in an operating system of a computing device, comprising: an authority control module adapted to display a verification interface in response to a request of starting a management program, acquire user authority information input at the verification interface, verify the user authority information, and start the management program after verification; a management program adapted to read an application configuration file, generate and display a menu page according to the application configuration file, the menu page comprising one or more menu items; and in response to a triggering operation on a target menu item at the menu page, start or close the target menu item according to the triggering operation, so as to control starting or closing of a target module corresponding to the target menu item.
[0013] According to an aspect of the present application, there is provided a computing device, comprising: at least one processor; a memory storing program instructions, wherein the program instructions are configured to be executed by the at least one processor, and the program instructions comprise instructions for executing the authority control method as described above.
[0014] According to an aspect of the present application, there is provided a readable storage medium storing program instructions, which, when read and executed by a computing device, cause the computing device to execute the authority control method as described above.
[0015] According to the technical solution of the present application, an authority control method is provided. According to the authority control method of the present application, if it is required to start or close a module in an application for which authority configuration has been performed, the user first needs to start a management program, and the authority control module can start the management program only after verifying the user authority, and then the management program can generate and display a menu page based on an application configuration file, and the user can perform starting or closing operation on a menu item corresponding to the module at the menu page, so as to start or close the corresponding module. In this way, the present application allows the user to perform starting or closing operation on the application module only after verifying the user authority, thereby realizing authority control on the starting or closing operation of the application module, and reducing user misoperation, and further improving the stability and security of the system.
[0016] Further, according to the technical solution of the present application, for a third-party application, a third-party application configuration file can be directly added, or authority control on a module in the third-party application can be directly applied for. When the user needs to start or close a module in the third-party application for which authority control has been applied for, the user also needs to verify the user authority first to start the management program, and then enter the menu page to start or close a third-party menu item, so as to start or close the corresponding module in the third-party application. In this way, authority control on the starting or closing operation of the module in the third-party application can be conveniently realized.
[0017] The above description is only a summary of the technical solutions of the present application. In order to enable one skilled in the art to more clearly understand the technical means of the present application and to implement the same according to the contents of the specification, and in order to enable the above and other purposes, features and advantages of the present application to be more apparent and easy to understand, the specific embodiments of the present application are described below. BRIEF DESCRIPTION OF DRAWINGS
[0018] To achieve the above and related objects and in view of its purposes, certain illustrative aspects will now be described below in connection with the following description and drawings, wherein the various aspects are indicative of but a few of the various ways in which the principles disclosed herein can be practiced. These aspects and their equivalents are intended to fall within the scope of the claimed subject matter. The foregoing and other objects, features, and advantages of the disclosure will become more apparent from the following detailed description, which proceeds with reference to the accompanying drawings. Throughout the present disclosure, like reference numerals are generally utilized to refer to like elements or features unless otherwise described in the text.
[0019] Figure 1 A schematic diagram of a computing device 100 according to one embodiment of the present application is shown;
[0020] Figure 2 A flowchart of a rights control method 200 according to one embodiment of the present application is shown;
[0021] Figure 3 A schematic diagram of a rights control apparatus 150 according to one embodiment of the present application is shown;
[0022] Figure 4 A schematic diagram of a menu page according to one embodiment of the present application is shown. DETAILED DESCRIPTION
[0023] Exemplary embodiments of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings. While example embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the present disclosure to those skilled in the art.
[0024] Figure 1A schematic diagram of a computing device 100 in accordance with one embodiment of the present application is shown. In a basic configuration, computing device 100 includes at least one processing unit 102 and system memory 104. According to an aspect, depending on the configuration and type of computing device, processing unit 102 can be implemented as a processor. System memory 104 includes, but is not limited to, volatile (e.g., random access memory (RAM)), non-volatile (e.g., read-only memory (ROM)), flash memory, or any combination. According to an aspect, system memory 104 includes operating system 105. Operating system 105 includes permissions control apparatus 150, which is configured to perform the permissions control method 200 of the present application.
[0025] According to an aspect, operating system 105 is suitable for controlling the operation of computing device 100, for example. Furthermore, examples can be practiced in conjunction with a graphics library, other operating systems, or in conjunction with any other application program, and is not limited to any particular application or system. This Figure 1 The basic configuration in FIG. 1 maybe be implemented via a bus. According to an aspect, in this configuration, the bus is a single bus throughout the platform, or it can be composed of any number of buses such as address, data, or control buses among others. According to an aspect, additional devices or components (not shown) can be used in the basic configuration, e.g., controller, peripheral device, voltage regulators, and power management devices. Figure 1 In one implementation, additional devices or components are shown as removable storage devices 106 and non-removable storage devices 107. According to an aspect, removable storage devices 106 include, for example, a floppy disk drive, a magnetic tape drive, an optical disk drive, etc. These devices are inserted into removable storage drive 108, or other like interface, as appropriate and when needed.
[0026] As stated above, according to an aspect, program module 103 is stored in system memory 104. According to an aspect, program module 103 can include one or more applications. The present application is not limited by the type of applications or the type of data that can be stored in the applications, e.g., the applications can include one or more of the following: email and contacts applications, word processing applications, spreadsheet applications, database applications, slide presentation applications, drawing or computer-aided application, web browser applications, etc.
[0027] According to an aspect, examples can be practiced with one or more circuits, logic elements, and / or processors comparable to those described herein that include discrete and integrated logic elements, implemented with microprocessors and / or microcontrollers, digital signal processors, microcomputers and / or any other processing circuitry, including a single core, or multiple cores, or coordinated processors, or cores and / or processors supporting multi- threaded processing. It should be further understood that, because a given implementation of the present application can employ one or more circuits, logic elements, and / or processors comparable to those described herein, embodiments of the present application can be directed, in some aspects, to such circuits, logic elements, and / or processors comparable to those described herein, individually or collectively, and / or as a system. Figure 1Each or many of the components illustrated in FIG. 1 can be practiced on a system-on-a-chip (SOC) integrated on a single integrated circuit in accordance with examples. According to one aspect, such an SOC device can include one or more processing units, graphics units, communications units, system virtualization units, and various application functionality all of which are integrated (or "burned") onto the chip substrate according to an embodiment. When operating via an SOC, the functionality described herein can be operated via application-specific logic integrated with other components of the computing device 100 on the single integrated circuit (chip). Embodiments of the application can also be practiced using other technologies that now exist or are developed in the future, including, but not limited to, mechanical, optical, fluidic, and quantum technologies. In addition, embodiments of the application can be practiced within a general computer device or in any other circuit or system.
[0028] According to one aspect, the computing device 100 can also have one or more input device(s) 112 such as a keyboard, a mouse, a pen, a voice input device, a touch input device, etc. Output device(s) 114 such as a display, speakers, a printer, etc. can also be included. The aforementioned devices are examples and others can be used. The computing device 100 can include one or more communication connections 116 allowing communications with other computing devices 118. Examples of suitable communication connections 116 include, but are not limited to: RF transmitter, receiver, and / or transceiver circuitry; universal serial bus (USB), parallel, and / or serial ports.
[0029] The term computer readable media as used herein includes computer storage media. Computer storage media can include volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, or program modules. The system memory 104, the removable storage device 109, and the non-removable storage device 110 are all computer storage media examples (i.e., memory storage.) Computer storage media can include Random Access Memory (RAM), Read Only Memory (ROM), Electronically Erasable Programmable Read Only Memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store information and which can be accessed by computing device 100. According to one aspect, any such computer storage media can be part of the computing device 100. Computer storage media does not include a modulated data signal or other propagated data signal.
[0030] According to an aspect, a communication medium is embodied by a computer readable instruction, a data structure, a program module, or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. According to an aspect, the term "modulated data signal" describes a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media includes wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared, and other wireless media.
[0031] In an embodiment according to the present application, the computing device 100 is configured to perform the permission control method 200 according to the present application. The computing device 100 comprises one or more processors, and one or more readable storage media storing program instructions which, when configured to be executed by the one or more processors, cause the computing device to implement permission control and management of opening or closing of modules in an application by performing the permission control method 200 in an embodiment of the present application.
[0032] According to an embodiment of the present application, the operating system of the computing device 100 comprises a permission control apparatus 150, which contains a plurality of program instructions for performing the permission control method 200 of the present application, which can instruct the processor to perform the permission control method 200 according to the present application.
[0033] Figure 2 A flow chart of the permission control method 200 according to an embodiment of the present application is shown. The method 200 is suitable for being performed in a computing device (the aforementioned computing device 100), and can be specifically performed in the operating system of the computing device 100.
[0034] In an embodiment according to the present application, the operating system of the computing device 100 comprises a permission control apparatus 150, which contains a plurality of program instructions for performing the permission control method 200 of the present application, which can instruct the processor to perform the permission control method 200 according to the present application. Figure 3 A schematic diagram of the permission control apparatus 300 according to an embodiment of the present application is shown. As shown, the permission control apparatus 150 comprises a permission control module 151 and a management program 152. Figure 3
[0035] It should be noted that in the embodiments, the permission control method 200 is only described in detail by taking the Linux operating system as an example. However, it should be understood that the permission control method 200 of the present application is not limited to the specific type of operating system on which the method is executed, and those skilled in the art can understand that the method can also be implemented on other types of operating systems, such as the Windows operating system, without creative labor. Any type of operating system that can achieve permission control of the opening or closing of modules in an application by the method of the present application is within the protection scope of the present application.
[0036] As shown in Figure 2 , the method 200 includes steps S210-S240.
[0037] Among them, the permission control module 151 can be configured to execute steps S210-S220, and the management program 152 can be configured to execute S230-S240. According to an embodiment of the present application, the permission control module 151 can be implemented as a polkit program, which is a module responsible for managing user permissions and elevating privileges on gnome.
[0038] First, in step S210, the permission control module 151 (Polkit) displays a verification interface in response to a request to open the management program 152. The verification interface can be implemented as a verification window, for example.
[0039] Subsequently, in step S220, the permission control module 151 obtains user permission information input by the user in the verification interface, verifies the user permission information, and opens the management program 152 after verification.
[0040] It should be noted that the management program 152 is used to manage the opening or closing (display or hiding) of the configured modules in the application. In the embodiments of the present application, the management program 152 can only be opened after the user's permission is verified.
[0041] In one implementation, the management program 152 can be implemented as a dde-advanced-control, which is used to manage the opening or closing (display or hiding) of the configured modules. The verification interface can be implemented as a dde-pokit-agent, for example. The dde-pokit-agent is a graphical verification interface on the Linux operating system, which is responsible for providing user permission verification and elevating some operations to root.
[0042] In an implementation, the permission control module 151 can add a permission configuration file in advance to control the opening or closing of the modules in the application. The permission configuration file can be implemented as a policy file, for example. The permission control module 151 can ensure that the operation of starting the management program 152 needs to acquire user permission information and can be executed only after the user permission information is verified. For example, when the user permission information contains administrator permission, the user permission information is verified.
[0043] Subsequently, in step S230, the management program 152 reads the application configuration file and generates and displays a menu page according to the application configuration file. Here, the menu page includes one or more menu items. Specifically, the menu page can include multi-level menu items.
[0044] In an implementation, the application configuration file can be implemented as a conf file.
[0045] The application configuration file contains one or more application names (e.g., system applications) and configuration information of one or more modules in each application. In other words, the modules in the applications are configured with permissions based on the application configuration file, so that the opening or closing of the modules can be controlled. Specifically, each application name corresponds to a group name, and the application name (group name) contains one or more key-value pairs, where the key value Key can represent a three-level menu item, and the mapping value Value corresponding to the key value can represent module information corresponding to the three-level menu item. That is, the application name (group name) contains one or more three-level menu items, and each three-level menu item can be associated with a module of an application.
[0046] When generating the menu page according to the application configuration file, specifically, a first-level menu item can be generated according to the file name of the application configuration file; one or more second-level menu items corresponding to one or more application names can be generated according to the application names in the application configuration file; and for each second-level menu item corresponding to an application name, one or more third-level menu items corresponding to the second-level menu item can be generated according to one or more key values under the application name, where each third-level menu item corresponds to a module.
[0047] Figure 4 A schematic diagram of a menu page according to an embodiment of the application is shown. As shown in FIG. 1, the menu page includes a first-level menu item 101, a second-level menu item 102, and a third-level menu item 103. Figure 4As shown, the first-level menu items are generated according to the file name of the application configuration file, for example, including the "Control Center" menu item. One or more second-level menu items are generated according to one or more application names in the application configuration file, for example, including the "Network", "Time and Date", "Power Management", "System Information", "Update", "Keyboard and Language" and the like. Among them, the third-level menu items corresponding to the second-level menu item "Network" include "appProxy", "Network Details", "DSL", "Hotspot", "System Proxy", "VPN", "Wired Connection", "Wireless Connection" and the like. The module corresponding to the "Wired Connection" menu item is the wired connection module, and the module corresponding to the "Wireless Connection" menu item is the wireless connection module.
[0048] Then, the user can perform a triggering operation on one or more menu items (target menu items) on the single page. In an implementation, as shown in Figure 4 As shown, each third-level menu item includes a corresponding control button. The user can perform a triggering operation on the control button corresponding to the third-level menu item on the menu page, so as to control the opening or closing of the corresponding third-level menu item.
[0049] Finally, in step S240, the management program 152 can perform the opening or closing of the target menu item according to the triggering operation of the user on the target menu item on the menu page, so as to control the opening or closing of the target module corresponding to the target menu item.
[0050] It can be understood that, according to the method 200 of the present application, when the user needs to perform the opening or closing operation on the target module, the user's permission information needs to be verified through steps S210 and S220 first. After the verification, the management program 152 can be opened, and step S230 can be executed through the management program to enter the menu page. Further, the user can perform the opening or closing operation on the target menu item corresponding to the target module, so as to control the opening or closing of the target module.
[0051] In an implementation, the management program 152 can read the application configuration file (conf file) from a predetermined directory. Here, the predetermined directory is, for example, / etc / deepin / ModuleVisible.
[0052] According to one embodiment of the present application, the developer of the third-party application can write the configuration information of one or more modules that need to be enabled or disabled in the conf file according to the corresponding format requirements to generate the third-party application configuration file. By adding the third-party application configuration file in the predetermined directory, the one or more modules that need to be enabled or disabled in the third-party application can be added. Moreover, the management program 152 can add the menu items corresponding to the modules that need to be enabled or disabled in the menu page according to the third-party application configuration file.
[0053] Specifically, in the permission control method 200 of the present application, after the user permission information is verified and the management program 152 is enabled, the management program 152 can monitor the predetermined directory. If the third-party application configuration file is added in the predetermined directory, the management program 152 can read the third-party application configuration file in the predetermined directory in response to the monitoring of the newly added third-party application configuration file in the predetermined directory, generate one or more third-party menu items (which can include secondary menu items and tertiary menu items) corresponding to the third-party application according to the third-party application configuration file, and display the newly generated one or more third-party menu items in the menu page. In this way, the user can enable or disable the one or more third-party menu items in the menu page to control the enabling or disabling of the modules corresponding to the third-party menu items.
[0054] In this way, according to the permission control method 200 of the present application, the third-party application does not need to be additionally configured, but only needs to add the third-party application configuration file related to the permission control requirement of itself (which contains the configuration information of one or more modules that need to be controlled), so as to realize the control of the enabling or disabling (display or hiding) of the modules of the third-party application by the management program of the present application.
[0055] Further, in an implementation, the management program 152 (dde-advanced-control) can provide a dynamic library libauthcontrol.so for setting permissions for the third-party application. The dynamic library contains a plurality of interfaces. The third-party application can call one or more interfaces in the dynamic library to request permission control for the opening or closing of one or more modules, so as to achieve permission control for the opening or closing of the one or more modules. Wherein, the third-party application can call the interface AuthControl::instance() in the dynamic library to obtain a singleton of AuthControl as a singleton corresponding to the third-party application, and can set the name of the singleton corresponding to the third-party application as the English name of the third-party application, so that the management program 152 obtains the icon and the application name (Chinese name) of the third-party application based on the English name of the third-party application. Subsequently, the third-party application can call the interface AuthControl::bind() in the dynamic library to bind one or more modules in the third-party application that need to be authenticated with the singleton corresponding to the third-party application. Here, the one or more modules include, for example, the page or operation module of the third-party application.
[0056] In this embodiment, the management program 152 obtains the application name and the icon of the third-party application, so as to generate the third-party menu items (including secondary menu items and tertiary menu items) corresponding to the one or more modules based on the application name and the icon of the third-party application, and display on the menu page.
[0057] In this way, the user can trigger the third-party menu items on the menu page to control the opening or closing of the third-party menu items, so as to control the opening or closing of the modules corresponding to the third-party menu items.
[0058] The management program 152 can open or close the third-party menu items according to the trigger operation in response to the user triggering the third-party menu items on the menu page. In an embodiment, after the management program 152 opens or closes the third-party menu items according to the trigger operation, the management program 152 can send a corresponding change signal to the third-party application, where the change signal is a state change signal that the third-party menu items change from closed to opened, or from opened to closed. The third-party application can open or close (display or hide) the modules corresponding to the third-party menu items according to the change signal after receiving the change signal. It should be noted that the third-party application can listen to the change signal sent by the management program 152, and open or close the modules corresponding to the third-party menu items according to the change signal.
[0059] In addition, in one embodiment, if one or more modules in the third-party application need to be controlled by the permission, and the corresponding menu item is directly displayed after the user permission information is verified, without displaying the menu item in a hierarchical manner, the third-party application configuration file does not need to be generated, and the third-party application configuration file does not need to be added in the predetermined directory.
[0060] Specifically, the management program 152 (dde-advanced-control) can provide the third-party application with a dynamic library libauthcontrol.so for setting permissions. The dynamic library includes a plurality of interfaces. The third-party application can call one or more interfaces in the dynamic library to request permission control on the opening or closing of one or more modules, so as to achieve permission control on the opening or closing of the one or more modules. The third-party application can call the interface AuthControl::instance() in the dynamic library to obtain a singleton of AuthControl as a singleton corresponding to the third-party application, and can set the name of the singleton corresponding to the third-party application as the English name of the third-party application, so that the management program 152 obtains the icon of the third-party application based on the English name of the third-party application. Subsequently, the third-party application can call the interface AuthControl::bind() in the dynamic library to bind one or more modules in the third-party application that need to be controlled by the permission to the singleton corresponding to the third-party application. Here, the one or more modules include, for example, a page or an operation module of the third-party application.
[0061] In this embodiment, the management program 152 can receive a permission control application for the opening or closing operation of one or more modules (for example, modules such as pages or operation modules that need to be controlled by the permission) sent by the third-party application. Specifically, the management program 152 can receive a permission control application for the opening or closing operation of one or more modules sent by the third-party application by calling one or more interfaces in the dynamic library. In one implementation, first, the third-party application can request to bind one or more modules in the third-party application that need to be controlled by the permission to the singleton corresponding to the third-party application by calling the interface AuthControl::bind(). Subsequently, the management program 152 can generate one or more third-party menu items corresponding to the one or more modules, and display the one or more third-party menu items on the menu page to update the menu page. Here, the management program 152 can obtain the icon of the third-party application, so as to directly generate the corresponding third-party menu item based on the icon of the third-party application and display the third-party menu item on the menu page.
[0062] In this way, the user can trigger the third-party menu item on the menu page to control the opening or closing of the third-party menu item, so as to control the opening or closing (display or hiding) of the module corresponding to the third-party menu item.
[0063] The management program 152 can respond to the user's triggering operation on the third-party menu item on the menu page, and open or close the third-party menu item according to the triggering operation, so as to control the opening or closing (display or hiding) of the module corresponding to the third-party menu item in the third-party application.
[0064] In one embodiment, after the management program 152 opens or closes the third-party menu item according to the triggering operation, it can send a corresponding change signal to the third-party application, where the change signal is a state change signal that the third-party menu item changes from closed to open, or from open to closed. The third-party application can open or close (display or hide) the module corresponding to the third-party menu item according to the change signal after receiving the change signal. It should be noted that the third-party application can listen to the change signal sent by the management program 152 and open or close the module corresponding to the third-party menu item according to the change signal.
[0065] It should be noted that in the above embodiment, after the permission control is applied to one or more modules in the third-party application, if the user needs to open one or more modules in the third-party application for which the permission control is applied, the user first needs to request to open the management program 152 in the computing device. Specifically, the computing device verifies the user's user permission information by performing steps S210-S220, and opens the management program 152 after verification. Further, steps S230-S240 are performed by the management program 152, specifically, the application configuration file can be read from the predetermined directory, and the third-party application configuration file can be monitored and read. Based on the configuration information in the application configuration file and the third-party application configuration file, a menu page including menu items corresponding to one or more modules in the application (system application) and one or more third-party menu items corresponding to one or more modules in the third-party application can be generated. Subsequently, the user can open or close one or more third-party menu items on the menu page to control the opening or closing of the modules in the third-party application corresponding to the third-party menu items. In this way, the opening or closing of the modules in the third-party application is controlled by permission, and the modules in the third-party application can only be opened or closed after the user's permission information is verified.
[0066] According to the permission control method 200 of the present application, if it is required to open or close a module in an application which has been configured with a permission, the user first needs to open the management program, and the permission control module can only open the management program after verifying the permission of the user, and then the management program can generate a menu page based on the application configuration file and display the menu page, and the user can open or close the menu item corresponding to the module on the menu page, so as to realize the opening or closing of the corresponding module. In this way, the present application allows the user to open or close the application module only after verifying the user's permission, thereby realizing permission control of the opening or closing operation of the application module, reducing the user's misoperation, and improving the stability and security of the system.
[0067] Further, according to the technical solution of the present application, for a third-party application, a third-party application configuration file can be directly added, or the permission control of a module in the third-party application can be directly applied for, and when the user needs to open or close a module in the third-party application for which the permission control has been applied for, the user also needs to verify the user's permission first to open the management program, and then can enter the menu page to open or close the third-party menu item, so as to open or close the corresponding module in the third-party application. In this way, the permission control of the opening or closing operation of the module in the third-party application can be conveniently realized.
[0068] The various techniques described herein can be implemented in connection with hardware or software or, where appropriate, with a combination of hardware / software. Thus, the methods and apparatus of the present application, or certain aspects or portions thereof, can take the form of program code (i.e., instructions) embodied in tangible media, such as removable hard disks, U disks, floppy diskettes, CD-ROMs, or any other machine-readable storage medium wherein, when the program code is loaded into an internal memory of the machine such as a computer, the machine becomes an apparatus for practicing the present application.
[0069] Where a program code is executed on a programmable computer, the mobile terminal generally includes a processor, a memory that is readable by the processor (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device. The memory is configured to store program code, and the processor is configured to execute instructions in the program code stored in the memory according to the present application.
[0070] By way of example, and not limitation, a readable medium includes a computer-readable storage medium and a communication medium. A computer-readable storage medium stores information such as computer-readable instructions, data structures, program modules or other data. A communication medium conveys information such as computer-readable instructions, data structures, program modules or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. Combinations of the any of the above are also included within the scope of readable media.
[0071] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order to not obscure the understanding of this description.
[0072] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order to not obscure the understanding of this description.
[0073] Similarly, it is to be understood that the above description is one example of inventive aspects of the present application and that not all of the features would necessarily be included in all embodiments of the application. In some instances, features have been described generally in terms of their functionality without necessarily describing the specifics of the structure where the function is implemented. Those skilled in the art will recognize that structures can be added to or otherwise change, for example adapt, the structure of these described embodiments in order to implement the described functionality.
[0074] It will be appreciated by those skilled in the art that the modules or units of the devices in the examples disclosed herein can be arranged in a device as described in the examples, or alternatively can be located in one or more devices different from the devices in the examples. The modules in the foregoing examples can be combined into one module or further divided into multiple sub-modules.
[0075] Those skilled in the art will appreciate that the modules in the apparatuses in the embodiments can be adapted and placed in one or more apparatuses other than the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and further can be split into multiple sub-modules or sub-units or sub-components. Any combination of all the features disclosed in the specification (including the accompanying claims, abstract and drawings), and any method or process or steps of any such methods or processes disclosed in the specification (including the accompanying claims, abstract and drawings) can be made, except that at least some of such features and / or processes or units are mutually exclusive, unless explicitly stated otherwise. Each feature disclosed in the specification (including the accompanying claims, abstract and drawings) can be replaced by alternative features serving the same, equivalent or similar purpose, unless explicitly stated otherwise.
[0076] Furthermore, those skilled in the art will appreciate that the features of the various embodiments described herein are not mutually exclusive and can be combined in different embodiments. For example, in the following claims, any of the embodiments claimed can be used in any combination.
[0077] Furthermore, some of the embodiments described herein are described as a method or combination of elements of a method implementable by a processor of a computer system or by other means of carrying out the function. Accordingly, a processor with the necessary instructions for carrying out such a method or element of a method forms a means for carrying out the method or element of a method. Furthermore, an element of a method described herein that is implemented as a means for carrying out a particular function performs that function whether or not recited as a means for carrying out that function.
[0078] As used herein, unless otherwise indicated, the use of the ordinal adjectives "first", "second", "third" and so on, in no way limits the number of objects that can be described by the terms. For example, a "first" object can be described simultaneously with a "second" object, even though only two objects can be described.
[0079] While the application has been described in accordance with the various embodiments shown and described, it is to be understood that the application is not limited to those precise embodiments, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the present application. It is intended that the scope of the application should only be limited as recited in the appended claims.
Claims
1. A method for controlling permissions, executed in an operating system of a computing device, the operating system comprising a permission control module, the method comprising the steps of: the permission control module displaying a verification interface in response to a request to start a management program; the permission control module obtaining user permission information input in the verification interface, verifying the user permission information, and starting the management program after verification, the management program being a dde-advanced-control for managing the starting or stopping of configured modules, the management program being adapted to provide a dynamic library; the management program reading an application configuration file, generating and displaying a menu page according to the application configuration file, the menu page comprising a plurality of menu items, the plurality of menu items comprising first-level menu items, second-level menu items, and third-level menu items, the first-level menu items comprising a control center menu item, the second-level menu items comprising network, time and date, power management, system information, update, keyboard, and language menu items, each second-level menu item corresponding to one or more third-level menu items, wherein each third-level menu item corresponds to a module; the management program starting or stopping a target module corresponding to a target menu item in response to a triggering operation on the target menu item in the menu page, so as to control the starting or stopping of the target module corresponding to the target menu item; the management program receiving a permission control application for starting or stopping one or more modules sent by a third-party application through calling one or more interfaces in the dynamic library, generating third-party menu items corresponding to one or more modules of the third-party application, and displaying the third-party menu items in the menu page; the management program sending a corresponding change signal to the third-party application in response to a triggering operation on the third-party menu item in the menu page, so as to control the starting or stopping of a module corresponding to the third-party menu item by the third-party application according to the change signal.
2. The method of claim 1, wherein, the application configuration file comprises one or more application names corresponding to one or more applications, and the step of generating the menu page according to the application configuration file comprises: generating the first-level menu items according to the file name of the application configuration file; generating one or more second-level menu items corresponding to one or more application names according to the one or more application names in the application configuration file; for each second-level menu item corresponding to an application name, generating one or more third-level menu items corresponding to the second-level menu item according to one or more key values corresponding to the application name, wherein each third-level menu item corresponds to a module.
3. The method of claim 1 or 2, wherein, the step of the management program reading the application configuration file comprises: the management program reading the application configuration file from a predetermined directory.
4. The method of claim 3, wherein, the method further comprises the steps of: the management program monitoring the predetermined directory. In response to monitoring that a third-party application configuration file is added under the predetermined directory, reading the third-party application configuration file, generating one or more third-party menu items corresponding to the third-party application according to the third-party application configuration file, and displaying the third-party menu items on the menu page, so as to open or close the third-party menu items, and control modules corresponding to the third-party menu items to be opened or closed.
5. A permission control apparatus residing in an operating system of a computing device, comprising: a permission control module adapted to display a verification interface in response to a request of opening a management program, acquire user permission information input in the verification interface, verify the user permission information, and open the management program after verification, the management program being a dde-advanced-control, the dde-advanced-control being used for managing opening or closing of configured modules, the management program being adapted to provide a dynamic library; a management program adapted to read an application configuration file, generate and display a menu page according to the application configuration file, the menu page comprising multi-level menu items, the multi-level menu items comprising first-level menu items, second-level menu items, and third-level menu items, the first-level menu items comprising a control center menu item, the second-level menu items comprising network, time and date, power management, system information, update, keyboard, and language menu items, each second-level menu item corresponding to one or more third-level menu items, wherein each third-level menu item corresponds to a module, and in response to a triggering operation on a target menu item in the menu page, opening or closing the target menu item according to the triggering operation, so as to control a target module corresponding to the target menu item to be opened or closed; the management program is further adapted to: receive a permission control application for opening or closing one or more modules sent by a third-party application through calling one or more interfaces in the dynamic library, generate third-party menu items corresponding to one or more modules of the third-party application, and display the third-party menu items on the menu page, and in response to a triggering operation on the third-party menu items in the menu page, send a corresponding change signal to the third-party application according to the triggering operation, so that the third-party application opens or closes the third-party menu items according to the change signal, and controls modules corresponding to the third-party menu items to be opened or closed.
6. A computing device, comprising: at least one processor; and a memory storing program instructions, wherein the program instructions are configured to be executed by the at least one processor, and the program instructions comprise instructions for executing the method of any one of claims 1-4.
7. A readable storage medium storing program instructions, when the program instructions are read and executed by a computing device, causing the computing device to execute the method of any one of claims 1-4.
Citation Information
Patent Citations
Customization of menus
US20130311911A1