A user privilege management method and device

By generating user identification codes and obtaining enterprise and project permissions, dynamically merging permissions, the problem of user permissions cannot be managed independently in traditional technology is solved, and efficient and flexible permission management and isolation are achieved.

CN115378708BActive Publication Date: 2025-05-30上海维搭信息科技有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211010916.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-23
Publication Date
2025-05-30
Estimated Expiration
2042-08-23

AI Technical Summary

Technical Problem

In traditional technology, user permissions cannot be independently customized in different enterprises and projects, which makes it difficult to achieve permission isolation and reduces the efficiency of permission management.

Method used

By generating user identification codes, obtaining the latest enterprise browsing history, determining the enterprise and project permissions to which the user belongs, dynamically determining the relevant status between enterprise permissions and project permissions, and combining permissions to generate the user's target permission collection.

Benefits of technology

It realizes independent management of enterprise permissions and project permissions, improves the efficiency and flexibility of permission management, and ensures permission isolation and customized management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115378708B_ABST
    Figure CN115378708B_ABST
Patent Text Reader

Abstract

The present application provides a user permission management method and apparatus. The method includes: obtaining the most recent enterprise browsing record corresponding to the user identification code; determining, according to the most recent enterprise browsing record, a first associated enterprise to which the user belongs, the first associated enterprise including a plurality of first projects; determining, according to the user identification code, a first enterprise permission set corresponding to the first associated enterprise, and determining a plurality of first target projects associated with the user from the plurality of first projects; for each first target project, determining, according to the user identification code, a first project permission set corresponding to the first target project; determining the correlation status between each first enterprise permission in the first enterprise permission set and each first target project; and determining, according to the correlation status and the first project permission set, a first target permission set for the user for each first target project. By independently managing enterprise permissions and project permissions, the present application improves management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of permission management, and particularly to a user permission management method and device. Background Art

[0002] The user account role permission management of the SAAS platform is generally applicable to various application information systems developed and managed by a company, including OA collaborative office systems, ERP management software, financial software, enterprise email, and website systems, etc. Generally, the user classification of information systems mainly includes two categories: system administrators and ordinary users; system administrators are mainly responsible for system parameter configuration in the application information system, user account opening and maintenance management, setting role and permission relationships, maintaining data dictionaries such as administrative divisions and organization codes, system log management, and data management and other system operation and maintenance work; ordinary users refer to non-system administrator users created and authorized by system administrators in the application information system, and have the permission to log in and use the application information system within the authorized scope.

[0003] During the process of business management, complex usage scenarios such as permission isolation and penetration are involved. In traditional technologies, problems such as user permission amplification or the inability to customize and manage user permissions independently in different enterprises and different projects will occur. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide at least a user permission management method and device, which can improve management efficiency by independently managing enterprise permissions and project permissions.

[0005] This application mainly includes the following aspects:

[0006] In a first aspect, an embodiment of this application provides a user permission management method, which generates a user identification code according to user login information, and obtains the most recent enterprise browsing record corresponding to the user identification code from a database according to the user identification code; according to the most recent enterprise browsing record, determines the first associated enterprise to which the user belongs, and the first associated enterprise includes multiple first projects; according to the user identification code, determines the first enterprise permission set corresponding to the user in the first associated enterprise, and determines multiple first target projects associated with the user from multiple first projects, and the first enterprise permission set includes multiple first enterprise permissions; for each first target project, determines the first project permission set corresponding to the user in the first target project according to the user identification code; for each first target project, determines the relevant status between each first enterprise permission and the first target project; for each first target project, determines the first target permission set of the user for the first target project according to the relevant status and the first project permission set corresponding to the first target project.

[0007] In a possible implementation, the relevant status includes an associated status or a non-associated status. Among them, for each first target item, the steps of determining the first target permission set of the user for the first target item according to the relevant status and the first item permission set corresponding to the first target item include: for each first target item: traverse the relevant status between each first enterprise permission and the first target item; if the relevant status between the first enterprise permission and the first target item is the associated status, incorporate the first enterprise permission into the first item permission set corresponding to the first target item to obtain the first target permission set of the first target item; if the relevant status between the first enterprise permission and the first target item is the non-associated status, do not incorporate the first enterprise permission into the first item permission set.

[0008] In a possible implementation, the item content of the current first target item browsed by the user is displayed on the item viewing interface, where the corresponding item content is displayed to the user according to the first target permission set of the user for the current first target item stored in the preset storage area; receive a project switching request executed by the user on the item viewing interface, the project switching request includes an item identifier, and the item identifier indicates the first target item to be switched to; according to the item identifier, obtain the first target permission set of the first target item to be switched to, and replace the first target permission set for the current first target item with the obtained first target permission set of the first target item to be switched to; based on the first target permission set of the user for the first target item to be switched to stored in the preset storage area, display the corresponding item content to the user.

[0009] In a possible implementation, the first item permission set corresponding to each first target item is determined by the following method: determine at least one first item role corresponding to the user in the first target item; for each first item role, determine the item role permission set corresponding to the first item role; according to all the item role permission sets, form the first item permission set corresponding to the first target item.

[0010] In a possible implementation, the first enterprise permission set corresponding to the first associated enterprise is determined by the following method: determine at least one first enterprise role corresponding to the user in the first associated enterprise; for each first enterprise role, determine the enterprise role permission set corresponding to the first enterprise role, and the enterprise role permission set includes multiple first enterprise permissions; according to all the enterprise role permission sets, form the first enterprise permission set corresponding to the first associated enterprise.

[0011] In a possible implementation, enterprise content of the currently viewed first associated enterprise by the user is displayed on the enterprise viewing interface, where the corresponding enterprise content displayed to the user is determined according to the first enterprise permission set of the user for the currently viewed first associated enterprise stored in the preset storage area; a enterprise switching request executed by the user on the enterprise viewing interface is received, the enterprise switching request includes an enterprise identifier, and the enterprise identifier indicates the second associated enterprise to be switched to; according to the enterprise identifier, a second enterprise permission set of the switched-to second associated enterprise is obtained, and the first enterprise permission set for the currently viewed first associated enterprise is replaced with the obtained second enterprise permission set of the switched-to second associated enterprise; and corresponding enterprise content is displayed to the user based on the second enterprise permission set of the user for the switched-to second associated enterprise stored in the preset storage area.

[0012] In a possible implementation, a call request for a target permission in a first target permission set executed by the user on the project viewing interface is received, the call request includes a user identification code, a target permission interface identifier, a target permission identifier, and a first associated enterprise identifier; a first enterprise permission set corresponding to the first associated enterprise identifier is obtained from a database according to the user identification code and the first associated enterprise identifier; it is determined whether the target permission identifier exists in the first enterprise permission set, if the target permission identifier exists in the first enterprise permission set, it is determined that the user has access permission to the target permission interface, and the user is allowed to access the target permission interface through the target permission interface identifier and obtain the target permission; if the target permission identifier does not exist in the first enterprise permission set, it is determined that the user does not have access permission to the target permission interface, and the user is prohibited from accessing the target permission interface.

[0013] In a possible implementation, the target permission interface is accessed through the target permission interface identifier and the encrypted permission is obtained; the received encrypted permission is decrypted according to the RSA key, and the decrypted encrypted permission is determined as the target permission.

[0014] In a second aspect, an embodiment of the present application further provides a user permission management device, which includes: a first acquisition module, configured to generate a user identification code according to user login information, and acquire the most recent enterprise browsing record corresponding to the user identification code from a database; a first determination module, configured to determine a first associated enterprise to which the user belongs according to the most recent enterprise browsing record, where the first associated enterprise includes multiple first projects; a second determination module, configured to determine a first enterprise permission set corresponding to the user in the first associated enterprise according to the user identification code, and determine multiple first target projects associated with the user from the multiple first projects, where the first enterprise permission set includes multiple first enterprise permissions; a third determination module, configured to, for each first target project, determine a first project permission set corresponding to the user in the first target project according to the user identification code; a relevant status determination module, configured to, for each first target project, determine the relevant status between each first enterprise permission and the first target project; a permission determination module, configured to, for each first target project, determine a first target permission set of the user for the first target project according to the relevant status and the first project permission set corresponding to the first target project.

[0015] In a possible implementation manner, the relevant status includes an associated status and a non-associated status, and the permission determination module is further configured to: for each first target project: traverse the relevant status between each first enterprise permission and the first target project; if the relevant status between the first enterprise permission and the first target project is an associated status, incorporate the first enterprise permission into the first project permission set corresponding to the first target project to obtain the first target permission set of the first target project; if the relevant status between the first enterprise permission and the first target project is a non-associated status, do not incorporate the first enterprise permission into the first project permission set.

[0016] The user permission management method and device provided by the embodiment of the present application, the method includes: generating a user identification code according to user login information, and acquiring the most recent enterprise browsing record corresponding to the user identification code from a database; determining a first associated enterprise to which the user belongs according to the most recent enterprise browsing record, where the first associated enterprise includes multiple first projects; determining a first enterprise permission set corresponding to the first associated enterprise according to the user identification code, and determining multiple first target projects associated with the user from the multiple first projects; for each first target project, determining a first project permission set corresponding to the first target project according to the user identification code; determining the relevant status between each first enterprise permission in the first enterprise permission set and each first target project; determining a first target permission set of the user for each first target project according to the relevant status and the first project permission set. By independently managing enterprise permissions and project permissions, the management efficiency is improved.

[0017] To make the above objects, features, and advantages of the present application more obvious and understandable, the following provides preferred embodiments in conjunction with the accompanying drawings and describes them in detail as follows. Description of the Drawings

[0018] To more clearly illustrate the technical solutions of the embodiments of the present application, the accompanying drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.

[0019] Figure 1 Shows the flowchart of a user privilege management method provided by an embodiment of the present application;

[0020] Figure 2 Shows the flowchart of a method for a user to switch project privileges provided by an embodiment of the present application;

[0021] Figure 3 Shows the flowchart of a method for a user to switch enterprises provided by an embodiment of the present application;

[0022] Figure 4 Shows the structural schematic diagram of a user privilege management device provided by an embodiment of the present application;

[0023] Figure 5 Shows the structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments

[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. It should be understood that the accompanying drawings in the present application only serve the purpose of illustration and description and are not used to limit the protection scope of the present application. Additionally, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in the present application show the operations implemented according to some embodiments of the present application. It should be understood that the operations in the flowchart may not be implemented in sequence, and steps without logical context relationships may be reversed or implemented simultaneously. Furthermore, those skilled in the art can add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of the present application.

[0025] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application usually described and illustrated in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application claimed, but only represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.

[0026] In the traditional user permission management solution, for each project in each enterprise, independent project management or independent operation management cannot be carried out, resulting in the inability to fully achieve permission isolation and reducing the permission management efficiency.

[0027] Based on this, the embodiments of the present application provide a user permission management method, which independently manages enterprise permissions and project permissions to improve management efficiency, specifically as follows:

[0028] Please refer to Figure 1 , Figure 1 which shows a flowchart of a user permission management method provided by the embodiments of the present application. As Figure 1 shown, the user permission management method provided by the embodiments of the present application includes the following steps:

[0029] S101. Generate a user identification code according to the user login information, and obtain the most recent enterprise browsing record corresponding to the user identification code from the database according to the user identification code.

[0030] In specific implementation, the present application is applicable to the SAAS platform. The user login information includes, but is not limited to, the login account, login password, login name, and login time used by the user to log in to the SAAS platform. A user identification code corresponding to the user login information is generated by obtaining the user login information. Here, it is necessary to first determine whether there is a corresponding associated enterprise for the user currently logging in to the SAAS platform according to the user identification code. Specifically, the most recent enterprise browsing record corresponding to the user identification code can be obtained from the database according to the user identification code. For the user identification code that has been associated with an enterprise, each time an enterprise is accessed, a corresponding enterprise browsing record will be generated. If the corresponding enterprise browsing record cannot be queried for the user identification code, it means that the login account used by the user to log in to the SAAS platform is not associated with the corresponding enterprise. At this time, it is necessary to further obtain the user permission set of the user on the SAAS platform according to the user identification code, and display the corresponding content on the basic information viewing interface of the SAAS platform according to the user permission set corresponding to the user identification code. For example, for users who have registered on the SAAS platform, the user permission set includes the permission to apply to join an enterprise.

[0031] S102. Determine the first associated enterprise to which the user belongs according to the most recent enterprise browsing record of the user.

[0032] In a specific embodiment, the first associated enterprise includes a plurality of first projects. Specifically, the SAAS platform will determine the user who creates the first associated enterprise as the enterprise administrator of the first associated enterprise, and assign a unique administrator identification code to the login account corresponding to the enterprise administrator. According to the administrator identification code, the corresponding administrator permission set can be obtained. The administrator permission set includes permissions such as creating projects, creating project roles, creating enterprise roles, enterprise application approval, project role assignment, enterprise role assignment, etc. The enterprise administrator of the first associated enterprise will create a plurality of first projects in the first associated enterprise in advance according to the current different needs of the enterprise, and generate the binding relationships between the plurality of first projects and the first associated enterprise.

[0033] The enterprise administrator can also create the first enterprise role and the first project role in the first associated enterprise through the permissions of creating project roles and creating enterprise roles, and at the same time generate the binding relationship between the first enterprise role and the first associated enterprise, and the binding relationship between the first project role and the corresponding first project. At the same time, according to the requirements of the first enterprise role, a plurality of first enterprise permissions corresponding to the first enterprise role are obtained from the database, and the binding relationship between the first enterprise role and the plurality of first enterprise permissions is established. Similarly, according to the requirements of the first project role, a plurality of project permissions corresponding to the first project role can be obtained from the database, and the binding relationship between the first project role and the plurality of project permissions is established.

[0034] At the same time, the enterprise administrator can receive the application of the user for the first associated enterprise and approve it, associate the corresponding user with the first associated enterprise, and at the same time assign the corresponding first enterprise role to the user who enters the first associated enterprise through the enterprise role assignment permission, and generate the binding relationship between the first enterprise role and the user within the first associated enterprise. Through the project role assignment permission, the corresponding first project role is assigned to the user who enters the first associated enterprise, and the binding relationship between the first project role and the user within the first project is generated.

[0035] In a specific embodiment, if the most recent enterprise browsing record corresponding to the user identification code can be obtained from the database, the enterprise indicated by the most recent enterprise browsing record is determined as the first associated enterprise corresponding to the user. At the same time, the enterprise content of the current first associated enterprise browsed by the user is displayed on the enterprise viewing interface. Among them, it is necessary to first determine the first enterprise permission set of the current first associated enterprise, and determine the enterprise content of the current first associated enterprise according to the first enterprise permission set.

[0036] S103. Determine the first enterprise permission set corresponding to the user in the first associated enterprise according to the user identification code, and determine multiple first target projects associated with the user from multiple first projects.

[0037] The first enterprise permission set includes multiple first enterprise permissions.

[0038] In a preferred embodiment, the first enterprise permission set corresponding to the first associated enterprise can be determined in the following manner:

[0039] Determine at least one first enterprise role corresponding to the user in the first associated enterprise. For each first enterprise role, determine the enterprise role permission set corresponding to the first enterprise role. According to all enterprise role permission sets, form the first enterprise permission set corresponding to the first associated enterprise.

[0040] In a preferred embodiment, first, according to the binding relationship between the user and the first enterprise role, determine at least one first enterprise role bound to the user indicated by the user identification code. Then, according to the binding relationship between the first enterprise role and multiple first enterprise permissions, determine multiple first enterprise permissions corresponding to each first enterprise role, form the enterprise role permission set corresponding to each first enterprise role, and form the first enterprise permission set corresponding to the first associated enterprise according to all enterprise role permission sets.

[0041] S104. For each first target project, determine the first project permission set corresponding to the user in the first target project according to the user identification code.

[0042] In a specific embodiment, the first project permission set corresponding to each first target project can be determined in the following manner:

[0043] Determine at least one first project role corresponding to the user in the first target project; for each first project role, determine the project role permission set corresponding to the first project role; according to all project role permission sets, form the first project permission set corresponding to the first target project.

[0044] In a preferred embodiment, first, according to the binding relationship between the user and the first project role, determine at least one first project role bound to the user indicated by the user identification code. Then, according to the binding relationship between the first project role and multiple first project permissions, determine multiple first project permissions corresponding to each first project role, form the project role permission set corresponding to each first project role, and form the first project permission set corresponding to the first target project according to all project role permission sets.

[0045] S105. For each first target project, determine the relevant status between each first enterprise permission and the first target project.

[0046] In a specific embodiment, the enterprise role assigned by the enterprise administrator to the user is determined as the first enterprise role, and the project role assigned to the user is determined as the first project role. Among them, for each first enterprise permission in the first enterprise permission set, the relevant status between the first enterprise permission and each first target project can also be set, where the relevant status is an associated status or non - associated.

[0047] Specifically, for each first enterprise permission, if the relevant status between the first enterprise permission and one of the first target projects is an associated status, it indicates that the first enterprise permission can penetrate into the management of the first target project at this time. If the relevant status between the first enterprise permission and one of the first target projects is a non - associated status, it indicates that the first enterprise permission cannot penetrate into the management of the first target project at this time.

[0048] For example, if the first enterprise permission is the permission to delete the first target project, if the relevant status between the first enterprise permission and one of the first target projects is an associated status, it indicates that the user has the permission to delete the first target project at this time. If the relevant status between the first enterprise permission and one of the first target projects is a non - associated status, it indicates that the user does not have the permission to delete the first target project at this time.

[0049] S106. For each first target project, determine the first target permission set of the user for the first target project according to the relevant status and the first project permission set corresponding to the first target project.

[0050] In a preferred embodiment, for each first target project, the steps of determining the first target permission set of the user for the first target project according to the relevant status and the first project permission set corresponding to the first target project include:

[0051] For each first target project:

[0052] Traverse the relevant status between each first enterprise permission and the first target project; if the relevant status between the first enterprise permission and the first target project is an associated status, incorporate the first enterprise permission into the first project permission set corresponding to the first target project to obtain the first target permission set of the first target project.

[0053] In a specific embodiment, each first enterprise permission in an associated state with the first target project is obtained. At this time, it indicates that the user's permission for the first target project not only includes the first project permission set but also each first enterprise permission in an associated state with the first target project. At this time, each first enterprise permission in an associated state with the first target project should be incorporated into the first project permission set corresponding to the first target project to obtain the first target permission set of the first target project.

[0054] If the relevant state between the first enterprise permission and the first target project is a non-associated state, the first enterprise permission is not incorporated into the first project permission set.

[0055] In a specific embodiment, the user can switch between multiple target projects associated within the corresponding associated enterprise. Specifically, please refer to Figure 2 , Figure 2 which shows the flowchart of a method for a user to switch project permissions provided by an embodiment of the present application. As shown in Figure 2 , the project and the corresponding project permissions can be switched within the first associated enterprise in the following manner:

[0056] S201. Display the project content of the current first target project browsed by the user on the project viewing interface.

[0057] In a preferred embodiment, the corresponding project content is displayed to the user according to the first target permission set of the user for the current first target project stored in the preset storage area. The preset storage area is used to place the first target permission set corresponding to the current target project.

[0058] S202. Receive a project switching request executed by the user on the project viewing interface. The project switching request includes a project identifier, and the project identifier indicates the first target project to be switched to.

[0059] In a preferred embodiment, other first target project identifiers can be displayed on the current project viewing interface, and the user can generate a project switching request by clicking on other first target project identifiers.

[0060] S203. According to the project identifier, obtain the first target permission set of the first target project to be switched to, and replace the first target permission set for the current first target project with the obtained first target permission set of the first target project to be switched to.

[0061] In a specific embodiment, the first target permission set of the first target project to be switched to can be used to replace the first target permission set for the current first target project, thereby completing the update of the project and the project permissions owned by the current user.

[0062] S204. Display the corresponding project content to the user based on the first target permission set of the user for the switched first target project stored in the preset storage area.

[0063] In a specific embodiment, based on the first target permission set of the user for the switched first target project stored in the preset storage area, obtain the resources corresponding to each permission in the first target permission set of the switched first target project, and display the corresponding project content to the user through the obtained resources.

[0064] Please refer to Figure 3 , Figure 3 which shows the flowchart of a method for a user to switch enterprises provided by an embodiment of the present application. As Figure 3 shown, the method for a user to switch from a first associated enterprise to a second associated enterprise includes:

[0065] S301. Display the enterprise content of the currently viewed first associated enterprise by the user on the enterprise viewing interface.

[0066] In a preferred embodiment, displaying the corresponding enterprise content to the user is determined according to the first enterprise permission set of the user for the currently viewed first associated enterprise stored in the preset storage area. Specifically, the preset storage area also stores the first enterprise permission set of the currently viewed first associated enterprise.

[0067] S302. Receive the enterprise switching request executed by the user on the enterprise viewing interface. The enterprise switching request includes an enterprise identifier, and the enterprise identifier indicates the second associated enterprise to be switched to.

[0068] Specifically, at least one second associated enterprise identifier may be displayed on the current enterprise viewing interface, and the user can generate a corresponding enterprise switching request by clicking on the second associated enterprise identifier.

[0069] S303. According to the enterprise identifier, obtain the second enterprise permission set of the switched second associated enterprise, and replace the first enterprise permission set for the currently viewed first associated enterprise with the obtained second enterprise permission set of the switched second associated enterprise.

[0070] S304. Display the corresponding enterprise content to the user based on the second enterprise permission set of the user for the switched second associated enterprise stored in the preset storage area.

[0071] In a possible implementation manner, return to S106. After S106, the user permission management method provided by the present application further includes:

[0072] Receive the call request of the user for the target permission in the first target permission set executed on the project viewing interface.

[0073] In a specific embodiment, the call request includes a user identification code, a target permission interface identifier, a target permission identifier, and a first associated enterprise identifier. Specifically, the currently displayed project viewing interface displays a list of the first target permission sets corresponding to the current first target project. The first target permission set list includes permission identifiers corresponding to multiple permissions in the first target permission set. In response to a selection operation on the target permission identifier in the permission identifiers, a target permission call request is generated.

[0074] Obtain the first enterprise permission set corresponding to the first associated enterprise identifier of the enterprise from the database according to the user identification code and the first associated enterprise identifier, and determine whether the target permission identifier exists in the first enterprise permission set. If the target permission identifier exists in the first enterprise permission set, it is determined that the user has access permission to the target permission interface, and the user is allowed to access the target permission interface through the target permission interface identifier and obtain the target permission.

[0075] If the target permission identification code does not exist in the first enterprise permission set, it is determined that the user does not have access permission to the target permission interface, and the user is prohibited from accessing the target permission interface.

[0076] In a specific embodiment, when the user accesses the target permission interface indicated by the target permission interface identifier through the user identification code, permission verification can be performed when the user accesses the target permission interface in the way of AOP slicing, and it is obtained whether the user has the access permission corresponding to the target permission interface among the permissions possessed by the user identification code. If the user has access permission, the user is allowed to call the target permission interface to access the resources corresponding to the permission. When the user has no access permission, the user is refused to call the target permission interface.

[0077] In a specific embodiment, access the target permission interface through the target permission interface identifier and obtain the encrypted permission, decrypt the received encrypted permission according to the RSA key, and determine the decrypted encrypted permission as the target permission.

[0078] Specifically, the resources corresponding to the permission are dynamically encrypted using asymmetric encryption. For example, the resources corresponding to the permission are encrypted and encoded using the 256-bit RAS algorithm. Then, when the resources corresponding to the permission are obtained, the resources need to be decrypted using a pre-set key to obtain the target resources corresponding to the target permission.

[0079] Based on the same inventive concept, a user permission management device corresponding to the user permission management method provided in the above embodiment is also provided in the embodiment of the present application. Since the principle of solving problems by the device in the embodiment of the present application is similar to the user permission management method in the above embodiment of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0080] Please refer toFigure 4 , Figure 4 shows a schematic structural diagram of a user privilege management device provided by an embodiment of the present application. As Figure 4 shown, the user privilege management device includes:

[0081] A first acquisition module 410, configured to generate a user identification code according to user login information, and acquire the most recent enterprise browsing record corresponding to the user identification code from a database;

[0082] A first determination module 420, configured to determine a first associated enterprise to which the user belongs according to the most recent enterprise browsing record, and the first associated enterprise includes a plurality of first projects;

[0083] A second determination module 430, configured to determine a first enterprise privilege set corresponding to the first associated enterprise according to the user identification code, and determine a plurality of first target projects associated with the user from the plurality of first projects;

[0084] A third determination module 440, configured to, for each first target project, determine a first project privilege set corresponding to the first target project according to the user identification code;

[0085] A relevant status determination module 450, configured to determine the relevant status between each first enterprise privilege in the first enterprise privilege set and each first target project;

[0086] A privilege determination module 460, configured to determine a first target privilege set of the user for each first target project according to the relevant status and the first project privilege set.

[0087] Optionally, the relevant status includes association and non - association. The privilege determination module 460 is further configured to: for each first target project with an associated enterprise privilege, incorporate each first enterprise privilege in an associated state with the first target project into the first project privilege set corresponding to the first target project to obtain the first target privilege set of the first target project; for each first target project with a non - associated enterprise privilege, determine only the first project privilege set corresponding to the first target project as the first target privilege set of the first target project.

[0088] Optionally, the device further includes a project permission switching module (not shown in the figure), which is used to: display the project content of the current first target project browsed by the user on the project viewing interface, wherein the corresponding project content is displayed to the user according to the first target permission set of the user for the current first target project stored in the preset storage area; receive a project switching request executed by the user on the project viewing interface, the project switching request includes a project identifier, and the project identifier indicates the first target project to be switched to; according to the project identifier, obtain the first target permission set of the first target project to be switched to, and replace the first target permission set of the current first target project with the obtained first target permission set of the first target project to be switched to; based on the first target permission set of the user for the first target project to be switched to stored in the preset storage area, display the corresponding project content to the user.

[0089] Optionally, the third determination module 440 is further used to: determine at least one first project role corresponding to the user in the first target project; for each first project role, determine the project role permission set corresponding to the first project role; according to all the project role permission sets, form the first project permission set corresponding to the first target project.

[0090] Optionally, the second determination module 430 is further used to: determine at least one first enterprise role corresponding to the user in the first associated enterprise; for each first enterprise role, determine the enterprise role permission set corresponding to the first enterprise role; according to all the enterprise role permission sets, form the first enterprise permission set corresponding to the first associated enterprise.

[0091] Optionally, the device further includes an enterprise permission switching module (not shown in the figure), and the enterprise permission switching module is used to: display the enterprise content of the current first associated enterprise browsed by the user on the enterprise viewing interface, wherein the corresponding enterprise content is displayed to the user according to the first enterprise permission set of the user for the current first associated enterprise stored in the preset storage area; receive an enterprise switching request executed by the user on the enterprise viewing interface, the enterprise switching request includes an enterprise identifier, and the enterprise identifier indicates the second associated enterprise to be switched to; according to the enterprise identifier, obtain the second enterprise permission set of the second associated enterprise to be switched to, and replace the first enterprise permission set of the current first associated enterprise with the obtained second enterprise permission set of the second associated enterprise to be switched to; based on the second enterprise permission set of the user for the second associated enterprise to be switched to stored in the preset storage area, display the corresponding enterprise content to the user.

[0092] Optionally, the device further includes a permission invocation module (not shown in the figure), configured to: receive a call request for a target permission in the first target permission set executed by the user on the project viewing interface, where the call request includes a user identification code, a target permission interface identifier, a target permission identifier, and a first associated enterprise identifier; obtain a first enterprise permission set corresponding to the first associated enterprise identifier of the enterprise from the database according to the user identification code and the first associated enterprise identifier; determine whether the target permission identifier exists in the first enterprise permission set, and if the target permission identifier exists in the first enterprise permission set, determine that the user has access permission to the target permission interface, and allow the user to access the target permission interface through the target permission interface identifier and obtain the target permission; if the target permission identifier does not exist in the first enterprise permission set, determine that the user does not have access permission to the target permission interface, and prohibit the user from accessing the target permission interface.

[0093] Optionally, the device further includes a permission encryption module (not shown in the figure), configured to: access the target permission interface through the target permission interface identifier and obtain the encrypted permission; decrypt the received encrypted permission according to the RSA key, and determine the decrypted encrypted permission as the target permission.

[0094] Please refer to Figure 5 , Figure 5 which shows a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 5 shown, a schematic structural diagram of an electronic device 500 provided by an embodiment of the present application includes: a processor 510, a memory 520, and a bus 530. The memory 520 stores machine-readable instructions executable by the processor 510. When the electronic device 500 runs, the processor 510 communicates with the memory 520 through the bus 530. When the machine-readable instructions are run by the processor 510, the steps of the user permission management method described in any one of the above embodiments are executed.

[0095] Based on the same application concept, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the user permission management method provided in the above embodiment are executed.

[0096] Specifically, the storage medium can be a general storage medium, such as a mobile disk, a hard disk, etc. When the computer program on the storage medium is run, the above user permission management method can be executed.

[0097] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein. In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some communication interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0098] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0099] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0100] If the above functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0101] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A user privilege management method, characterized in that, the method includes: generating a user identification code according to the user login information, and obtaining the most recent enterprise browsing record corresponding to the user identification code from the database according to the user identification code; determining a first associated enterprise to which the user belongs according to the most recent enterprise browsing record, and the first associated enterprise includes a plurality of first projects; determining a first enterprise privilege set corresponding to the user in the first associated enterprise according to the user identification code, and determining a plurality of first target projects associated with the user from the plurality of first projects, the first enterprise privilege set includes a plurality of first enterprise privileges, and the first enterprise privilege set is determined by the first enterprise role assigned to the user identification code; for each first target project, determining a first project privilege set corresponding to the user in the first target project according to the user identification code; for each first target project, determining the relevant status between each first enterprise privilege and the first target project, and the relevant status is used to indicate whether to incorporate the first enterprise privilege into the first target project; for each first target project, determining a first target privilege set of the user for the first target project according to the relevant status and the first project privilege set corresponding to the first target project; the relevant status includes an associated status or a non-associated status, wherein, for each first target project, the step of determining a first target privilege set of the user for the first target project according to the relevant status and the first project privilege set corresponding to the first target project includes: for each first target project: traversing the relevant status between each first enterprise privilege and the first target project; if the relevant status between the first enterprise privilege and the first target project is an associated status, incorporating the first enterprise privilege into the first project privilege set corresponding to the first target project to obtain the first target privilege set of the first target project; if the relevant status between the first enterprise privilege and the first target project is a non-associated status, not incorporating the first enterprise privilege into the first project privilege set; the method further includes: displaying the project content of the current first target project browsed by the user on the project viewing interface, wherein displaying the corresponding project content to the user is determined according to the first target privilege set of the user for the current first target project stored in the preset storage area; receiving a project switching request executed by the user on the project viewing interface, and the project switching request includes a project identifier, and the project identifier indicates the first target project to be switched to; obtaining the first target privilege set of the first target project to be switched to according to the project identifier, and replacing the first target privilege set for the current first target project with the obtained first target privilege set of the first target project to be switched to; displaying the corresponding project content to the user based on the first target privilege set of the user for the first target project to be switched to stored in the preset storage area.

2. The method according to claim 1, characterized in that, Determine the first project permission set corresponding to each first target project in the following manner: Determine at least one first project role corresponding to the user in the first target project; For each first project role, determine the project role permission set corresponding to the first project role; Based on all the project role permission sets, form the first project permission set corresponding to the first target project.

3. The method according to claim 1, wherein, Determine the first enterprise permission set corresponding to the first associated enterprise in the following manner: Determine at least one first enterprise role corresponding to the user in the first associated enterprise; For each first enterprise role, determine the enterprise role permission set corresponding to the first enterprise role, and the enterprise role permission set includes multiple first enterprise permissions; Based on all the enterprise role permission sets, form the first enterprise permission set corresponding to the first associated enterprise.

4. The method according to claim 1, wherein, The method further includes: Display the enterprise content of the currently viewed first associated enterprise by the user on the enterprise viewing interface, wherein the corresponding enterprise content is displayed to the user according to the first enterprise permission set of the user for the currently viewed first associated enterprise stored in the preset storage area; Receive an enterprise switching request executed by the user on the enterprise viewing interface, the enterprise switching request includes an enterprise identifier, and the enterprise identifier indicates the second associated enterprise to be switched to; According to the enterprise identifier, obtain the second enterprise permission set of the switched-to second associated enterprise, and replace the first enterprise permission set for the currently viewed first associated enterprise with the obtained second enterprise permission set of the switched-to second associated enterprise; Based on the second enterprise permission set of the user for the switched-to second associated enterprise stored in the preset storage area, display the corresponding enterprise content to the user.

5. The method according to claim 1, wherein, The method further includes: Receive a call request for a target permission in the first target permission set executed by the user on the project viewing interface, the call request includes a user identification code, a target permission interface identifier, a target permission identifier, and a first associated enterprise identifier; According to the user identification code and the first associated enterprise identifier, obtain the first enterprise permission set corresponding to the first associated enterprise identifier from the database; Determine whether the target permission identifier exists in the first enterprise permission set. If the target permission identifier exists in the first enterprise permission set, determine that the user has access permission to the target permission interface, and allow the user to access the target permission interface through the target permission interface identifier and obtain the target permission; If the target permission identifier does not exist in the first enterprise permission set, determine that the user does not have access permission to the target permission interface, and prohibit the user from accessing the target permission interface.

6. The method according to claim 5, wherein, The method further includes: Access the target permission interface through the target permission interface identifier and obtain the encrypted permission; Decrypt the received encrypted permission according to the RSA key, and determine the decrypted encrypted permission as the target permission.

7. A user permission management device, It is characterized in that the device includes: a first acquisition module, configured to generate a user identification code according to user login information, and acquire the most recent enterprise browsing record corresponding to the user identification code from a database according to the user identification code; a first determination module, configured to determine a first associated enterprise to which the user belongs according to the most recent enterprise browsing record, where the first associated enterprise includes a plurality of first projects; a second determination module, configured to determine a first enterprise permission set corresponding to the user in the first associated enterprise according to the user identification code, and determine a plurality of first target projects associated with the user from the plurality of first projects, where the first enterprise permission set includes a plurality of first enterprise permissions, and the first enterprise permission set is determined by a first enterprise role assigned to the user identification code; a third determination module, configured to, for each first target project, determine a first project permission set corresponding to the user in the first target project according to the user identification code; a relevant status determination module, configured to, for each first target project, determine the relevant status between each first enterprise permission and the first target project, where the relevant status is used to indicate whether to incorporate the first enterprise permission into the first target project; a permission determination module, configured to, for each first target project, determine a first target permission set of the user for the first target project according to the relevant status and the first project permission set corresponding to the first target project; the relevant status includes an associated status and a non-associated status; the permission determination module is further configured to: for each first target project: traverse the relevant status between each first enterprise permission and the first target project; if the relevant status between the first enterprise permission and the first target project is the associated status, incorporate the first enterprise permission into the first project permission set corresponding to the first target project to obtain the first target permission set of the first target project; if the relevant status between the first enterprise permission and the first target project is the non-associated status, do not incorporate the first enterprise permission into the first project permission set; the device further includes a project permission switching module, configured to: display the project content of the current first target project browsed by the user on a project viewing interface, where the corresponding project content is displayed to the user according to the first target permission set of the user for the current first target project stored in a preset storage area; receive a project switching request executed by the user on the project viewing interface, where the project switching request includes a project identifier indicating the first target project to be switched to; acquire the first target permission set of the first target project to be switched to according to the project identifier, and replace the first target permission set for the current first target project with the acquired first target permission set of the first target project to be switched to; display the corresponding project content to the user based on the first target permission set of the user for the first target project to be switched to stored in the preset storage area.

Citation Information

Patent Citations

  • Project switch-on / off control method and system

    CN107659427A