Annotation-based permission verification method, device, electronic device, and storage medium
Through the annotation-based permission verification method, different types of login state requests are parsed and processed, and the problem that the existing technology can only be used for one type of login state verification is solved, and flexible verification of multiple types of login states is achieved.
Patent Information
- Application Number
- CN202211320182.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-26
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-10-26
AI Technical Summary
The existing account authentication and permission management modules can only be verified for one type of login state and cannot adapt to different types of login states.
Using annotation-based permission verification method, by analyzing the login request sent by the user terminal, determining the annotation information of the target field, and querying the corresponding login state processing identifier in the data set to obtain the login state processing object for verification.
It realizes adaptation and verification of different types of login states, supports multiple types of login state verification, and improves the flexibility and adaptability of permission verification.
Smart Images

Figure CN115632868B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and in particular to an annotation-based permission verification method, device, electronic device and storage medium. Background Art
[0002] Account authentication and permissions have always been an important module of web application systems. Currently, the existing account authentication and permission management modules can only verify one type of login state. Summary of the invention
[0003] The purpose of the embodiments of the present application is to provide an annotation-based permission verification method, device, electronic device and storage medium, so as to adapt the corresponding login state processing objects for different types of login states, thereby supporting the verification of multiple types of login states.
[0004] In a first aspect, the present invention provides an annotation-based permission verification method, the method comprising:
[0005] When receiving a login request sent by a user terminal, parsing the login request and obtaining a parsing result;
[0006] Determine whether the parsing result contains a target field, and if the parsing result contains the target field, determine annotation information corresponding to the target field;
[0007] Based on the annotation information of the target field, query the first data set for a login state processing identifier corresponding to the annotation information, wherein the first data set stores at least two pre-selected login state processing identifiers and a mapping relationship between each of the pre-selected login state processing identifiers and pre-selected annotation information;
[0008] Acquire a login state processing object based on the login state processing identifier;
[0009] The login state carried in the login request is verified based on the login state processing object, and the permission range corresponding to the login state is determined based on the verification result of the login state.
[0010] In the first aspect of the present application, when a login request sent by a user terminal is received, the login request is parsed to obtain a parsing result, and then by judging whether the parsing result contains a target field, the annotation information corresponding to the target field can be determined when the parsing result contains the target field, and then based on the annotation information of the target field, a login state processing identifier corresponding to the annotation information can be queried in the first data set, and then a login state processing object can be obtained based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0011] Compared with the prior art, since the first data set of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information.
[0012] In an optional implementation manner, before verifying the login state carried in the login request based on the login state processing object and determining the permission scope corresponding to the login state based on the verification result of the login state, the method further includes:
[0013] Determine whether the login request carries the login state, and if the login request does not carry the login state, return first prompt information to the user terminal, wherein the first prompt information is used to prompt the user of the user terminal to log in again.
[0014] In the above optional implementation manner, by judging whether the login request carries the login state, the first prompt information can be returned to the user terminal when the login request does not carry the login state.
[0015] In an optional embodiment, the method further comprises:
[0016] When the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information is queried in a configuration file under a preset namespace.
[0017] In the above optional implementation, when the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information can be queried through a configuration file under a preset namespace.
[0018] In an optional embodiment, the method further comprises:
[0019] When the login state processing identifier corresponding to the annotation information cannot be found based on the configuration file under the preset namespace, obtaining preset verification information;
[0020] The login state carried in the login request is verified based on the preset verification configuration information, and the authority range corresponding to the login state is determined based on the verification result of the login state.
[0021] In the above-mentioned optional implementation, when the login state processing identifier corresponding to the annotation information cannot be queried based on the configuration file under the preset namespace, the preset verification information can be obtained, and then the login state carried by the login request can be verified based on the preset verification configuration information, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0022] In a second aspect, the present invention provides an annotation-based permission verification device, the device comprising:
[0023] A receiving module, used for receiving a login request sent by a user terminal;
[0024] The parsing module is used to parse the login request sent by the user terminal and obtain the parsing result when receiving the login request;
[0025] A first judgment module is used to judge whether the parsing result contains a target field, and if the parsing result contains the target field, determine annotation information corresponding to the target field;
[0026] A first query module, used for querying a login state processing identifier corresponding to the annotation information in a first data set based on the annotation information of the target field, wherein the first data set stores at least two pre-selected login state processing identifiers and a mapping relationship between each of the pre-selected login state processing identifiers and pre-selected annotation information;
[0027] A first acquisition module, used to acquire a login state processing object based on the login state processing identifier;
[0028] A verification module is used to verify the login state carried in the login request based on the login state processing object, and determine the authority scope corresponding to the login state based on the verification result of the login state.
[0029] In the second aspect of the present application, when a login request sent by a user terminal is received, the login request is parsed to obtain a parsing result, and then by judging whether the parsing result contains a target field, the annotation information corresponding to the target field can be determined when the parsing result contains the target field, and then the login state processing identifier corresponding to the annotation information can be queried in the first data set based on the annotation information of the target field, and then the login state processing object can be obtained based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0030] Compared with the prior art, since the first data set of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information.
[0031] In an optional embodiment, the device further comprises:
[0032] A second judgment module is used to judge whether the login request carries the login state before verifying the login state carried by the login request based on the login state processing object and determining the authority scope corresponding to the login state based on the verification result of the login state; if the login request does not carry the login state, a first prompt message is returned to the user terminal, wherein the first prompt message is used to prompt the user of the user terminal to log in again.
[0033] In the above optional implementation manner, by judging whether the login request carries the login state, the first prompt information can be returned to the user terminal when the login request does not carry the login state.
[0034] In an optional embodiment, the device further comprises:
[0035] The second query module is used to query the login state processing identifier corresponding to the annotation information in the configuration file under the preset namespace when the login state processing identifier corresponding to the annotation information does not exist in the first data set.
[0036] In the above optional implementation, when the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information can be queried through a configuration file under a preset namespace.
[0037] In an optional embodiment, the device further comprises:
[0038] A second acquisition module is used to acquire preset verification information when the login state processing identifier corresponding to the annotation information cannot be found based on the configuration file under the preset namespace;
[0039] Furthermore, the verification module is further used to verify the login state carried in the login request based on the preset verification configuration information, and determine the authority scope corresponding to the login state based on the verification result of the login state.
[0040] When the login state processing identifier corresponding to the annotation information cannot be found based on the configuration file under the preset namespace, the preset verification information can be obtained to verify the login state carried by the login request based on the preset verification configuration information, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0041] In a third aspect, the present invention provides an electronic device, comprising:
[0042] Processor; and
[0043] A memory is configured to store machine-readable instructions, which, when executed by the processor, execute the annotation-based permission verification method as described in any one of the aforementioned implementations.
[0044] The electronic device disclosed in the third aspect of the present application executes an annotation-based permission verification method, and then when receiving a login request sent by a user terminal, it can obtain a parsing result by parsing the login request, and then by judging whether there is a target field in the parsing result, it can determine the annotation information corresponding to the target field when the target field exists in the parsing result, and then based on the annotation information of the target field, it can query the login state processing identifier corresponding to the annotation information in the first data set, and then based on the login state processing identifier, it can obtain the login state processing object, so that the login state carried by the login request can be verified based on the login state processing object, and the permission scope corresponding to the login state can be determined based on the verification result of the login state.
[0045] Compared with the prior art, since the first data set of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information.
[0046] In a fourth aspect, the present invention provides a storage medium storing a computer program, wherein the computer program is executed by a processor as the annotation-based permission verification method as described in any of the aforementioned implementation modes.
[0047] The storage medium disclosed in the third aspect of the present application executes an annotation-based permission verification method, and when a login request sent by a user terminal is received, the login request is parsed to obtain a parsing result, and then by judging whether the parsing result contains a target field, the annotation information corresponding to the target field can be determined when the parsing result contains the target field, and then the login state processing identifier corresponding to the annotation information can be queried in the first data set based on the annotation information of the target field, and then the login state processing object can be obtained based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the permission range corresponding to the login state can be determined based on the verification result of the login state.
[0048] Compared with the prior art, since the first data set of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0050] Figure 1 It is a flowchart of an annotation-based permission verification method disclosed in an embodiment of the present application;
[0051] Figure 2 It is a structural diagram of an annotation-based permission verification device disclosed in an embodiment of the present application;
[0052] Figure 3 It is a structural schematic diagram of an electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION
[0053] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0054] Embodiment 1
[0055] See also Figure 1 , Figure 1 is a flowchart of an annotation-based permission verification method disclosed in an embodiment of the present application, such as Figure 1 As shown, the method of the embodiment of the present application includes the following steps:
[0056] 101. When receiving a login request sent by a user terminal, parse the login request and obtain a parsing result;
[0057] 102. Determine whether the target field exists in the parsing result. If the target field exists in the parsing result, determine annotation information corresponding to the target field.
[0058] 103. Based on the annotation information of the target field, query the first data set for a login state processing identifier corresponding to the annotation information, wherein the first data set stores at least two pre-selected login state processing identifiers and a mapping relationship between each pre-selected login state processing identifier and pre-selected annotation information;
[0059] 104. Acquire a login state processing object based on the login state processing identifier;
[0060] 105. Verify the login state carried in the login request based on the login state processing object, and determine the permission scope corresponding to the login state based on the verification result of the login state.
[0061] In an embodiment of the present application, when a login request sent by a user terminal is received, the login request is parsed to obtain a parsing result, and then by determining whether the target field exists in the parsing result, the annotation information corresponding to the target field can be determined when the target field exists in the parsing result, and then the login state processing identifier corresponding to the annotation information can be queried in the first data set based on the annotation information of the target field, and then the login state processing object can be obtained based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0062] Compared with the prior art, since the first data set of the embodiment of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information.
[0063] In the embodiment of the present application, the method of the embodiment of the present application can be applied to a server, wherein the server is connected to the user terminal in communication, and then the server can receive a login request sent by the user terminal. Further, with respect to step 101, a specific method of parsing the login request and obtaining the parsing result is:
[0064] Identify the protocol type of the login request, parse the login request based on the protocol type, and obtain the parsing result.
[0065] In the embodiment of the present application, specifically, the parsing result includes a login state, wherein the login state refers to an identity token sent by the server to the user terminal, which indicates that the user terminal is in a trusted communication state with the server, and the identity token enables the server to verify the authority of the user terminal. Further, there are multiple types of login states. For example, if the token used by the user terminal saves the user's account information and other login information, then the user terminal uses a token-type login state, and if the session used by the user terminal saves the user's account information and other login information, then the user terminal uses a session-type login state. Based on this, the server performs different processing methods for different types of login states. For example, the session-type login state is processed using processing method A, and the token-type login state is processed using processing method B, wherein processing method A and processing method B are implemented through a login state processing object, that is, the login state processing object includes the properties and methods required to implement processing methods A and B.
[0066] In an embodiment of the present application, for step 101, the parsing result also includes fields other than the login status, for example, a custom field A, or a field indicating the method of sending the login request, wherein these fields can all be used as target fields.
[0067] In the embodiment of the present application, with respect to step 102, illustratively, assuming that field B needs to be used as the target field, it is necessary to determine whether field B is included in the parsing result.
[0068] In the embodiment of the present application, for step 103, the first data set may be a set map set, wherein the annotation information in the map set is used as the key, and the pre-selected login state processing identifier is used as the value.
[0069] In an embodiment of the present application, for step 104, the specific method of obtaining the login state processing object based on the login state processing identifier is: creating a login state processing object based on the login state processing identifier, or searching the login state processing object corresponding to the login state processing identifier from the memory.
[0070] In the embodiment of the present application, for step 105, a specific process of verifying the login state carried in the login request based on the login state processing object and determining the permission scope corresponding to the login state based on the verification result of the login state is as follows:
[0071] The time verification method of the login state processing object is called to verify whether the login state time is within the preset time range. If so, it is determined that the login state verification has passed, and the permission range corresponding to the login state is determined based on the permission database, where the permission range represents the range of resources that the user terminal can access.
[0072] In an optional implementation, before step 104: verifying the login state carried in the login request based on the login state processing object and determining the permission scope corresponding to the login state based on the verification result of the login state, the method of the embodiment of the present application further includes the following steps:
[0073] It is determined whether the login request carries the login state. If the login request does not carry the login state, a first prompt message is returned to the user terminal, wherein the first prompt message is used to prompt the user of the user terminal to log in again.
[0074] In the above optional implementation manner, by judging whether the login request carries the login state, the first prompt information can be returned to the user terminal when the login request does not carry the login state.
[0075] In the above optional implementation, the first prompt information is used to prompt the user to log in again, for example, the first prompt information may be “Login status cannot be obtained, please log in again.” Further, when the user logs in again, the server will assign a new login status to the user terminal based on a preset program.
[0076] The application scenario of the above optional implementation mode may be: the user clears the cache data of the user terminal browser, thereby causing the login state in the buffered data to be cleared.
[0077] In an optional implementation manner, the method of the embodiment of the present application further includes the following steps:
[0078] When the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information is queried in the configuration file under the preset namespace.
[0079] In the above optional implementation manner, when the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information can be queried through a configuration file under a preset namespace.
[0080] In the above optional implementation manner, the configuration file under the preset namespace refers to the configuration file under the specified directory.
[0081] In an optional implementation manner, the method of the embodiment of the present application further includes the following steps:
[0082] When the login state processing identifier corresponding to the comment information cannot be found based on the configuration file under the preset namespace, the preset verification information is obtained;
[0083] The login state carried in the login request is verified based on the preset verification configuration information, and the permission scope corresponding to the login state is determined based on the verification result of the login state.
[0084] In the above optional implementation, when the login state processing identifier corresponding to the annotation information cannot be queried based on the configuration file under the preset namespace, the preset verification information can be obtained, and the login state carried by the login request can be verified based on the preset verification configuration information, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0085] Embodiment 2
[0086] See also Figure 2 , Figure 2 is a schematic diagram of the structure of an annotation-based permission verification device disclosed in an embodiment of the present application, such as Figure 2 As shown, the device of the embodiment of the present application includes the following functional modules:
[0087] Receiving module 201, used to receive a login request sent by a user terminal;
[0088] The parsing module 202 is used to parse the login request and obtain the parsing result when receiving the login request sent by the user terminal;
[0089] The first judgment module 203 is used to judge whether the parsing result contains the target field, and if the parsing result contains the target field, determine the annotation information corresponding to the target field;
[0090] A first query module 204 is used to query the login state processing identifier corresponding to the annotation information in the first data set based on the annotation information of the target field, and the first data set stores at least two pre-selected login state processing identifiers and a mapping relationship between each pre-selected login state processing identifier and the pre-selected annotation information;
[0091] A first acquisition module 205, configured to acquire a login state processing object based on a login state processing identifier;
[0092] The verification module 206 is used to verify the login state carried in the login request based on the login state processing object, and determine the permission range corresponding to the login state based on the verification result of the login state.
[0093] In an embodiment of the present application, when a login request sent by a user terminal is received, the login request is parsed to obtain a parsing result, and then by determining whether the target field exists in the parsing result, the annotation information corresponding to the target field can be determined when the target field exists in the parsing result, and then the login state processing identifier corresponding to the annotation information can be queried in the first data set based on the annotation information of the target field, and then the login state processing object can be obtained based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0094] Compared with the prior art, since the first data set of the embodiment of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the example of the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information can make the login state verification method more flexible.
[0095] In an optional implementation manner, the device of the embodiment of the present application may also include the following functional modules:
[0096] The second judgment module is used to verify the login state carried by the login request based on the login state processing object, and before determining the authority scope corresponding to the login state based on the verification result of the login state, determine whether the login request carries the login state; if the login request does not carry the login state, return the first prompt information to the user terminal, wherein the first prompt information is used to prompt the user of the user terminal to log in again.
[0097] In the above optional implementation manner, by judging whether the login request carries the login state, the first prompt information can be returned to the user terminal when the login request does not carry the login state.
[0098] In an optional implementation manner, the device of the embodiment of the present application further includes the following functional modules:
[0099] The second query module is used to query the login state processing identifier corresponding to the annotation information in the configuration file under the preset namespace when the login state processing identifier corresponding to the annotation information does not exist in the first data set.
[0100] In the above optional implementation manner, when the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information can be queried through a configuration file under a preset namespace.
[0101] In an optional implementation manner, the device of the embodiment of the present application further includes the following functional modules:
[0102] The second acquisition module is used to acquire preset verification information when the login state processing identifier corresponding to the comment information cannot be found based on the configuration file under the preset namespace;
[0103] Furthermore, the verification module is further used to verify the login state carried in the login request based on preset verification configuration information, and determine the authority scope corresponding to the login state based on the verification result of the login state.
[0104] When the login state processing identifier corresponding to the annotation information cannot be found in the configuration file under the preset namespace, the preset verification information can be obtained to verify the login state carried by the login request based on the preset verification configuration information, and the authority scope corresponding to the login state can be determined based on the verification result of the login state.
[0105] It should be noted that for other detailed descriptions of the device in the embodiment of the present application, please refer to the relevant description of the embodiment of the present application, and the embodiment of the present application will not go into details.
[0106] Embodiment 3
[0107] See also Figure 3 , Figure 3 is a schematic diagram of the structure of an electronic device disclosed in an embodiment of the present application, such as Figure 3 As shown, the electronic device of the embodiment of the present application includes:
[0108] Processor 301; and
[0109] The memory 303 is configured to store machine-readable instructions. When the instructions are executed by the processor 301, the permission verification method based on annotations as described in any one of the aforementioned implementations is performed.
[0110] The electronic device disclosed in the embodiment of the present application executes an annotation-based permission verification method, and when receiving a login request sent by a user terminal, it can obtain a parsing result by parsing the login request, and then determine whether there is a target field in the parsing result, and when the target field exists in the parsing result, it can determine the annotation information corresponding to the target field, and then query the login state processing identifier corresponding to the annotation information in the first data set based on the annotation information of the target field, and then obtain the login state processing object based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the permission scope corresponding to the login state can be determined based on the verification result of the login state.
[0111] Compared with the prior art, since the first data set of the embodiment of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the embodiment of the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the embodiment of the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information.
[0112] Embodiment 4
[0113] An embodiment of the present application discloses a storage medium storing a computer program, and the computer program is executed by a processor as an annotation-based permission verification method as described in any of the aforementioned implementations.
[0114] The storage medium disclosed in the embodiment of the present application executes an annotation-based permission verification method, and when a login request sent by a user terminal is received, the login request is parsed to obtain a parsing result, and then by judging whether the parsing result contains a target field, the annotation information corresponding to the target field can be determined when the parsing result contains the target field, and then the login state processing identifier corresponding to the annotation information can be queried in the first data set based on the annotation information of the target field, and then the login state processing object can be obtained based on the login state processing identifier, so that the login state carried by the login request can be verified based on the login state processing object, and the permission scope corresponding to the login state can be determined based on the verification result of the login state.
[0115] Compared with the prior art, since the first data set of the embodiment of the present application includes at least two pre-selected login state processing identifiers, it is possible to match the login state processing identifier corresponding to the annotation information based on the first data set, and then adaptively use the login state processing object to verify the login state based on the login state processing identifier. In other words, the embodiment of the present application can adapt the corresponding login state processing object for different types of login states, thereby supporting the verification of multiple types of login states. On the other hand, the embodiment of the present application can more flexibly verify the login state through the mapping relationship between the pre-selected login state processing identifier and the pre-selected annotation information.
[0116] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.
[0117] In addition, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0118] Furthermore, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0119] It should be noted that if the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can essentially be embodied in the form of a software product, or in other words, the part that contributes to the prior art or the part of the technical solution. The computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM) random access memory (RAM), disk or optical disk, and other media that can store program codes.
[0120] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any such actual relationship or order between these entities or operations.
[0121] The above are only embodiments of the present application and are not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the scope of protection of the present application.
Claims
1. A permission verification method based on annotations, It is characterized in that The method comprises: When receiving a login request sent by a user terminal, parsing the login request and obtaining a parsing result; Determine whether the parsing result contains a target field, and if the parsing result contains the target field, determine annotation information corresponding to the target field; Based on the annotation information of the target field, query the first data set for a login state processing identifier corresponding to the annotation information, wherein the first data set stores at least two pre-selected login state processing identifiers and a mapping relationship between each of the pre-selected login state processing identifiers and pre-selected annotation information; Acquire a login state processing object based on the login state processing identifier; The login state carried in the login request is verified based on the login state processing object, and the permission range corresponding to the login state is determined based on the verification result of the login state.
2. The method according to claim 1, It is characterized in that Before verifying the login state carried in the login request based on the login state processing object and determining the authority scope corresponding to the login state based on the verification result of the login state, the method further includes: Determine whether the login request carries the login state, and if the login request does not carry the login state, return first prompt information to the user terminal, wherein the first prompt information is used to prompt the user of the user terminal to log in again.
3. The method according to claim 1, It is characterized in that The method further comprises: When the login state processing identifier corresponding to the annotation information does not exist in the first data set, the login state processing identifier corresponding to the annotation information is queried in a configuration file under a preset namespace.
4. The method according to claim 3, It is characterized in that The method further comprises: When the login state processing identifier corresponding to the annotation information cannot be found based on the configuration file under the preset namespace, obtaining preset verification information; The login state carried in the login request is verified based on the preset verification information, and the authority range corresponding to the login state is determined based on the verification result of the login state.
5. An annotation-based permission verification device, It is characterized in that The device comprises: A receiving module, used for receiving a login request sent by a user terminal; The parsing module is used to parse the login request sent by the user terminal and obtain the parsing result when receiving the login request; A first judgment module is used to judge whether the parsing result contains a target field, and if the parsing result contains the target field, determine annotation information corresponding to the target field; A first query module, used for querying a login state processing identifier corresponding to the annotation information in a first data set based on the annotation information of the target field, wherein the first data set stores at least two pre-selected login state processing identifiers and a mapping relationship between each of the pre-selected login state processing identifiers and pre-selected annotation information; A first acquisition module, used to acquire a login state processing object based on the login state processing identifier; A verification module is used to verify the login state carried in the login request based on the login state processing object, and determine the authority scope corresponding to the login state based on the verification result of the login state.
6. The device as claimed in claim 5, It is characterized in that The device also includes: A second judgment module is used to judge whether the login request carries the login state before verifying the login state carried by the login request based on the login state processing object and determining the authority scope corresponding to the login state based on the verification result of the login state; if the login request does not carry the login state, a first prompt message is returned to the user terminal, wherein the first prompt message is used to prompt the user of the user terminal to log in again.
7. The device according to claim 5, It is characterized in that The device also includes: The second query module is used to query the login state processing identifier corresponding to the annotation information in the configuration file under the preset namespace when the login state processing identifier corresponding to the annotation information does not exist in the first data set.
8. The device according to claim 7, It is characterized in that The device also includes: A second acquisition module is used to acquire preset verification information when the login state processing identifier corresponding to the annotation information cannot be found based on the configuration file under the preset namespace; Furthermore, the verification module is further used to verify the login state carried in the login request based on the preset verification information, and determine the authority scope corresponding to the login state based on the verification result of the login state.
9. An electronic device, It is characterized in that include: processor; as well as A memory configured to store machine-readable instructions, which, when executed by the processor, execute the annotation-based permission verification method as described in any one of claims 1 to 4.
10. A storage medium, It is characterized in that The storage medium stores a computer program, and the computer program is executed by a processor according to the annotation-based permission verification method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Method and device for performing authentication and authorization based on aspect-oriented programming (AOP)
CN107508793A
Login access control method and device
CN114282187A