A method, system, device and storage medium for permission control

CN116340974BActive Publication Date: 2026-09-18SHANGHAI ZHONGTONGJI NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310238247.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-13
Publication Date
2026-09-18
Estimated Expiration
2043-03-13

AI Technical Summary

Technical Problem

但是在报表展示的时候一般需要对数据权限做出限制,但是一般公司都会有自己的组织架构以及权限控制系统,需要在两套系统之间做兼容处理,导致数据权限过滤过程复杂且数据权限过滤不够准确

Benefits of technology

[0030] This application monitors relevant user data in the relevant enterprise system. If the relevant user data changes in the relevant enterprise system, the changed information is synchronized to FineReport in real time. Using the result of the synchronized data to FineReport, a report proxy service is used for joint processing. Using the result of the joint processing by the report proxy service, the current user identity is queried through a preset intermediate relationship table, and data permission filtering is performed on the relevant user data in the relevant enterprise system. This application helps solve the compatibility issues between the relevant enterprise system and the FineReport system when creating reports using FineReport, simplifying the complex data permission filtering process and improving the accuracy of data permission filtering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116340974B_ABST
    Figure CN116340974B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data processing, in particular to a permission control method, system, device and storage medium. The method comprises the following steps: real-time monitoring of relevant data information of relevant users in a relevant enterprise system; if the relevant data information of the relevant users in the relevant enterprise system changes, the change information is synchronised to FineReport in real time; the relevant data information is synchronised to FineReport, and the result is jointly processed through a report agent service; the result of the joint processing of the report agent service is used to query the current user identity through a preset intermediate relationship table, and the relevant data information of the relevant users in the relevant enterprise system is filtered according to the data permission. The application helps to solve the compatibility processing between the relevant enterprise system and the FineReport system through the report agent service when the report is made through FineReport, simplifies the data permission filtering process, and improves the accuracy of the data permission filtering.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a method, system, device and storage medium for access control. Background Technology

[0002] While the existing FineReport system allows users to create roles and positions to control report permissions, real-world access control is often more complex, and this model frequently clashes with an enterprise's internal organizational structure. For example, in the franchised express delivery industry, organizations are typically divided into regions, centers, performance-based outlets, regular outlets, and contracted areas, making the existing model completely inadequate.

[0003] For example, when developing data reports, we often use reporting systems to create reports, such as FineReport. However, when displaying reports, it is generally necessary to restrict data permissions. But companies usually have their own organizational structure and access control systems, requiring compatibility processing between the two systems. This makes the data permission filtering process complex and inaccurate.

[0004] In existing technologies, when creating reports using FineReport, compatibility processing is required between the relevant enterprise system and the FineReport system, resulting in a complex data permission filtering process that is not accurate or flexible enough. Summary of the Invention

[0005] To at least partially overcome the problem in related technologies where compatibility processing between relevant enterprise systems and the FineReport system is required when creating reports using FineReport, resulting in complex and inaccurate data permission filtering, this application provides a method, system, device, and storage medium for access control.

[0006] The proposed solution is as follows:

[0007] Firstly, this application provides a method for access control, the method comprising:

[0008] Real-time monitoring of relevant user data information in relevant enterprise systems;

[0009] If the relevant data information of the relevant users in the relevant enterprise system changes, the changed information will be synchronized to FineReport in real time.

[0010] The results of synchronizing the relevant data information to FineReport are then processed jointly through the report proxy service.

[0011] Using the results of the joint processing of the report proxy service, the current user's identity is queried through a preset intermediate relationship table, and data permission filtering is performed on the relevant data information of the relevant users in the relevant enterprise system.

[0012] Furthermore, the process of synchronizing the relevant data information to FineReport and then performing joint processing through the report proxy service includes:

[0013] Using the results of synchronizing the relevant data information to FineReport, an intermediate relationship table is constructed. The intermediate relationship table is used to store the relevant information of relevant users in the relevant enterprise system and the relevant data information of relevant users in the relevant enterprise system in FineReport, as well as the relationship information between the two.

[0014] Using the aforementioned intermediate relationship table, data access permission information is obtained through data warehouse processing.

[0015] Using the results of synchronizing the relevant data information to FineReport and the relevant data permissions, the user information in the token of the relevant enterprise system is parsed through the report proxy service.

[0016] Furthermore, the step of using an intermediate relationship table and processing it through a data warehouse to obtain data permission scope information includes:

[0017] The data warehouse periodically calculates the data permission information of each relevant user in the relevant enterprise system, and generates user data permission range data for each user.

[0018] Furthermore, the process of using the results of the joint processing of the report proxy service to query the current user's identity through a preset intermediate relationship table, and filtering the relevant data information of the relevant users in the relevant enterprise system for data permissions, includes:

[0019] Using the results of the joint processing of the report proxy service, the set of data permission scope information and the results of parsing user information in the token of the relevant enterprise system is used as the query condition. The current user identity is queried through the intermediate relationship table, and data permissions are filtered for relevant users in the relevant enterprise system.

[0020] Secondly, this application provides an access control system, the system comprising:

[0021] The monitoring module is used to monitor relevant data information of relevant users in the relevant enterprise system in real time.

[0022] The acquisition module is used to synchronize the changed information to FineReport in real time if the relevant data information of the relevant users in the relevant enterprise system changes.

[0023] The data processing module is used to synchronize the relevant data information to FineReport and perform joint processing through the report proxy service;

[0024] The data permission filtering module is used to utilize the results of the joint processing of the report proxy service, query the current user's identity through a preset intermediate relationship table, and filter the data permissions of relevant data information of relevant users in the relevant enterprise system.

[0025] Thirdly, this application provides an access control device, the device comprising:

[0026] Memory, on which executable programs are stored;

[0027] A processor for executing the executable program in the memory to implement the steps of any of the methods described above.

[0028] Fourthly, this application provides a computer-readable storage medium storing computer instructions for causing a computer to perform the steps of any of the methods described above.

[0029] The technical solution provided in this application may include the following beneficial effects:

[0030] This application monitors relevant user data in the relevant enterprise system. If the relevant user data changes in the relevant enterprise system, the changed information is synchronized to FineReport in real time. Using the result of the synchronized data to FineReport, a report proxy service is used for joint processing. Using the result of the joint processing by the report proxy service, the current user identity is queried through a preset intermediate relationship table, and data permission filtering is performed on the relevant user data in the relevant enterprise system. This application helps solve the compatibility issues between the relevant enterprise system and the FineReport system when creating reports using FineReport, simplifying the complex data permission filtering process and improving the accuracy of data permission filtering.

[0031] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0032] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0033] Figure 1 This is a schematic flowchart of a method for access control provided in one embodiment of this application;

[0034] Figure 2 This is a schematic diagram of the system composition for access control provided in another embodiment of this application;

[0035] Figure 3 This is a schematic diagram of a device composition for access control provided in another embodiment of this application. Detailed Implementation

[0036] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0037] Example 1

[0038] Please see Figure 1 , Figure 1 This is a schematic flowchart of an access control method according to an embodiment of this application, the method including:

[0039] S1. Monitor relevant user data information in relevant enterprise systems in real time;

[0040] S2. If the relevant data information of the relevant users in the relevant enterprise system changes, the changed information will be synchronized to FineReport in real time;

[0041] S3. Utilize the results synchronized to FineReport using the relevant data information, and perform joint processing through the report proxy service;

[0042] S4. Using the results of the joint processing of the report proxy service, query the current user's identity through a preset intermediate relationship table, and filter the relevant data information of the relevant users in the relevant enterprise system for data permissions.

[0043] In one embodiment, as described in step S3, the process of synchronizing the results of the relevant data information to FineReport and performing joint processing through a report proxy service includes:

[0044] Using the results of synchronizing the relevant data information to FineReport, an intermediate relationship table is constructed. The intermediate relationship table is used to store the relevant information of relevant users in the relevant enterprise system and the relevant data information of relevant users in the relevant enterprise system in FineReport, as well as the relationship information between the two.

[0045] Using the aforementioned intermediate relationship table, data access permission information is obtained through data warehouse processing.

[0046] Using the results of synchronizing the relevant data information to FineReport and the relevant data permissions, the user information in the token of the relevant enterprise system is parsed through the report proxy service.

[0047] Specifically, the process of using an intermediate relationship table and processing it through a data warehouse to obtain data permission scope information includes:

[0048] The data warehouse periodically calculates the data permission information of each relevant user in the relevant enterprise system, and generates user data permission range data for each user.

[0049] Specifically, the process of using the results of the joint processing of the report proxy service to query the current user's identity through a preset intermediate relationship table, and filtering the relevant data information of the relevant users in the relevant enterprise system for data permissions, includes:

[0050] Using the results of the joint processing of the report proxy service, the set of data permission scope information and the results of parsing user information in the token of the relevant enterprise system is used as the query condition. The current user identity is queried through the intermediate relationship table, and data permissions are filtered for relevant users in the relevant enterprise system.

[0051] In practice, the relationship between enterprise system users and FineReport users is handled and maintained through an intermediate relationship table in the report proxy service. The proxy service detects user changes in the enterprise system and synchronizes them to FineReport in near real-time, while simultaneously storing the relationships through the intermediate relationship table. The data warehouse then uses this relationship to periodically calculate user data permission scopes and generate a user data permission table.

[0052] Specifically, the report proxy service parses the user information from the business system's token, acting as a single sign-on mechanism. When FineReport queries report data, this user information is included and used as a filter condition during the query. Combined with the data permission table generated above, this completes the filtering of data permissions.

[0053] In one embodiment, a report proxy service is used to connect various business systems and FineReport. Complex logic is completed within the proxy service, reducing the complexity of business system integration. The report proxy service parses tokens for federated login, and user permission filtering is handled in the backend program, eliminating the need for the frontend to pass filtering conditions, thus ensuring data security. Federated login is achieved by generating a relationship table between enterprise system users and FineReport users, and data permissions are filtered using a user permission table, enabling interconnection even when the organizational structures of the two systems are completely different.

[0054] In practice, the method of generating user permission tables does not need to be so granular. Instead, the internal organizational structure of the enterprise can be synchronized to the data warehouse. When querying report data, the permissions of users corresponding to the organizational structure can be queried. However, this method will result in high complexity of query conditions and reduced query performance.

[0055] This application monitors relevant user data in a relevant enterprise system in real time. If the relevant user data changes in the relevant enterprise system, the changed information is synchronized to FineReport in real time. Using the results of this synchronization to FineReport, a report proxy service is used for joint processing. Using the results of this joint processing, a preset intermediate relationship table is used to query the current user's identity, and data permission filtering is applied to the relevant user data in the relevant enterprise system. This application helps solve the compatibility issues between the relevant enterprise system and the FineReport system when creating reports using FineReport, simplifying the complex data permission filtering process and improving the accuracy of data permission filtering.

[0056] Please refer to Example 2 Figure 2 , Figure 2 This is a schematic diagram of an access control system according to another embodiment of this application, the system comprising:

[0057] The monitoring module 101 is used to monitor relevant data information of relevant users in the relevant enterprise system in real time.

[0058] The acquisition module 102 is used to synchronize the changed information to FineReport in real time if the relevant data information of the relevant users in the relevant enterprise system changes.

[0059] Data processing module 103 is used to utilize the results of synchronizing the relevant data information to FineReport and perform joint processing through the report proxy service;

[0060] The data permission filtering module 104 is used to use the results of the joint processing of the report proxy service to query the current user identity through a preset intermediate relationship table and filter the relevant data information of the relevant users in the relevant enterprise system for data permissions.

[0061] Example 3

[0062] Please see Figure 3 , Figure 3 This is a schematic diagram of a device composition for access control according to another embodiment of this application, the device including:

[0063] Memory 31, on which an executable program is stored;

[0064] Processor 32 is configured to execute the executable program in the memory 31 to implement the steps of any of the methods described above.

[0065] Furthermore, this application provides a computer-readable storage medium storing computer instructions for causing a computer to perform the steps of any of the methods described above. The storage medium may be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), etc.; the storage medium may also include combinations of the above types of memory.

[0066] It is understood that the same or similar parts in the above embodiments can be referred to each other, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.

[0067] It should be noted that in the description of this application, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means at least two.

[0068] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.

[0069] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0070] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0071] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0072] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0073] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0074] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. A method for access control, characterized in that, The method includes: Real-time monitoring of relevant user data information in relevant enterprise systems; If the relevant data information of the relevant users in the relevant enterprise system changes, the changed information will be synchronized to FineReport in real time; The results of synchronizing the relevant data information to FineReport are then processed jointly through the report proxy service. Using the results of the joint processing of the report proxy service, the current user's identity is queried through a preset intermediate relationship table, and data permission filtering is performed on the relevant data information of the relevant users in the relevant enterprise system; The process of synchronizing the relevant data information to FineReport and then performing joint processing through the report proxy service includes: Using the results of synchronizing the relevant data information to FineReport, an intermediate relationship table is constructed. The intermediate relationship table is used to store the relevant information of relevant users in the relevant enterprise system and the relevant data information of relevant users in the relevant enterprise system in FineReport, as well as the relationship information between the two. Using the aforementioned intermediate relationship table, data access permission information is obtained through data warehouse processing. Using the results synchronized to FineReport and related data permissions, the user information in the token of the relevant enterprise system is parsed through the report proxy service; The process of jointly processing the results using the report proxy service involves querying the current user's identity through a preset intermediate relationship table and filtering the relevant data information of the relevant users in the relevant enterprise system based on data permissions, including: Using the results of the joint processing of the report proxy service, the set of data permission scope information and the results of parsing user information in the token of the relevant enterprise system is used as the query condition. The current user identity is queried through the intermediate relationship table, and data permissions are filtered for relevant users in the relevant enterprise system.

2. The method according to claim 1, characterized in that, The process of using an intermediate relationship table and processing it through a data warehouse to obtain data permission scope information includes: The data warehouse periodically calculates the data permission information of each relevant user in the relevant enterprise system, and generates user data permission range data for each user.

3. A system for access control, applied to the access control method according to any one of claims 1-2, characterized in that, The system includes: The monitoring module is used to monitor relevant data information of relevant users in the relevant enterprise system in real time. The acquisition module is used to synchronize the changed information to FineReport in real time if the relevant data information of the relevant users in the relevant enterprise system changes. The data processing module is used to synchronize the relevant data information to FineReport and perform joint processing through the report proxy service; The data permission filtering module is used to utilize the results of the joint processing of the report proxy service, query the current user's identity through a preset intermediate relationship table, and filter the data permissions of relevant data information of relevant users in the relevant enterprise system.

4. A device for access control, characterized in that, The device includes: Memory, on which executable programs are stored; A processor for executing the executable program in the memory to implement the steps of the method according to any one of claims 1-2.

5. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the steps of the method according to any one of claims 1-2.

Citation Information

Patent Citations

  • Method for managing user-defined report system through business system

    CN113626425A

  • Data authority control system and method based on intelligent report platform

    CN115270088A