Login control method and device, computer device, and storage medium
By obtaining object identifiers and flags, querying the list of target companies, and controlling the login results of office applications, the problem of data leakage caused by employees logging in with identities from other companies is solved, and the security of internal enterprise data is ensured.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2022-08-16
- Publication Date
- 2026-07-28
AI Technical Summary
In traditional technologies, employees logging into office applications on company computers using the identities of employees from other companies can easily lead to the leakage of internal company data.
By obtaining the object identifier and flag bits of the target object, querying the list of the target enterprise, and controlling the login results of office applications, it is possible to ensure that the target object can only log in as a member of the target enterprise.
This effectively prevents internal data leaks and ensures the security of internal enterprise data.
Smart Images

Figure CN117640119B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a login control method, apparatus, computer equipment, storage medium, and computer program product. Background Technology
[0002] With the development of computer technology, applications are becoming increasingly diverse. For enterprise-oriented office applications, it is necessary to ensure the security of internal enterprise data.
[0003] In traditional technology, a user can be an employee of multiple companies at the same time. They can apply for employee identities under multiple companies in office applications, and users can also log in to office applications using employee identities under different companies. However, if an employee logs in to an office application on their own company's computer using an employee identity from another company, it can easily lead to the leakage of internal data within the company. Summary of the Invention
[0004] Therefore, it is necessary to provide a login control method, device, computer equipment, computer-readable storage medium, and computer program product to address the aforementioned technical problems, which can effectively prevent the leakage of internal enterprise data and ensure the security of internal enterprise data.
[0005] Firstly, this application provides a login control method. The login control method includes:
[0006] In response to a login request for an office application on the desktop, obtain the object identifier of the target object; the target object is the user of the authorized account associated with the office application.
[0007] When an object identifier is configured with a flag, and the flag does not match the login enterprise identifier used when requesting to log in to the office application, obtain the list of target enterprises represented by the flag.
[0008] Based on the object identifier and flag bits, query the target identity identifier of the target object under the target enterprise;
[0009] Control the login results of office applications based on target identity identifiers and list sets.
[0010] Secondly, this application also provides a login control device. The login control device includes:
[0011] The object identifier acquisition module is used to obtain the object identifier of the target object in response to login requests for office applications on the desktop; the target object is the user object of the authorized account associated with the office application.
[0012] The list acquisition module is used to acquire the list of target companies represented by the flag when the object identifier is configured with a flag and the flag does not match the login enterprise identifier used when requesting to log in to the office application.
[0013] The target identity identification module is used to query the target identity of a target object under the target enterprise based on the object identifier and the flag bit;
[0014] The login control module is used to control the login results of office applications based on the target identity and list set.
[0015] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:
[0016] In response to a login request for an office application on the desktop, obtain the object identifier of the target object; the target object is the user of the authorized account associated with the office application.
[0017] When an object identifier is configured with a flag, and the flag does not match the login enterprise identifier used when requesting to log in to the office application, obtain the list of target enterprises represented by the flag.
[0018] Based on the object identifier and flag bits, query the target identity identifier of the target object under the target enterprise;
[0019] Control the login results of office applications based on target identity identifiers and list sets.
[0020] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0021] In response to a login request for an office application on the desktop, obtain the object identifier of the target object; the target object is the user of the authorized account associated with the office application.
[0022] When an object identifier is configured with a flag, and the flag does not match the login enterprise identifier used when requesting to log in to the office application, obtain the list of target enterprises represented by the flag.
[0023] Based on the object identifier and flag bits, query the target identity identifier of the target object under the target enterprise;
[0024] Control the login results of office applications based on target identity identifiers and list sets.
[0025] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:
[0026] In response to a login request for an office application on the desktop, obtain the object identifier of the target object; the target object is the user of the authorized account associated with the office application.
[0027] When an object identifier is configured with a flag, and the flag does not match the login enterprise identifier used when requesting to log in to the office application, obtain the list of target enterprises represented by the flag.
[0028] Based on the object identifier and flag bits, query the target identity identifier of the target object under the target enterprise;
[0029] Control the login results of office applications based on target identity identifiers and list sets.
[0030] The aforementioned login control method, device, computer equipment, storage medium, and computer program product, in response to a login request from a target object to log in to an office application on a desktop, obtain the object identifier of the target object. If the object identifier is configured with a flag bit, and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application, obtain the list of target enterprises represented by the flag bit, and control the login result of the office application based on the target object's target identity identifier under the target enterprise and the list of enterprise identifiers. For the target enterprise, the aforementioned login control method can restrict its members from logging into the office application on the desktop using member identities under other enterprises. In the target enterprise's office environment, its members can only log in to the office application on the desktop in that office environment using their member identities under the target enterprise, which can effectively prevent the leakage of internal data of the target enterprise and ensure the security of internal data. Attached Figure Description
[0031] Figure 1 This is a diagram illustrating the application environment of the login control method in one embodiment;
[0032] Figure 2 This is a flowchart illustrating the login control method in one embodiment;
[0033] Figure 3 This is a schematic diagram of a QR code login page in one embodiment;
[0034] Figure 4 This is a schematic diagram of the login operation page in one embodiment;
[0035] Figure 5 This is a schematic diagram illustrating the display of a first prompt message on the login operation page in one embodiment;
[0036] Figure 6 This is a schematic diagram illustrating the display of a second prompt message on a login prompt page, as shown in one embodiment.
[0037] Figure 7 This is a schematic diagram of a security management page in one embodiment;
[0038] Figure 8 This is a schematic diagram illustrating the on / off state of login restrictions for a target enterprise in an office application, as shown in one scenario embodiment.
[0039] Figure 9 This is a schematic diagram illustrating the process of modifying the flag bits of a member object when a target enterprise adds a new member object, as shown in one scenario embodiment.
[0040] Figure 10 This is a schematic diagram illustrating the process by which a target object logs into an office application on a desktop using its login identity under the logged-in enterprise, as shown in one scenario embodiment.
[0041] Figure 11 This is a schematic diagram of a login control method in a specific embodiment;
[0042] Figure 12 This is a schematic diagram of a login control method in a specific embodiment;
[0043] Figure 13 This is a schematic diagram of a login control method in a specific embodiment;
[0044] Figure 14 This is a structural block diagram of the login control device in one embodiment;
[0045] Figure 15 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0046] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0047] The login control method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, desktop 102 communicates with server 104 and mobile 106 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104, or it can be located in the cloud or on other network servers.
[0048] When a target object logs into the office application on desktop 102, server 104 receives a login request from desktop 102. This login request can be initiated by the office application on desktop 102 when the target object triggers the login control or account switching control of the office application on desktop 102; or it can be initiated by mobile terminal 106 when the target object scans the login graphic code of the office application using a communication application on mobile terminal 106, or triggers the login operation of the office application using wireless sensing on mobile terminal 106. In response to the login request, server 104 obtains the object identifier of the target object. When the target object has configured a flag bit, and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application, server 104 can obtain the list of target enterprises represented by the flag bit. Server 104 can query the target identity identifier of the target object under the target enterprise based on the object identifier and the flag bit. Server 104 can also control the login result of the office application based on the target identity identifier and the list.
[0049] Among them, desktop 102 can be a tablet computer, laptop computer, desktop computer, etc.
[0050] Server 104 can be an independent physical server or a service node in a blockchain system. The service nodes in the blockchain system form a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol that runs on top of the Transmission Control Protocol (TCP).
[0051] In addition, server 104 can also be a server cluster consisting of multiple physical servers, which can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0052] Mobile devices 106 can be smartphones, tablets, IoT devices, and portable wearable devices. Among them, IoT devices can be smart in-vehicle devices, and portable wearable devices can be smartwatches, smart bracelets, and head-mounted devices, etc.
[0053] Desktop 102 can be connected to server 104 and mobile terminal 106 via Bluetooth, USB (Universal Serial Bus) or network communication methods, and this application does not impose any restrictions on this.
[0054] In one embodiment, such as Figure 2As shown, a login control method is provided, which is applied to... Figure 1 Taking the server in the example, the following steps are included:
[0055] Step S202: In response to a login request for an office application on the desktop, obtain the object identifier of the target object; the target object is the user of the authorized account associated with the office application.
[0056] Among them, office applications are enterprise-oriented applications that can provide enterprises with services such as communication, document editing, document sharing, meetings, approvals, and attendance tracking. After logging into the office application with their member identity within the enterprise, members of the enterprise can use the office application to communicate with other members, share documents, and perform work-related tasks such as attendance tracking.
[0057] The authorized account associated with the office application is the account used by the target user. The target user registers for the office application using this account, which is the authorized account associated with the office application. The target user can log in to the office application using this authorized account. In other words, the target user is the user of the authorized account.
[0058] The account used by the target can be the target's phone number, email address, or social media account, where the social media account is linked to an office application with which the office application has business dealings. For example, if the target registers for an office application using their phone number, after successful registration, the target's phone number becomes an authorized account associated with the office application.
[0059] The object identifier of the target object is a unique identifier for the target object in office applications, which can distinguish different objects. For example, when the target object registers for an office application, the server assigns a unique object identifier to the target object. The specific form of the object identifier can be set according to actual needs. For example, the object identifier can be in string form, and the object identifier can include at least one of numbers, letters, or special symbols. This application embodiment does not limit the specific form of the object identifier.
[0060] Specifically, when the target object logs into the office application on the desktop, the server receives the login request; the server obtains the object identifier of the target object carried in the login request.
[0061] In one implementation, the desktop office application displays a login graphic code used to log in to the desktop office application. The target user, already logged in as a member of the mobile office application, scans the login graphic code using the mobile application, which then sends a login request to the server. In this implementation, the mobile application sends a login request to the server, and this login request enables the target user to log in to the desktop office application as a member.
[0062] In another implementation, the target object previously logged into the desktop office application as a specific member and then logged out. The next time the target object logs into the desktop office application, it can trigger the login control on the desktop, which in turn sends a login request to the server. In this implementation, the desktop sends a login request to the server, and this login request is used to enable the target object to log into the desktop office application as a specific member (the same member as during the previous login).
[0063] In another implementation, the target user has already logged into the office application on the desktop as the first member. Using the account switching control in the desktop application, the user switches companies, and then the desktop sends a login request to the server. In this implementation, the desktop sends a login request to the server, and this login request is used to enable the target user to log into the office application on the desktop as a second member. Here, the second member identity is the target user's member identity under the company after the switching operation, while the first member identity is the target user's member identity under the company before the switching operation.
[0064] Step S204: When the object identifier is configured with a flag bit and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application, obtain the list of target enterprises represented by the flag bit.
[0065] The flag is a field associated with the object identifier. The flag restricts the target object to logging into the desktop office application only as a member of the enterprise corresponding to that flag. For example, the object identifier and the flag can be associated in a key-value pair, where the key is the object identifier and the value is the flag of the object identifier.
[0066] The login company identifier is a unique identifier for the company, distinguishing different companies. When a company registers for an office application, the server assigns a unique identifier to it. The target is a member of the login company, logging into the office application on the desktop as a member of that company. For example, if the target is a member of company A, and logs into the office application on the desktop as a member of company A, then company A is the login company, and company A's identifier is the login company identifier.
[0067] The flag bit includes the enterprise identifier, and the target enterprise represented by the flag bit is the enterprise corresponding to the enterprise identifier in the flag bit. The identifier of the target enterprise is the enterprise identifier. For example, the flag bit includes the enterprise identifier (corporation id, corvid): corvid(B), and the enterprise B corresponding to corvid(B) is the target enterprise.
[0068] The target company's list is set by the target company and includes some of its members. These members are not subject to the target company's login restrictions. In other words, if the flag of these members represents the target company, these members can log in to the desktop office application as members of other companies.
[0069] Specifically, the server obtains the flag bit configured for the object identifier. If the flag bit is not empty, it reads the enterprise identifier in the flag bit. The login request carries the login enterprise identifier used when requesting to log in to the office application. The server obtains the login enterprise identifier carried in the login request. If the flag bit does not match the login enterprise identifier, the server obtains the enterprise identifier in the flag bit and searches for the list of names associated with the enterprise identifier.
[0070] If the flag does not match the login company identifier, it means that the login company is not the target company. For example, if the target company restricts the target object from logging into the desktop office application as a member of another company, then the target object's flag is used to identify the target company. If the target object logs into the desktop office application as a member of the login company, the flag does not match the login company identifier. If the target object logs into the desktop office application as a member of the target company, the flag matches the login company identifier.
[0071] If there is only one company identifier in the flag position, the flag position does not match the logged-in company identifier, which may be because the company identifier included in the flag position is different from the logged-in company identifier; if there are at least two company identifiers in the flag position, the flag position does not match the logged-in company identifier, which may be because the flag position does not include a company identifier that is the same as the logged-in company identifier.
[0072] Step S206: Based on the object identifier and the flag bit, query the target identity identifier of the target object under the target enterprise.
[0073] Among them, the target identity identifier is the identifier of the target object's membership status under the target enterprise.
[0074] Specifically, the target object can be a member of multiple companies. Therefore, in office applications, the target object has multiple member identities corresponding to multiple companies, and thus the target object has multiple member identity identifiers corresponding to multiple companies. The multiple member identity identifiers of the target object are associated with the identifiers of the multiple companies to which the target object belongs.
[0075] The flags configured for the object identifier include the enterprise identifier of the target enterprise. The server queries multiple identity identifiers under the object identifier and determines the target identity identifier associated with the enterprise identifier among the multiple identity identifiers.
[0076] For example, let the object identifier of the target object be G1, and the multiple identity identifiers under G1 be v1, v2, v3 and v4, where the identifier of the enterprise corresponding to v1 is corid(A), the identifier of the enterprise corresponding to v2 is corid(B), the identifier of the enterprise corresponding to v3 is corid(C), and the identifier of the enterprise corresponding to v4 is corid(D); assuming that the enterprise identifier included in the flag of the target object is corid(B), then v2 is the target identity identifier of the target object.
[0077] Step S208: Based on the target identity and list set, control the login result of the office application.
[0078] The login results include: logging into the desktop office application based on the target's login member status under the login enterprise, or prohibiting the target's login into the desktop office application based on the target's login member status under the login enterprise.
[0079] In one implementation, the list includes multiple identity identifiers, each corresponding to a multiple object. These multiple objects are members of the target enterprise, and they are not subject to the login restrictions of the target enterprise. If the multiple identity identifiers included in the list include the target identity identifier, then the target object logs into the desktop office application based on its login member identity under the login enterprise. If the multiple identity identifiers included in the list do not include the target identity identifier, then logging into the desktop office application based on the target object's login member identity under the login enterprise is prohibited.
[0080] For example, the list includes multiple identity identifiers: v(a), v(b), v(c), and v(d). Assuming the target identity identifier (the identity identifier of the target object under the target enterprise) is v(a), the target object is not subject to the login restrictions of the target object. That is to say, the target object can log in to the desktop office application using its member identity under other enterprises (including the login enterprise), and the target object can log in to the desktop office application using its login member identity under the login enterprise.
[0081] For example, the list includes multiple identity identifiers: v(a), v(b), v(c), and v(d). Assuming the target identity identifier is v(e), the target object is subject to the login restrictions of the target object. That is, the target object cannot log in to the desktop office application using its member identity under other enterprises (including the login enterprise), thereby prohibiting the target object from logging in to the desktop office application using its login member identity under the login enterprise.
[0082] The aforementioned login control method, in response to a login request from a target object to log in to an office application on a desktop, obtains the target object's object identifier. If the object identifier is configured with a flag, and the flag does not match the login enterprise identifier used when requesting to log in to the office application, it obtains the list of target enterprises represented by the flag. Based on the target object's target identity identifier under the target enterprise and the list, it controls the login result of the office application. For the target enterprise, the aforementioned login control method can restrict its members from logging into the office application on the desktop using member identities under other enterprises. Within the target enterprise's office environment, its members can only log in to the office application on the desktop of that office environment using their member identities under the target enterprise, effectively preventing the leakage of internal data of the target enterprise and ensuring the security of internal enterprise data.
[0083] In some embodiments, obtaining the list of target enterprises represented by the flag bit includes: obtaining the on / off state of the login restriction item of the office application; when the on / off state is on, obtaining the list of target enterprises represented by the flag bit; the data processing method of the media page further includes: when the on / off state is off, logging into the office application based on the login identity identifier of the target object; the login identity identifier is the identity identifier under another enterprise used when requesting to log into the office application.
[0084] Among them, the login restrictions for office applications refer to the login restrictions imposed on the target enterprise in office applications; the login restrictions for the target enterprise in office applications are used to enable or disable the login restriction function of the target enterprise; the open / closed state of the login restriction item includes an open state or a closed state. If the open / closed state of the login restriction item is open, the target enterprise has enabled the login restriction function; if the open / closed state of the login restriction item is closed, the target enterprise has disabled the login restriction function.
[0085] When the target company enables the login restriction function, members under the target company are subject to the target company's login restrictions (restricting members of the target company from logging into the desktop office application as members of other companies). When the target company disables the login restriction function, members under the target company are not subject to the target company's login restrictions.
[0086] In some embodiments, the on / off state of login restrictions on office applications of a target enterprise is associated with the enterprise identifier of the target enterprise; the flag bit includes the enterprise identifier of the target enterprise, and the on / off state of login restrictions on office applications of the target enterprise can be found based on the enterprise identifier; for example, the enterprise identifier of the target enterprise is corid(B). If the on / off state of the login restriction associated with corid(B) is on, then the on / off state of the login restriction on office applications of the target enterprise is on; if the on / off state of the login restriction associated with corid(B) is off, then the on / off state of the login restriction on office applications of the target enterprise is off.
[0087] The logging-in enterprise is the enterprise corresponding to the request to log in to the office application; the login identity is the identity of the target object under the logging-in enterprise; for example, if the target object logs in to the office application on the desktop as a member under enterprise A, then enterprise A is the logging-in enterprise, and the identity of the target object under enterprise A is the login identity.
[0088] Specifically, if the login restriction settings of the target company on the office application are in the open state, it means that the members (including the target object) under the target company are subject to the login restrictions of the target company, and the list of the target company is obtained; if the login restriction settings are in the closed state, it means that the target object is not subject to the login restrictions of the target company, and then the target object logs in to the office application on the desktop based on the login identity of the target object.
[0089] For example, the target object logs into the desktop office application using its identity under company A. That is, company A is the logging-in company, and the target object's identity under company A is the login identity. Assume that the target object's login identity under the logging-in company is v1. Obtain the on / off status of the login restrictions of the target company (company B) in the office application. If the login restrictions are on, obtain the list of company B. If the login restrictions are off, the target object logs into the desktop office application with v1.
[0090] In the above embodiments, when the login restrictions of the target enterprise on the office application are turned off, the target object is not subject to the login restrictions of the target enterprise, and the target object logs into the application on the desktop with a login identity. When the login restrictions of the target enterprise on the office application are turned on, the target object is subject to the login restrictions of the target enterprise and obtains the list of the target enterprise. Thus, when the login restrictions of the target enterprise are turned on, the members under the target enterprise are subject to the login restrictions of the target enterprise. The target enterprise can set the on / off state of the login restrictions according to its own needs, ensuring the flexibility of the login restrictions of the target enterprise on the office application.
[0091] In some embodiments, the login result of the office application is controlled based on the target identity and the list set, including: obtaining the existence status of the target identity and the enterprise identity respectively; the enterprise identity is the identity of the target enterprise; when each existence status meets the preset status conditions, the login result of the office application is controlled according to the target identity and the list set.
[0092] The existence status of the target identity identifier reflects the usage status of the target object's membership identity under the target enterprise; the existence status of the enterprise identifier reflects the operational status of the target enterprise. For example, the existence status of the target identity identifier includes any one of the following: normal status, resigned status, inactive status, or disabled status; the existence status of the enterprise identifier includes any one of the following: normal status, dissolved status, or disabled status. The above-mentioned existence status of the target identity identifier and the enterprise identifier are merely examples. In practical applications, the existence status of the target identity identifier and the enterprise identifier may also include other statuses. This application embodiment does not limit the existence status of the target identity identifier and the enterprise identifier.
[0093] Specifically, each existing status meets the preset status conditions, which can be that each existing status is in a normal state; the existing status of the target identity is in a normal state, which means that the target object can use its member identity under the target enterprise normally. For example, the target object can log in to the office application using its member identity under the target enterprise and handle work affairs through the office application; the existing status of the enterprise identity is in a normal state, which means that the target enterprise has not been dissolved and can operate normally.
[0094] The existence status of the target identity is associated with the target identity itself, and the existence status of the enterprise identity is associated with the enterprise identity. The existence status of the target identity is obtained by searching for its associated existence status, and the existence status of the enterprise identity is obtained by searching for its associated existence status. When both the target identity and the enterprise identity are in a normal state, the login results for the office application are controlled based on the target identity and the list set.
[0095] For example, the enterprise identifier of the target enterprise is corid(B), and the target identity identifier of the target object under the target enterprise is v2. The existence status of v2 and the existence status of corid(B) are obtained. If the existence status of v2 and corid(B) are both normal, the login result of the office application is controlled according to the list set of v2 and the target enterprise.
[0096] In the above embodiments, the existence status of the target identity and the enterprise identity is used to determine whether the target object is subject to login restrictions of the target enterprise. When the existence status of both the target identity and the enterprise identity is normal, it is determined that the target object is subject to login restrictions of the target enterprise. Then, the login result of the office application is controlled according to the target identity and the list set, so that the login control method is applicable to application scenarios where the target identity and the enterprise identity are in different existence statuses.
[0097] In some embodiments, the login control method further includes: when at least one of the persistence status of the target identity or the persistence status of the enterprise identity does not meet a preset status condition, logging into the office application based on the login identity of the target object; wherein, the login identity is an identity under another enterprise used when requesting to log into the office application.
[0098] Specifically, if at least one of the existence status of the target identity or the existence status of the enterprise identity does not meet the preset status conditions, it means that at least one of the following conditions is met: the existence status of the target identity is not in a normal state, or the existence status of the enterprise identity is not in a normal state.
[0099] For example, at least one of the existence status of the target identity or the existence status of the enterprise identity does not meet the preset status conditions, including but not limited to the following situations: Situation 1: The existence status of the target identity is in the resigned state, and the existence status of the enterprise identity is in the normal state; Situation 2: The existence status of the target identity is in the inactive state, and the existence status of the enterprise identity is in the normal state; Situation 3: The existence status of the target identity is in the normal state, and the existence status of the enterprise identity is in the dissolved state.
[0100] When at least one of the following conditions is met: the existence status of the target identity identifier is not in a normal state, or the existence status of the enterprise identifier is not in a normal state, the target object is not subject to the login restrictions of the target enterprise, and can then log in to the office application on the desktop based on the login identity identifier of the target object.
[0101] For example, the target identity is in a "left-employment" state, while the enterprise identity is in a "normal" state. In other words, if the target has left the target enterprise, the target is not subject to the target enterprise's login restrictions, and thus the target can use the login identity to log in to the desktop office application.
[0102] For example, the target identity is in a normal state, while the enterprise identity is in a dissolved state. In other words, if the target enterprise has been dissolved and cannot operate normally, the target object is not subject to the login restrictions of the target enterprise, and thus the target object can log in to the office application on the desktop using the login identity.
[0103] In the above embodiments, the existence status of the target identity and the enterprise identity determines whether the target object is subject to login restrictions of the target enterprise. When at least one of the existence status of the target identity or the enterprise identity is not in a normal state, the target object is not subject to login restrictions of the target enterprise. Thus, the target object can use the login identity to log in to the office application on the desktop, avoiding the situation where the target object is restricted from logging into the office application on the desktop when all existence statuses do not meet the preset status conditions. This makes the login control method applicable to application scenarios where the target identity and the enterprise identity are in different existence statuses.
[0104] In some embodiments, when all existing states meet preset state conditions, the login result of the office application is controlled based on the target identity identifier and the list set, including: when all existing states meet preset state conditions, querying the target object's target job identifier under the target enterprise based on the target identity identifier; when the list set includes at least one of the target identity identifier or the target job identifier, logging into the office application based on the target object's login identity identifier; the login identity identifier is an identity identifier under another enterprise used when requesting to log into the office application. When the list set does not include the target identity identifier and the target job identifier, logging into the office application is prohibited.
[0105] The target job identifier reflects the target object's position within the target company. The list includes at least one job identifier within the target company, or at least one identity identifier within the target company, or at least one job identifier and at least one identity identifier within the target company. Objects corresponding to job identifiers or identity identifiers within the list are not subject to login restrictions imposed by the target company.
[0106] Specifically, if the list includes at least one of the target job identifier or the target identity identifier, it means that the target is not subject to the login restrictions of the target company and can log in to the office application on the desktop based on the target's login identity identifier.
[0107] If the list does not include the target job identifier and the target identity identifier, it means that the target is subject to login restrictions imposed by the target company, and is therefore prohibited from logging into office applications. Prohibiting login into office applications means prohibiting login into office applications based on the target's login identity identifier.
[0108] In some embodiments, the target job identifier includes a target department identifier or a target job level identifier. The target department identifier is used to indicate the department in which the target person works within the target company, and the target job level identifier is used to indicate the job level of the target person within the target company.
[0109] For example, the target department identifier (department id, departure) of the target object is departure1, which indicates that the target object works in the department of external experts in the target company; the target job level identifier is tagid1, which indicates that the target object's job level in the target company is a senior position.
[0110] In one possible scenario, if the target company allows members of its external expert departments to access the platform without login restrictions, then the department identifier `departid1` of the external expert department is added to the target company's list. The target job identifier of the target individual is obtained, which includes the target department identifier. Assuming the target department identifier is `departid1`, and the target company's list includes `departid1`, the target individual is not subject to the target company's login restrictions. Therefore, the target individual can log in to the desktop office application using their login identity. For example, if the target individual is an external expert for multiple companies (including the target company and the logging-in company), and their target department identifier within the target company is `departid1`, and the target company's list includes `departid1`, then the target individual can log in to the desktop office application using their login identity.
[0111] In one possible scenario, if a target company allows members with senior positions to be exempt from login restrictions, then the senior position's job level identifier (tagid1) is added to the target company's list. The target object's target job identifier is obtained, which includes the target job level identifier. Assuming the target job level identifier is tagid1, and the target company's list includes tagid1, then the target object is not subject to the target company's login restrictions. Therefore, the target object can log in to the desktop office application using their login identity. For example, if the target object is a senior partner in the target company, and the target object's target job level identifier within the target company is tagid1, and the target company's list includes tagid1, then the target object can log in to the desktop office application using their login identity.
[0112] The above scenarios are merely examples. In practical applications, the list set can be set according to the actual needs of the target company. For example, in some possible scenarios, the target company's list set may include the department identifier of the sales department. This application does not limit the target department identifier or target job level identifier included in the list set.
[0113] In the above embodiments, when both the target identity identifier and the enterprise identifier are in a normal state, it is then determined whether the target object is subject to the login restrictions of the target enterprise based on the list set, the target identity identifier, and the target job identifier. If the list set includes at least one of the target identity identifier or the target job identifier, the target object is not subject to the login restrictions of the target enterprise. If the list set does not include the target identity identifier and the target job identifier, the target object is subject to the login restrictions of the target enterprise. The target enterprise can use the list set to differentiate the login restrictions for each member under the target enterprise, so that some members are not subject to the login restrictions of the target enterprise, avoiding the impact of uniform settings on some members' work affairs, making the login restrictions of the target enterprise more flexible, while also ensuring that other members are subject to the login restrictions of the target enterprise, thus protecting the data security of the target enterprise.
[0114] In some embodiments, when the list does not include the target identity and the target job title, logging into the office application is prohibited, including: when the list does not include the target identity and the target job title, obtaining the on / off state of the recording switch of the target enterprise on the office application; if the recording switch is off, logging into the office application is prohibited; the login control method further includes: if the recording switch is on, logging into the office application based on the login identity of the target object.
[0115] The recording switch is used to enable or disable the login recording function of the target enterprise. If the recording switch is in the off state, the target enterprise has disabled the login recording function. If the recording switch is in the on state, the target enterprise has enabled the login recording function.
[0116] When a target company disables login logging, it will restrict its members (including the target individual) from logging into desktop office applications using identities from other companies, without recording such login activity. When a target company enables login logging, it will not restrict its members from logging into desktop office applications using identities from other companies, but will record such login activity.
[0117] Specifically, when the list does not include the target identity and target job title, if the recording switch is off, login to the office application is prohibited and the login behavior is not recorded; if the recording switch is on, login to the office application is based on the target's login identity and the login behavior is recorded. The server records the login behavior and generates a log report, which the target company can query.
[0118] In the above embodiments, the target enterprise can choose to restrict its members from logging into the desktop office application using identity identifiers under other enterprises by modifying the on / off state of the recording switch, or not restrict it and only record the login behavior. This provides the target enterprise with a more flexible login restriction method that can be applied to a variety of application scenarios.
[0119] In some embodiments, in response to a login request for an office application on a desktop, obtaining the object identifier of the target object includes: in response to a login request for an office application on a desktop, obtaining the open / closed state of a fault switch; if the open / closed state of the fault switch is closed, then obtaining the object identifier of the target object; the login control method further includes: if the open / closed state of the fault switch is open, then logging into the office application based on the login identity identifier of the target object.
[0120] The fault switch is used to enable or disable the login restriction function of the office application. When the fault switch is in the off state, the login restriction function of the office application is enabled, and when the fault switch is in the on state, the login restriction function of the office application is disabled.
[0121] Specifically, the server obtains the number of complaints regarding the login restriction function of the office application within a preset statistical period. If the number of complaints within the preset statistical period is within a preset range, it indicates that the error rate of the login restriction function of the office application is high. In this case, the server sets the fault switch to the on state, that is, disables the login restriction function of the office application, so that all objects are not subject to login restrictions, and the target objects can log in to the office application on the desktop using their login identity. If the number of complaints within the preset statistical period is not within the preset range, it indicates that the error rate of the login restriction function of the office application is low. In this case, the server sets the fault switch to the off state, that is, enables the login restriction function of the office application, and the target objects are subject to the login restrictions of the target enterprise represented by its flag bit. The preset statistical period and preset range can be set according to actual needs. This application embodiment does not limit the specific values of the preset statistical period and preset range.
[0122] In the above embodiments, a fault switch is set for the login restriction function. When the error rate of the login restriction function is high, all objects are not subject to login restrictions. As a result, the target objects can log in to the office application on the desktop, avoiding the situation where the target objects cannot log in to the office application on the desktop due to the high error rate of the login restriction function, thus ensuring the normal operation of the office application on the desktop.
[0123] In some embodiments, when the object identifier is not configured with a flag bit, or when the flag bit configured with the object identifier matches the login enterprise identifier, the office application is logged in based on the login identity identifier of the target object; wherein, the login identity identifier is an identity identifier under another enterprise used when requesting to log in to the office application.
[0124] Specifically, if an object identifier has no configured flags, it can mean that the corresponding flags are empty, meaning the flags for the object identifier do not include the company identifier. If no flags are configured for an object identifier, it indicates that the target object does not have a corresponding company, and the target object is not subject to any company's login restrictions; it can log in to the desktop office application using its login identity. It should be noted that if an object identifier has no configured flags, and the target object has multiple identities under multiple companies, then the target object can log in to the desktop office application using any of its identities.
[0125] The fact that the flags configured for the object identifier match the logged-in enterprise identifier means that the logged-in enterprise is the target enterprise. If the flags include one enterprise identifier, the flags matching the logged-in enterprise identifier can mean that the enterprise identifier included in the flags is the same as the logged-in enterprise identifier. If the flags include at least two enterprise identifiers, the flags matching the logged-in enterprise identifier can mean that the flags include enterprise identifiers that are the same as the logged-in enterprise identifier.
[0126] The flag represents the target enterprise, restricting the target object from logging into the desktop office application as a member of another enterprise. If the logging enterprise is the target enterprise, that is, the target object logs into the desktop office application using the target identity, this login request is not restricted by the target enterprise.
[0127] In the above embodiments, if the flag bit configured in the object identifier configuration is empty, the target object is not subject to any enterprise login restrictions, allowing the target object to log in to the desktop office application using the login identity identifier without affecting the target object's ability to handle work affairs through the desktop office application; if the target object logs in to the desktop office application using the target identity identifier, the target object is not subject to the login restrictions of the target enterprise, allowing members under the target enterprise to handle work affairs through the desktop office application without affecting the target object's ability to handle work affairs through the desktop office application, and without causing leakage of the target enterprise's internal data.
[0128] In some embodiments, after blocking login to the office application, the method further includes: if the login request is a request to log in to the office application sent by the mobile terminal when scanning a QR code to log in, then sending a first prompt message to the mobile terminal to instruct the mobile terminal to display the first prompt message on the login operation page; if the login request is an account switching request for the office application sent by the desktop terminal, then sending a second prompt message to the desktop terminal to instruct the desktop terminal to display the second prompt message on the login prompt page.
[0129] QR code login is a method of logging into an office application on a desktop by scanning a login graphic code on the desktop using a mobile device. The target user has already logged into the office application on the mobile device with their logged-in identity. The office application on the desktop displays the login graphic code. By scanning this login graphic code using the mobile device, the target user can then log into the office application on the desktop with their logged-in identity.
[0130] The login page can be the page displayed after scanning the login graphic code on a mobile office application. In response to the triggering operation on this login page, the mobile application sends a login request to the server.
[0131] An account switch request is a request sent from the desktop application to the server when an account switch operation is performed. This account switch request is treated as a login request. The target user has already logged into the desktop application with a different identity (not the login identity, but the target identity). The target user selects the company to log in to via the account switch operation, switching to the login identity used to log into the desktop application. In response to this account switch operation, the desktop application sends a login request (account switch request) to the server.
[0132] Both the first and second prompt messages indicate that the user is unable to log in to the desktop office application based on their login identity.
[0133] Specifically, if the login request is sent from a mobile device, the server sends a first prompt message to the mobile device. After receiving the first prompt message, the mobile device displays the first prompt message on the login page. If the login request is sent from a desktop device, the server sends a second prompt message to the desktop device. After receiving the second prompt message, the desktop device displays a login prompt page through the office application, where the second prompt message is displayed.
[0134] For example, such as Figure 3As shown, launching the office application on the desktop displays a QR code login page y3. This page includes a login graphic code y31 and initial login information y32. The initial login information y32 prompts the target user to scan the login graphic code y31 using a mobile device. The target user has already logged into the office application on the mobile device with their logged-in identity. The mobile office application scans the login graphic code y31 on the QR code login page y3, displaying the login operation page. Figure 4 As shown, the login operation page y4 includes a login control y41. In response to the triggering of the login control y41, the mobile terminal sends a login request to the server. In practical applications, the login operation page y4 may also include second login information y42, which is used to prompt the target object. This login behavior is used to log in to the office application on the desktop. The login operation page y4 may also include a cancel login control y43. In response to the triggering of the cancel login control y43, the login behavior ends.
[0135] After blocking access to office applications, the server sends an initial notification message to the mobile device, such as... Figure 5 As shown, the mobile device displays the first prompt message y44 on the login operation page y4. For example, the first prompt message y44 is: "Because the target company has enabled login restrictions, the current company cannot log in through the desktop terminal."
[0136] For example, the target user has already logged into the desktop office application with a different identity, such as... Figure 6 As shown, the settings page y6 of the office application includes an account switching control y61. In response to the triggering of the account switching control y61, multiple enterprise controls (not shown in the figure) are displayed on the settings page y6. These enterprise controls include the control corresponding to the logged-in enterprise. In response to the triggering of the control corresponding to the logged-in enterprise, the desktop client sends a login request (account switching request) to the server. After blocking login to the office application, the server sends a second prompt message to the desktop client. The desktop client displays a login prompt page y62 on the settings page y6, and displays the second prompt message y63 on the login prompt page y62. The second prompt message includes: "Due to the target enterprise enabling restricted login, the current enterprise cannot log in via the desktop client." In practical applications, since the login prompt page y62 is displayed after blocking login to the office application, the login prompt page y62 can also include a login failure prompt message y64.
[0137] In some embodiments, the login request may be initiated by the desktop office application when the target object triggers the login control of the desktop office application. For example, if the target object previously logged into the desktop office application with a login identity and then logged out, the next time the target object logs into the desktop office application, it can trigger the login control of the desktop office application, which in turn sends a login request to the server. This login request enables the target object to log into the desktop office application with the login identity. After blocking login to the office application, the server sends a second prompt message to the desktop.
[0138] In the above embodiments, after blocking login to the office application, if the login request is sent when logging in via mobile QR code, the server sends a first prompt message to the mobile device and displays the first prompt message on the login operation page of the mobile device; if the login request is sent when switching accounts on the desktop, the server sends a second prompt message to the desktop device and displays the second prompt message on the login prompt page of the desktop device; after blocking login to the office application, that is, after the target object is restricted from logging in by the target enterprise, the target object can learn about the reason for blocking login to the office application through the login operation page on the mobile device or the login prompt page on the desktop device.
[0139] In some embodiments, after logging into the office application based on the login identity of the target object, the method further includes: when the duration of logging into the office application based on the login identity reaches a preset duration, obtaining the flag bit of the object identifier; when the flag bit of the object identifier does not match the login enterprise identifier and the login restriction of the office application is in the on / off state, re-obtaining the list of target enterprises represented by the flag bit of the object identifier; re-querying the target identity identifier and target job identifier of the target object under the target enterprise represented by the flag bit of the object identifier; if the re-obtained list does not include the re-queried target identity identifier and re-queried target job identifier, then logging out of the office application on the desktop.
[0140] Specifically, when the target user logs into the office application on the desktop with a login identity for a preset period of time, the target user logs into the office application on the desktop again with the same login identity. For ease of explanation, the target user's initial login to the office application on the desktop is referred to as the first login, and the subsequent login is referred to as the continued login. The preset period of time separates the first login and the continued login. It should be noted that the first login is only the first login relative to the continued login, and does not refer to the target user's first login on the desktop since using the office application, or any other kind of first login. The preset period of time can be set according to actual needs. For example, the preset period of time is set to 2 hours. This application embodiment does not limit the preset period of time.
[0141] When re-login, the server re-acquires the flag of the object identifier. The enterprise identifier included in the flag obtained during the re-login may be the same as or different from the enterprise identifier included in the flag obtained during the first login.
[0142] If the enterprise identifier included in the flag obtained during the continued login does not match the login enterprise identifier, and the login restriction item of the target enterprise corresponding to that enterprise identifier is in the open state in the office application, then obtain the list of target enterprises corresponding to that enterprise identifier.
[0143] It should be noted that if the enterprise identifier included in the flags obtained during the continued login is different from the enterprise identifier included in the flags obtained during the first login, then the target enterprise corresponding to the enterprise identifier during the continued login will also be different from the target enterprise corresponding to the enterprise identifier during the first login, and consequently the list set re-obtained during the continued login will also be different from the list set obtained during the first login.
[0144] If the enterprise identifier included in the flags obtained during the continued login is the same as the enterprise identifier included in the flags obtained during the initial login, then the target enterprise corresponding to the enterprise identifier during the continued login will be the same as the target enterprise corresponding to the enterprise identifier during the initial login. However, the list of target enterprises may change within the preset time period, so the list re-obtained during the continued login may also be different from the list obtained during the initial login. If the list of target enterprises does not change within the preset time period, then the list re-obtained during the continued login will be the same as the list obtained during the initial login.
[0145] During the login renewal process, the system re-queries the target's identity identifier and target job identifier under the target company at the time of the login renewal. If the target company at the time of login renewal is the same as the target company at the time of the initial login, the target identity identifier queried during the login renewal process will be the same as the target identity identifier at the time of the initial login. The target job identifier queried during the login renewal process may be the same as or different from the target job identifier queried during the initial login process.
[0146] If the target company when resuming login is different from the target company when logging in for the first time, the target identity identifier queried again when resuming login will be different from the target identity identifier when logging in for the first time, and the target job identifier queried again when resuming login will be different from the target job identifier queried when logging in for the first time.
[0147] If the re-obtained list does not include the target identity and the target job title that were queried again, it means that the target is subject to login restrictions imposed by the target company when continuing login. That is, the target company restricts the target from logging into the desktop office application with the login identity under other companies (including the login company), and thus logs out of the desktop office application.
[0148] For example, the target object's object identifier is G1. Upon first login, the target object logs into the desktop office application using its login identity v1 under the logged-in enterprise (Enterprise A). Upon first login, the target object's login into the desktop office application based on login identity v1 includes, but is not limited to, the following:
[0149] Case 1: When logging in for the first time, if the target object's object identifier G1 is not configured with a flag, or if the target object's flag includes the corporate identifier corid(A), then the desktop office application will be logged in based on the login identity v1.
[0150] Case 2: Upon first login, the flags configured in the object identifier G1 of the target object include the enterprise identifier corid(B). Thus, enterprise B is the target enterprise for the first login. The login restriction items of enterprise B in the office application are in the closed state. Therefore, the office application on the desktop is logged in based on the login identity v1.
[0151] Scenario 3: Upon first login, if Company B is the target company and the login restrictions on the office application are enabled, obtain the list set D1 of Company B, and query the target identity v2 and target job ID z2 of the target object under Company B. If D1 includes v2 or z2, then log in to the office application on the desktop based on the login identity v1.
[0152] When resuming login, logging out of desktop office applications includes, but is not limited to, the following situations:
[0153] Scenario 4: During login continuation, the target object's object identifier G1 is configured with a flag bit, which includes the enterprise identifier corid(B). Enterprise B is the target enterprise during login continuation. The login restriction settings of Enterprise B in the office application are in the on / off state. The target object's list of names in Enterprise B, D2 (different from the list of names obtained in Scenario 3), is retrieved again. The target identity identifier v2 and the target job identifier z2 under Enterprise B are queried again. D2 does not include v2 and z2. The target object is subject to the login restrictions of Enterprise B and logs out of the office application on the desktop.
[0154] Case 5: During login continuation, the target object's object identifier G1 is configured with a flag bit, which includes the enterprise identifier corid(C). Enterprise C is the target enterprise during login continuation (different from the target enterprise in Case 3). The login restriction settings of Enterprise C in the office application are in the on / off state. The target object's list set D3 in Enterprise C is retrieved again. The target identity identifier v3 and the target job identifier z3 under Enterprise C are queried again. D3 does not include v3 and z3. The target object is subject to the login restrictions of Enterprise C and logs out of the office application on the desktop.
[0155] In some embodiments, when the duration of logging into the office application based on the login identity reaches a preset duration, after obtaining the flag bit of the object identifier, the process further includes: if the flag bit configured for the object identifier is empty, or if the enterprise identifier configured for the object identifier matches the login enterprise identifier, then the user does not log out of the office application on the desktop; or, if the enterprise identifier configured for the object identifier does not match the login enterprise identifier, and the login restriction settings of the office application are in the off state, then the user does not log out of the office application on the desktop; or, if the flag bit of the object identifier does not match the login enterprise identifier, and the login restriction settings of the office application are in the on state, then the user re-obtains the list of target enterprises represented by the flag bit of the object identifier; re-queries the target identity identifier and target job identifier of the target object under the target enterprise represented by the flag bit of the object identifier; if the re-obtained list includes the re-queried target identity identifier and the re-queried target job identifier, then the user does not log out of the office application on the desktop.
[0156] In some embodiments, re-acquiring the list of target enterprises represented by the flag bit of the object identifier further includes: acquiring the re-queried target identity identifier and the existence status of the enterprise identifiers included in the flag bit of the object identifier; if the existence status of the re-queried target identity identifier and the existence status of the enterprise identifiers included in the flag bit of the object identifier both meet preset status conditions, then re-acquiring the list of target enterprises represented by the flag bit of the object identifier. The login control method further includes: if at least one of the existence status of the re-queried target identity identifier or the existence status of the enterprise identifiers included in the flag bit of the object identifier does not meet preset status conditions, then not logging out of the office application on the login desktop.
[0157] Specifically, if the status of the re-queried identity identifier is normal, and the status of the enterprise identifier included in the flag of the object identifier is normal, the list of target enterprises represented by the flag of the object identifier is obtained. If at least one of the status of the re-queried target identity identifier or the status of the re-queried target job identifier does not meet the preset status conditions, the target object is not subject to the login restrictions of the target enterprise represented by the flag of the object identifier, and thus does not log out of the office application on the desktop.
[0158] In the above embodiments, when the target object logs into the office application on the desktop with its login identity for a preset period of time, login verification is performed again. Within this preset period of time, the target enterprise corresponding to the target object, the on / off status of the login restrictions on the office application of the target enterprise, the list of the target enterprise, the target job identifier of the target object under the target enterprise, the existence status of the identity identifier of the target object under the target enterprise, and the existence status of the enterprise identifier of the target enterprise may all change, thereby affecting the login result of the target object's continued login. For the target enterprise, if the target enterprise modifies the relevant content of the login restriction at some point, such as modifying the on / off status of the login restrictions on the office application of the target enterprise, or modifying the list of the target enterprise, the login restriction can be imposed on the already logged-in target object through continued login, thus ensuring the security of the target enterprise's internal data.
[0159] In some embodiments, when the duration of logging into the office application based on the login identity reaches a preset duration, the flag bit of the object identity is obtained, including: obtaining the flag bit of the object identity at preset intervals.
[0160] Specifically, after logging into the office application based on the login identity of the target object, a renewed login is performed at preset intervals. This allows for timely restriction of logins on the target object when changes occur in the target enterprise corresponding to the target object, the on / off status of login restrictions on the target enterprise in the office application, the list of target enterprises, the target position identifier of the target object under the target enterprise, the existence status of the target object's identity identifier under the target enterprise, and the existence status of the enterprise identifier of the target enterprise. This improves the security of the internal data of the target enterprise.
[0161] In some embodiments, the login control method further includes: responding to a request to adjust login restrictions for an office application, updating the status of login restrictions for the office application to obtain the open / closed status of the login restrictions; obtaining an object identifier set; the object identifier set includes object identifiers of each object in the target enterprise; when the open / closed status is open and the flag bits configured for the object identifiers in the object identifier set are empty, adding the enterprise identifier of the target enterprise to the flag bits corresponding to each object identifier in the object identifier set; when the open / closed status is closed and the flag bits configured for the object identifiers in the object identifier set are not empty, removing the enterprise identifier from the flag bits corresponding to each object identifier in the object identifier set.
[0162] The login restrictions for office applications refer to the login restrictions imposed on the target company's office applications. Each object within the target company refers to a member of the target company, and each object's identifier is a unique identifier. The target object is included among the objects within the target company.
[0163] Specifically, the desktop client sends a login restriction adjustment request to the server. The server receives the request, obtains the enterprise identifier and status identifier carried in the request, determines the target enterprise corresponding to the enterprise identifier, and modifies the on / off state of the target enterprise's login restrictions in the office application to the state corresponding to the status identifier. For example, if the status identifier carried in the login restriction adjustment request is a first status identifier, the on / off state of the target enterprise's login restrictions in the office application is modified to an on state; if the status identifier carried in the login restriction adjustment request is a second status identifier, the on / off state of the target enterprise's login restrictions in the office application is modified to a off state.
[0164] The target company's enterprise identifier is associated with a status identifier (used to reflect the on / off state of login restrictions). For example, if the status identifier carried in the login restriction adjustment request is a first status identifier, then the status identifier associated with the enterprise identifier is set to the first status identifier, thereby changing the on / off state of the target company's login restrictions in office applications to the on state; if the status identifier carried in the login restriction adjustment request is a second status identifier, then the status identifier associated with the enterprise identifier is set to the second status identifier, thereby changing the on / off state of the target company's login restrictions in office applications to the off state. In practical applications, the first status identifier can be represented as ON, and the second status identifier can be represented as OFF.
[0165] After the server modifies the open / closed state of the login restriction based on the login restriction adjustment request, it returns the modified data to the desktop. After receiving the modified data, the desktop initiates an asynchronous task corresponding to the login restriction adjustment request to the server. When the server processes the asynchronous task, it obtains the open / closed state of the login restriction based on the enterprise identifier of the target enterprise, as well as the flag bit configured in the object identifier set.
[0166] It should be noted that in this embodiment, the flag bit of the object identifier configuration obtained by the server is the flag bit of the object identifier under the target enterprise. That is to say, if the flag bit is empty, it means that the flag bit does not include the enterprise identifier of the target enterprise, but does not mean that the flag bit does not include the identifier of any enterprise.
[0167] If the login restriction is enabled, the server iterates through the object identifiers in the object identifier set. For each object identifier, if the configured flag is empty, it means that the flag does not include the target company's identifier, and the server adds the target company's identifier to the object identifier's flag. If the configured flag is not empty, it means that the flag includes the target company's identifier, and the server does not process the object identifier's flag. When the login restriction is enabled, the flags configured for each object identifier in the object identifier set include the company identifier, and therefore, all objects under the target company are subject to the target company's login restrictions.
[0168] If the login restriction is in the off state, the server iterates through each object identifier in the object identifier set. For each object identifier, if the flag configured for that object identifier is not empty, the server removes the enterprise identifier from the flag list; if the flag configured for that object identifier is empty, the server does not process the flag for that object identifier. When the login restriction is in the off state, the flags configured for each object identifier in the object identifier set do not include the enterprise identifier, and therefore, objects under the target enterprise are not subject to the login restrictions of the target enterprise.
[0169] It's important to note that after the desktop client initiates an asynchronous task corresponding to the login restriction adjustment request to the server, the desktop client can perform other operations without waiting for the result of this asynchronous task. After receiving the asynchronous task, the server can process it at a preset time, such as 12:00 noon daily. The server will process the asynchronous task corresponding to the login restriction adjustment request at 12:00 noon each day. Because the server processes the flags of each member under the target company while processing the asynchronous task corresponding to the login restriction adjustment request, rather than synchronously modifying the flags of each member under the target company when changing the closed state of the login restrictions, there may be situations where the flags of the target object include the target company's enterprise identifier, but the target company's login restriction status is closed.
[0170] In the above embodiment, the server receives a login restriction adjustment request, modifies the on / off state of the login restrictions of the target enterprise in the office application according to the login restriction adjustment request, and adds or deletes the enterprise identifier in the flag bit configured in the object identifier set based on the on / off state of the login restrictions. This makes all members under the target enterprise subject to the login restrictions of the target enterprise, or none of them subject to the login restrictions of the target enterprise. In this way, when the on / off state of the login restrictions of the target enterprise in the office application is modified, it is not necessary to manually modify the flag bits of each member under the target enterprise. The server can uniformly modify the flag bits of each member under the target enterprise, which improves efficiency.
[0171] In some embodiments, in response to a request to adjust login restrictions for an office application, updating the status of login restrictions for the office application includes: receiving a request from a desktop client to adjust login restrictions for the office application; the login restriction adjustment request is a request to adjust the status of login restrictions triggered on the security management page of the office application; the security management page includes login restrictions and other security management items; and updating the status of login restrictions in response to the login restriction adjustment request.
[0172] The security management page includes login restriction controls for login restrictions and security management controls for other security management items. The display style of the login restriction controls reflects the on / off state of the login restriction. For example, if the display style of the login restriction control is that the checkbox of the login restriction control includes a check icon, it indicates that the login restriction is in the on / off state; if the display style of the login restriction control is that the checkbox of the login restriction control does not include a check icon, it indicates that the login restriction is in the off state.
[0173] like Figure 7As shown, desktop login settings can be configured on the security management page y7. The security management page y7 includes a login restriction control y71, which contains a checkbox. When the login restriction is enabled, the checkbox includes a selected icon; when it is disabled, the checkbox does not include the selected icon. Figure 7 The login restriction item shown is in the "on" state, and the selected icon of the login restriction control y71 is "√". The security management page y7 also includes description information y72 for the login restriction item. The description information y72 describes the effect of the login restriction item being in the "on" state, for example... Figure 7 The description information y72 includes: "When enabled, members using desktop devices can only log in to their own company and cannot log in to or switch to other companies. Mobile devices are not affected."
[0174] The above-described display style of the login restriction control is only an example. In practical applications, the display style of the login restriction control can be other styles, such as using different colors to indicate the on / off state of login restriction items. This application does not limit the display style of the login restriction control.
[0175] Specifically, management members of the target enterprise can log in to the desktop office application as administrators. After logging in, they can access the application's security management page. The desktop application, in response to the login restriction controls on the security management page being triggered, sends a login restriction adjustment request to the server. The server then updates the status of the login restrictions in response to the request.
[0176] When the login restriction item in the security management page is in the "on" state, the flags corresponding to each object under the target enterprise include the enterprise identifier, and thus each object under the target enterprise is subject to the login restrictions of the target enterprise. When the login restriction item in the security management page is in the "off" state, the flags corresponding to each object under the target enterprise do not include the enterprise identifier, and thus each object under the target enterprise is not subject to the login restrictions of the target enterprise.
[0177] In some embodiments, after the server updates the status of the login restriction item, it sends the return data corresponding to the login restriction item adjustment request to the desktop client. This return data is used by the desktop client to update the display style of the login restriction control in the security management page.
[0178] For example, before the login restriction control in the security management page is triggered, the login restriction item is in the closed state, and the checkbox of the login restriction control does not include the selected icon. After the login restriction control is triggered, the server updates the open / closed state of the login restriction item to the open state, and the server sends the first return data to the desktop client so that the desktop client updates the display style of the login restriction control according to the first return data, so that the checkbox of the login restriction control includes the selected icon.
[0179] For example, before the login restriction control in the security management page is triggered, the login restriction item is in the on state, and the checkbox of the login restriction control includes the selected icon. After the login restriction control is triggered, the server updates the on state of the login restriction item to the off state, and the server sends second return data to the desktop client so that the desktop client updates the display style of the login restriction control according to the second return data, so that the checkbox of the login restriction control does not include the selected icon.
[0180] In the above embodiments, the target company's management members can modify the on / off status of login restrictions on the office application through the security management page. They can uniformly modify the flags of all objects under the target company, ensuring that all objects are subject to the target company's login restrictions, or that none are subject to them. Furthermore, the security management page allows the target company's management members to more intuitively determine the on / off status of login restrictions.
[0181] In some embodiments, the login control method further includes: receiving an activation task request; the activation task request is an asynchronous task request initiated after a new member object is added to the target enterprise; in response to the activation task request, obtaining the on / off status of the login restriction items of the office application; when the on / off status is on and the flag bit under the object identifier of the member object is empty, adding the enterprise identifier of the target enterprise to the flag bit under the object identifier of the member object.
[0182] Specifically, when an object is added as a member of the target enterprise, that object becomes a newly added member object of the target enterprise. The activation task request can be initiated by the mobile device. For example, an object registers for an office application on a mobile device using its email address. After successful registration, it applies to become a member of the target enterprise. Once the application is approved, the object becomes a newly added member object of the target enterprise, and the mobile device sends an activation task request to the server. The activation task request can also be initiated by the server. For example, the server responds to the newly added member object of the target enterprise by initiating an activation task request.
[0183] When the server receives an activation task request, it obtains the on / off status of the login restrictions on the target enterprise's office applications based on the activation task request. If the login restrictions are on, the server obtains the flag bit under the object identifier of the member object. If the flag bit under the object identifier of the member object is empty, it means that the flag bit does not include the enterprise identifier of the target enterprise, so the enterprise identifier is added to the flag bit under the object identifier of the member object.
[0184] In some embodiments, when the open / closed state is open and the flag bit under the object identifier of the member object is not empty, the flag bit under the object identifier of the member object is not modified; when the open / closed state is closed, the flag bit under the object identifier of the member object is not modified.
[0185] It should be noted that, in this embodiment, the flag bit under the object identifier of the member object obtained by the server is the flag bit under the target enterprise of the member object's object identifier. That is to say, if the flag bit is empty, it means that the flag bit does not include the enterprise identifier of the target enterprise, but does not mean that the flag bit does not include the identifier of any enterprise. If the flag bit is not empty, it means that the flag bit includes the enterprise identifier of the target enterprise.
[0186] In practical applications, if the object is applying to become a member of the target object for the first time, the flag bit under the object identifier of the member object will be empty; if the object is not applying to become a member of the target object for the first time, the flag bit under the object identifier of the member object may include the enterprise identifier.
[0187] In the above embodiments, when a new member object is added to the target enterprise, if the login restriction settings of the target enterprise in the office application are enabled, the enterprise identifier of the target enterprise is added to the flag bit of the member object through the activation task request initiated after the new member object is added. This makes the member object subject to the login restriction of the target enterprise. In this way, when the login restriction settings of the target enterprise in the office application are enabled, it is not necessary to set the flag bit separately for the new member object. Compared with setting the flag bit for the new member object manually, this improves efficiency, avoids forgetting to set the flag bit for the new member object, and ensures the security of internal data.
[0188] In one scenario embodiment, the server includes a dynamic component, a user information component, an enterprise object component, and a function switch component; such as Figure 8 As shown, the process of modifying the on / off state of login restrictions on office applications for a target enterprise includes:
[0189] When the login restrictions on the target enterprise's office application are in the off state, the target enterprise's management members log in to the office application on the desktop as administrators, modify the on / off state of the login restrictions on the security management page of the office application, and the desktop sends a login restriction adjustment request to the server. The server's function switch component receives the login restriction adjustment request, and based on the login restriction adjustment request, the function switch component changes the on / off state of the target enterprise's login restrictions on the office application to the on state, and returns the modified data to the desktop after the modification is completed.
[0190] After receiving the modified data, the desktop client initiates an asynchronous task to the server. The server's dynamic component receives the asynchronous task. When the dynamic component processes the asynchronous task, it obtains the on / off status of the login restriction items of the target enterprise in the office application from the function switch component based on the enterprise identifier of the target enterprise. The obtained on / off status of the login restriction items is the on state.
[0191] The dynamic component obtains the object identifier set of the target enterprise from the enterprise object component based on the enterprise identifier of the target enterprise. The object identifier set includes the object identifiers of each object in the target enterprise. For each object identifier in the object identifier set, the dynamic component obtains the flag bit configured for that object identifier from the user information component. If the flag bit configured for that object identifier is empty, the dynamic component sends the enterprise identifier of the target enterprise to the user information component, and the user information component adds the enterprise identifier of the target enterprise to the flag bit configured for that object identifier.
[0192] When the user information component successfully adds the enterprise identifier to the flag configured in the object identifier configuration, the user information component will return a success data to the dynamic component. If the dynamic component does not receive the success data within the preset waiting time, it means that the user information component failed to add the enterprise identifier to the flag configured in the object identifier configuration. Then the dynamic component will add the enterprise identifier to the flag configured in the object identifier configuration again until the dynamic component successfully adds the enterprise identifier to the flag configured in the object identifier configuration.
[0193] In one scenario embodiment, the server includes a login component, a dynamic component, a user information component, and a function switch component; such as Figure 9 As shown, when a target enterprise adds a new member object, the process of modifying the member object's flags includes:
[0194] When an object becomes a newly added member object of the target enterprise, the login component in the server sends an activation task request to the dynamic component. This activation task request is an asynchronous task request. When the dynamic component processes the activation task request, it obtains the on / off status of the login restriction items of the target enterprise in the office application from the function switch component based on the enterprise identifier of the target enterprise. The obtained on / off status of the login restriction items is the on state.
[0195] The dynamic component obtains the flag bit configured by the object identifier of the member object from the user information component. If the flag bit is empty, the dynamic component sends the enterprise identifier of the target enterprise to the user information component, and the user information component adds the enterprise identifier of the target enterprise to the flag bit.
[0196] In one scenario embodiment, the server includes a login component, a user information component, an enterprise object component, a dynamic component, an administrator component, and a list component; such as Figure 10 As shown, the process by which the target user logs into the desktop office application using their login identity under the logged-in enterprise includes:
[0197] The mobile office application scans the login graphic code displayed on the desktop office application, and the mobile application sends a login request to the server.
[0198] The login component in the server receives the login request and obtains the object identifier of the target object and the login enterprise identifier based on the login request.
[0199] The login component obtains the open / closed status of the fault switch. If the fault switch is in the open state, the login restriction process is exited, and the target object logs into the office application on the desktop with the login identity.
[0200] If the fault switch is in the closed state, the login component obtains the flag bit of the target object's object identifier configuration from the user information component based on the object identifier;
[0201] If the flag is empty, the login restriction process will be exited, and the target will log in to the office application on the desktop with the login identity.
[0202] If the flag is not empty, the login component determines whether the enterprise identifier included in the flag matches the login enterprise identifier;
[0203] If a match is found, the login restriction process is exited, and the target user logs into the desktop office application using their login identity.
[0204] If they do not match, the login component will retrieve the on / off status of the login restrictions for the target company in office applications from the list based on the target company's corporate identifier.
[0205] If the login restriction settings of the target enterprise on the office application are in the off state, the login restriction process will be exited and the target will log in to the office application on the desktop with the login identity.
[0206] If the login restrictions of the target enterprise in the office application are enabled, the login component will obtain the target identity of the target object under the target enterprise from the user information component based on the object identifier and the enterprise identifier included in the flag bit.
[0207] The login component obtains the persistence status of the target identity from the dynamic component and the persistence status of the enterprise identity from the administrator component, based on the target identity.
[0208] If at least one of the existence status of the target identity or the existence status of the enterprise identity is not in a normal state, the target object logs in to the office application on the desktop using the login identity.
[0209] If both the existence status of the target identity and the existence status of the enterprise identity are normal, the login component will retrieve the list of the target enterprise from the list component based on the enterprise identity.
[0210] The login component retrieves the target job identifier of the target object within the target enterprise from the enterprise object component based on the object identifier;
[0211] The login component determines whether the list contains the target identity identifier or the target job identifier;
[0212] If the list includes either the target identity identifier or the target job identifier, the login restriction process will be exited, and the target will log in to the desktop office application using the login identity identifier.
[0213] If the list does not include the target identity and target job identifier, the login component retrieves the on / off status of the record switch for the target company.
[0214] If the recorded switch is in the on state, the login restriction process is exited, the target object logs into the office application on the desktop with the login identity, and the login is recorded.
[0215] If the record switch is in the off state, then the target object is prohibited from logging into the office application on the desktop with the login identity, and the first prompt message is sent to the mobile device.
[0216] In one specific embodiment, such as Figure 11 As shown, the login control methods include:
[0217] S1101, In response to a login request for an office application on the desktop, the server obtains the object identifier of the target object; the target object is the user object of the authorized account associated with the office application.
[0218] S1102A, When the object identifier is configured with a flag bit, and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application, the server obtains the open / closed status of the login restriction items of the office application.
[0219] S1102B: When the object identifier is not configured with a flag, or when the flag configured with the object identifier matches the login enterprise identifier, the server logs into the office application based on the login identity identifier of the target object; the login identity identifier is the identity identifier under another enterprise used when requesting to log into the office application.
[0220] S1103A, when the open / closed state is open, the server obtains the list of target companies represented by the flag bit;
[0221] S1103B, when the open / closed state is closed, the server logs into the office application based on the login identity of the target object;
[0222] S1104, the server queries the target identity identifier of the target object under the target enterprise based on the object identifier and the flag bit; obtains the existence status of the target identity identifier and the enterprise identifier respectively; the enterprise identifier is the identifier of the target enterprise;
[0223] S1105A, when all existing states meet the preset state conditions, the server queries the target position identifier of the target object under the target enterprise based on the target identity identifier.
[0224] S1105B, when at least one of the persistence status of the target identity or the persistence status of the enterprise identity does not meet the preset status conditions, the server logs into the office application based on the login identity of the target object.
[0225] S1106A, When the target identity and target job title are not included in the list, the server prohibits login to office applications;
[0226] S1106B, When the list set includes at least one of the target identity identifier or the target job identifier, the server logs into the office application based on the login identity identifier of the target object;
[0227] S1107A, If the login request is a request to log in to an office application sent by the mobile terminal when scanning a QR code, the server sends a first prompt message to the mobile terminal to instruct the mobile terminal to display the first prompt message on the login operation page;
[0228] S1107B, If the login request is an account switching request for office applications sent by the desktop client, the server sends a second prompt message to the desktop client to instruct the desktop client to display the second prompt message on the login prompt page;
[0229] S1108, When the duration of logging into the office application based on the login identity reaches the preset duration, the server obtains the flag bit of the object identifier;
[0230] S1109, When the flag bit of the object identifier does not match the login enterprise identifier and the login restriction item of the office application is in the open state, the server re-obtains the list of target enterprises represented by the flag bit of the object identifier.
[0231] S1110, the server re-queries the target identity identifier and target job identifier of the target object under the target enterprise represented by the flag bit of the object identifier;
[0232] S1111 If the re-acquired list does not include the target identity identifier and the target job identifier queried again, the server will log out of the office application on the desktop client.
[0233] In one specific embodiment, such as Figure 12 As shown, the login control method also includes:
[0234] S1201, The server receives a login restriction adjustment request sent by the desktop client for the office application; the login restriction adjustment request is a status adjustment request for login restrictions triggered on the security management page of the office application; the security management page includes login restrictions and other security management items;
[0235] S1202, The server responds to the login restriction adjustment request, updates the status of the login restriction, and obtains the open / closed status of the login restriction;
[0236] S1203, The server obtains the object identifier set; the object identifier set includes the object identifiers of each object in the target enterprise;
[0237] S1204A, when the open / closed state is open and the flag bits configured for the object identifiers in the object identifier set are empty, the server adds the target enterprise's enterprise identifier to the flag bits corresponding to each object identifier in the object identifier set.
[0238] S1204B: When the open / closed state is closed and the flags configured for the object identifiers in the object identifier set are not empty, the server will remove the enterprise identifier from the flags corresponding to each object identifier in the object identifier set.
[0239] In one specific embodiment, such as Figure 13 As shown, the login control method also includes:
[0240] S1301, The server receives an activation task request; the activation task request is an asynchronous task request initiated after a new member object is added to the target enterprise.
[0241] S1302, In response to the activation task request, the server obtains the on / off status of the login restrictions for the office application;
[0242] S1303, when the open / closed state is open and the flag bit under the object identifier of the member object is empty, the server adds the enterprise identifier of the target enterprise to the flag bit under the object identifier of the member object.
[0243] The above login control method involves the target object logging into the office application on the desktop, obtaining the target object's object identifier, and if the object identifier is configured with a flag bit, and the flag bit does not match the login enterprise identifier used when requesting to log into the office application, obtaining the list of target enterprises represented by the flag bit, and controlling the login result of the office application based on the target object's target identity identifier under the target enterprise and the list of enterprise identifiers. For the target enterprise, the above login control method can restrict its members from logging into the office application on the desktop using their member identities under other enterprises. In the target enterprise's office environment, its members can only log into the office application on the desktop in that office environment using their member identities under the target enterprise, which can effectively prevent the leakage of internal data of the target enterprise and ensure the security of internal data.
[0244] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0245] Based on the same inventive concept, this application also provides a login control device for implementing the login control method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more login control device embodiments provided below can be found in the limitations of the login control method described above, and will not be repeated here.
[0246] In one embodiment, such as Figure 14 As shown, a login control device is provided, including: an object identifier acquisition module 100, a list acquisition module 200, a target identity identifier determination module 300, and a login control module 400; wherein,
[0247] The object identifier acquisition module 100 is used to obtain the object identifier of the target object in response to a login request for an office application on the desktop; the target object is the user object of the authorized account associated with the office application.
[0248] The list acquisition module 200 is used to acquire the list of target enterprises represented by the flag when the object identifier is configured with a flag bit and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application.
[0249] The target identity determination module 300 is used to query the target identity of a target object under the target enterprise based on the object identifier and the flag bit;
[0250] The login control module 400 is used to control the login results of office applications based on the target identity and list set.
[0251] In some embodiments, the login control device further includes:
[0252] The login restriction adjustment module is used to respond to login restriction adjustment requests for office applications, update the status of login restrictions for office applications, and obtain the open / closed status of login restrictions.
[0253] The object identifier set acquisition module is used to acquire the object identifier set; the object identifier set includes the object identifiers of each object in the target enterprise;
[0254] The first flag setting module is used to add the target company's enterprise identifier to the flag position corresponding to each object identifier in the object identifier set when the open / closed state is open and the flag position configured for the object identifier in the object identifier set is empty.
[0255] The second flag setting module is used to remove the enterprise identifier from the flags corresponding to each object identifier in the object identifier set when the open / closed state is closed and the flags configured for the object identifiers in the object identifier set are not empty.
[0256] In some embodiments, the login restriction adjustment module is specifically used to receive a login restriction adjustment request sent by the desktop client for the office application; the login restriction adjustment request is a status adjustment request for login restrictions triggered on the security management page of the office application; the security management page includes login restrictions and other security management items; in response to the login restriction adjustment request, the status of the login restrictions is updated.
[0257] In some embodiments, the login control device further includes:
[0258] The activation task request receiving module is used to receive activation task requests; the activation task request is an asynchronous task request initiated after a new member object is added to the target enterprise.
[0259] The on / off state acquisition module is used to obtain the on / off state of login restrictions of office applications in response to activation task requests.
[0260] The third flag setting module is used to add the target company's enterprise identifier to the flag position under the object identifier of the member object when the open / closed state is open and the flag position under the object identifier of the member object is empty.
[0261] In some embodiments, the list acquisition module 200 includes:
[0262] The on / off state acquisition unit is used to acquire the on / off state of login restrictions in office applications;
[0263] The list acquisition unit is used to acquire the list of target companies represented by the flag bit when the open / closed state is open.
[0264] The login control device also includes:
[0265] The first login unit is used to allow the target object to log in to the office application with a login identity when the open / closed state is closed; the login identity is an identity under another enterprise used when requesting to log in to the office application.
[0266] In some embodiments, the login control module 400 includes:
[0267] The survival status acquisition unit is used to acquire the survival status of the target identity identifier and the enterprise identifier, respectively; the enterprise identifier is the identifier of the target enterprise.
[0268] The login control unit is used to control the login result of the office application based on the target identity and list set when all existing states meet the preset state conditions.
[0269] In some embodiments, the first login unit is further configured to log in to the office application based on the login identity of the target object when at least one of the existence status of the target identity or the existence status of the enterprise identity does not meet the preset status conditions; wherein, the login identity is an identity under another enterprise used when requesting to log in to the office application.
[0270] In some embodiments, the login control unit includes:
[0271] The target job identifier acquisition unit is used to query the target job identifier of the target object under the target enterprise based on the target identity identifier when all existing states meet the preset state conditions.
[0272] The first login unit is also used to log in to the office application based on the login identity of the target object when the list set includes at least one of the target identity identifier or the target job identifier; the login identity identifier is the identity identifier under another enterprise used when requesting to log in to the office application;
[0273] The second login unit is used to prevent login to office applications when the target identity and target job title are not included in the list.
[0274] In some embodiments, the login control device further includes:
[0275] The information sending unit is used to send a first prompt message to the mobile terminal if the login request is a login request for the office application sent when the mobile terminal scans a QR code to log in, so as to instruct the mobile terminal to display the first prompt message on the login operation page;
[0276] The information sending unit is also used to send a second prompt message to the desktop if the login request is an account switching request for an office application sent by the desktop, so as to instruct the desktop to display the second prompt message on the login prompt page.
[0277] In some embodiments, the first login unit is further configured to log in to the office application based on the login identity of the target object when the object identifier is not configured with a flag bit or the flag bit configured with the object identifier matches the login enterprise identifier; wherein, the login identity is an identity identifier under another enterprise used when requesting to log in to the office application.
[0278] In some embodiments, the login control device further includes:
[0279] The login continuation module is used to retrieve the flag of the object identifier when the login duration based on the login identity reaches a preset duration; if the flag of the object identifier does not match the login enterprise identifier and the login restriction of the office application is in the on / off state, it re-retrieves the list of target enterprises represented by the flag of the object identifier; it re-queries the target identity identifier and target job identifier of the target object under the target enterprise represented by the flag of the object identifier; if the re-retrieved list does not include the re-queried target identity identifier and re-queried target job identifier, the server logs out of the office application on the login desktop.
[0280] Each module in the aforementioned login control device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0281] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 15 As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and databases. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media to run. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a login control method.
[0282] Those skilled in the art will understand that Figure 15 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0283] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0284] The object identifier acquisition module is used to obtain the object identifier of the target object in response to a login request for an office application on the desktop; the target object is the user of the authorized account associated with the office application.
[0285] The list acquisition module is used to acquire the list of target enterprises represented by the flag when the object identifier is configured with a flag bit and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application.
[0286] The target identity identification module is used to query the target identity identification of the target object under the target enterprise based on the object identifier and the flag bit;
[0287] The login control module is used to control the login result of the office application based on the target identity and the list.
[0288] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0289] The object identifier acquisition module is used to obtain the object identifier of the target object in response to a login request for an office application on the desktop; the target object is the user of the authorized account associated with the office application.
[0290] The list acquisition module is used to acquire the list of target enterprises represented by the flag when the object identifier is configured with a flag bit and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application.
[0291] The target identity identification module is used to query the target identity identification of the target object under the target enterprise based on the object identifier and the flag bit;
[0292] The login control module is used to control the login result of the office application based on the target identity and the list.
[0293] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0294] The object identifier acquisition module is used to obtain the object identifier of the target object in response to a login request for an office application on the desktop; the target object is the user of the authorized account associated with the office application.
[0295] The list acquisition module is used to acquire the list of target enterprises represented by the flag when the object identifier is configured with a flag bit and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application.
[0296] The target identity identification module is used to query the target identity identification of the target object under the target enterprise based on the object identifier and the flag bit;
[0297] The login control module is used to control the login result of the office application based on the target identity and the list.
[0298] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0299] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any application to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0300] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0301] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A login control method, characterized in that, The method includes: In response to a login request for an office application on a desktop, the object identifier of the target object is obtained; the target object is the user of the authorized account associated with the office application, and the target object has member identities corresponding to multiple enterprises; When the object identifier is configured with a flag bit, and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application, the list of target enterprises represented by the flag bit is obtained; the flag bit is used to restrict the target object to log in to the office application on the desktop as a member under the enterprise corresponding to the flag bit; the list includes some members in the target enterprise, and when the flag bit of these members represents the target enterprise, these members can log in to the office application on the desktop as members under other enterprises; Based on the object identifier and the flag bit, query the target identity identifier of the target object under the target enterprise; Based on the target identity and the list, the login result of the office application is controlled.
2. The method according to claim 1, characterized in that, The method further includes: In response to a request to adjust login restrictions for the office application, the status of the login restrictions for the office application is updated to obtain the open / closed status of the login restrictions. Obtain an object identifier set; the object identifier set includes the object identifiers of each object in the target enterprise; When the open / closed state is open and the flag bit configured for the object identifier in the object identifier set is empty, the enterprise identifier of the target enterprise is added to the flag bit corresponding to each object identifier in the object identifier set. If the open / closed state is closed and the flag bit configured for the object identifier in the object identifier set is not empty, the enterprise identifier is removed from the flag bit corresponding to each object identifier in the object identifier set.
3. The method according to claim 2, characterized in that, The step of updating the status of the login restrictions for the office application in response to the request to adjust the login restrictions for the office application includes: The system receives a login restriction adjustment request sent by the desktop client for the office application; the login restriction adjustment request is a status adjustment request for login restrictions triggered on the security management page of the office application; the security management page includes the login restrictions and other security management items. In response to the login restriction adjustment request, update the status of the login restriction.
4. The method according to claim 1, characterized in that, The method further includes: Receive activation task request; the activation task request is an asynchronous task request initiated after the target enterprise adds a new member object; In response to the activation task request, obtain the on / off status of the login restrictions of the office application; When the opening / closing state is open and the flag bit under the object identifier of the member object is empty, add the enterprise identifier of the target enterprise to the flag bit under the object identifier of the member object.
5. The method according to claim 1, characterized in that, The step of obtaining the list of target companies represented by the flag bit includes: Obtain the on / off status of the login restrictions for the office application; When the open / closed state is in the open state, obtain the list of target companies represented by the flag bit; The method further includes: when the open / closed state is closed, logging into the office application based on the login identity identifier of the target object; the login identity identifier is an identity identifier under another enterprise used when requesting to log into the office application.
6. The method according to claim 1, characterized in that, The step of controlling the login result of the office application based on the target identity and the list includes: Obtain the current status of the target identity identifier and the enterprise identifier; the enterprise identifier is the identifier of the target enterprise. When all the existing states meet the preset state conditions, the login result of the office application is controlled according to the target identity and the list set.
7. The method according to claim 6, characterized in that, The method further includes: When at least one of the existence status of the target identity or the existence status of the enterprise identity does not meet the preset status condition, the office application is logged in based on the login identity of the target object; The login identity identifier is an identity identifier from another enterprise used when requesting to log in to the office application.
8. The method according to claim 6, characterized in that, When all the existing states meet the preset state conditions, the login result of the office application is controlled according to the target identity and the list set, including: When all the existing states meet the preset state conditions, the target position identifier of the target object under the target enterprise is queried based on the target identity identifier; When the list includes at least one of the target identity identifier or the target job identifier, the user logs into the office application based on the login identity identifier of the target object; the login identity identifier is an identity identifier under another enterprise used when requesting to log in to the office application. If the target identity and the target job title are not included in the list, login to the office application is prohibited.
9. The method according to claim 8, characterized in that, After prohibiting login to the office application, the method further includes: If the login request is a request to log in to the office application sent by the mobile terminal when scanning a QR code, then a first prompt message is sent to the mobile terminal to instruct the mobile terminal to display the first prompt message on the login operation page; If the login request is an account switching request for the office application sent by the desktop client, then a second prompt message is sent to the desktop client to instruct the desktop client to display the second prompt message on the login prompt page.
10. The method according to claim 1, characterized in that, The method further includes: When the object identifier is not configured with a flag bit, or when the flag bit configured with the object identifier matches the login enterprise identifier, the office application is logged in based on the login identity identifier of the target object; The login identity identifier is an identity identifier from another enterprise used when requesting to log in to the office application.
11. The method according to any one of claims 5, 7, 8 or 10, characterized in that, After logging into the office application based on the login identity of the target object, the process further includes: When the duration of login to the office application based on the login identity reaches a preset duration, the flag bit of the object identifier is obtained; When the flag bit of the object identifier does not match the login enterprise identifier, and the login restriction item of the office application is in the open state, the list of target enterprises represented by the flag bit of the object identifier is retrieved again. Re-query the target identity identifier and target job identifier of the target object under the target enterprise represented by the flag bit of the object identifier; If the re-obtained list does not include the target identity and target job title that were queried again, then log out of the office application on the desktop client.
12. A login control device, characterized in that, The device includes: The object identifier acquisition module is used to obtain the object identifier of the target object in response to a login request for an office application on the desktop; the target object is the user of the authorized account associated with the office application, and the target object has member identities corresponding to multiple enterprises; The list acquisition module is used to acquire the list of target companies represented by the flag bit when the object identifier is configured with a flag bit and the flag bit does not match the login enterprise identifier used when requesting to log in to the office application; the flag bit is used to restrict the target object to log in to the office application on the desktop as a member under the enterprise corresponding to the flag bit; the list includes some members in the target enterprise, and when the flag bit of these members represents the target enterprise, these members can log in to the office application on the desktop as members under other enterprises; The target identity identification module is used to query the target identity identification of the target object under the target enterprise based on the object identifier and the flag bit; The login control module is used to control the login result of the office application based on the target identity and the list.
13. The login control device according to claim 12, characterized in that, The device further includes: The login restriction adjustment module is used to respond to the login restriction adjustment request for the office application, update the status of the login restriction of the office application, and obtain the open / closed status of the login restriction. The object identifier set acquisition module is used to acquire an object identifier set; the object identifier set includes the object identifiers of each object in the target enterprise; The first flag setting module is used to add the enterprise identifier of the target enterprise to the flag position corresponding to each object identifier in the object identifier set when the opening / closing state is open and the flag position configured for the object identifier in the object identifier set is empty. The second flag setting module is used to remove the enterprise identifier from the flags corresponding to each object identifier in the object identifier set when the open / closed state is closed and the flags configured for the object identifiers in the object identifier set are not empty.
14. The login control device according to claim 13, characterized in that, The login restriction adjustment module is also used to receive a login restriction adjustment request sent by the desktop client for the office application; the login restriction adjustment request is a status adjustment request for login restrictions triggered on the security management page of the office application; the security management page includes the login restrictions and other security management items; in response to the login restriction adjustment request, the status of the login restrictions is updated.
15. The login control device according to claim 12, characterized in that, The device further includes: An activation task request receiving module is used to receive activation task requests; the activation task request is an asynchronous task request initiated after the target enterprise adds a new member object; The on / off state acquisition module is used to acquire the on / off state of the login restriction items of the office application in response to the activation task request. The third flag setting module is used to add the enterprise identifier of the target enterprise to the flag position under the object identifier of the member object when the opening / closing state is open and the flag position under the object identifier of the member object is empty.
16. The login control device according to claim 12, characterized in that, The list acquisition module is also used to acquire the on / off status of the login restriction items of the office application; when the on / off status is on, acquire the list of target enterprises represented by the flag bit. The login control module is also used to log in to the office application based on the login identity identifier of the target object when the open / closed state is closed; the login identity identifier is an identity identifier under another enterprise used when requesting to log in to the office application.
17. The login control device according to claim 12, characterized in that, The login control module is also used to obtain the existence status of the target identity identifier and the enterprise identifier respectively; the enterprise identifier is the identifier of the target enterprise; when all the existence statuses meet the preset status conditions, the login result of the office application is controlled according to the target identity identifier and the list set.
18. The login control device according to claim 17, characterized in that, The login control module is further configured to log in to the office application based on the login identity of the target object when at least one of the existence status of the target identity or the existence status of the enterprise identity does not meet the preset status conditions; wherein, the login identity is an identity under another enterprise used when requesting to log in to the office application.
19. The login control device according to claim 17, characterized in that, The login control module is also used to query the target position identifier of the target object under the target enterprise based on the target identity identifier when all the existing states meet the preset state conditions; when the list includes at least one of the target identity identifier or the target position identifier, log in to the office application based on the login identity identifier of the target object; the login identity identifier is the identity identifier under another enterprise used when requesting to log in to the office application; If the target identity and the target job title are not included in the list, login to the office application is prohibited.
20. The login control device according to claim 19, characterized in that, The device further includes an information sending module, which is used to send a first prompt message to the mobile terminal if the login request is a login request sent by the mobile terminal when scanning a QR code to log in to the office application, so as to instruct the mobile terminal to display the first prompt message on the login operation page; If the login request is an account switching request for the office application sent by the desktop client, then a second prompt message is sent to the desktop client to instruct the desktop client to display the second prompt message on the login prompt page.
21. The login control device according to claim 12, characterized in that, The login control module is also used to log in to the office application based on the login identity identifier of the target object when the object identifier is not configured with a flag bit, or when the flag bit configured with the object identifier matches the login enterprise identifier; wherein, the login identity identifier is an identity identifier under another enterprise used when requesting to log in to the office application.
22. The login control device according to any one of claims 16, 18, 19 or 21, characterized in that, The login control module is further configured to: obtain the flag bit of the object identifier when the duration of login to the office application based on the login identity reaches a preset duration; and re-obtain the list of target enterprises represented by the flag bit of the object identifier when the flag bit of the object identifier does not match the login enterprise identifier and the login restriction item of the office application is in the on / off state. It will also re-query the target identity and target position identifier of the target object under the target enterprise represented by the flag bit of the object identifier. If the re-obtained list does not include the target identity and target job title that were queried again, then log out of the office application on the desktop client.
23. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 11.
24. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 11.
25. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 11.