Method, device and readable storage medium for managing permissions
By constructing tree-like and hierarchical relationship diagrams, the scope of permissions for target roles is clearly defined, solving the problem of complex permission management in enterprises and achieving clear and efficient permission configuration management.
Patent Information
- Application Number
- CN202510004238.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-01-02
AI Technical Summary
In large chain supermarkets and banks, which have multiple organizational levels, access control is complex and unclear, making it difficult to accurately assess the scope of permissions between different corporate roles.
By constructing tree-like and hierarchical relationship diagrams, the scope of authority for target roles is clarified based on the subordinate relationships of the organization, providing customized permission configuration methods. By utilizing the user's operation of configuring role permissions, the organization corresponding to the target role is determined and data management permissions are set.
It simplifies the difficulty of permission management, improves the clarity and efficiency of permission configuration, meets the permission setting needs of different users, avoids permission chaos, and improves the user experience.
Smart Images

Figure CN119847397B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and more specifically, to a method, apparatus, device, and readable storage medium for access control. Background Technology
[0002] In large chain supermarkets and banks, which have multiple organizational levels, different corporate roles are assigned different organizational management permissions. Since there are often multiple entities at the same level, permission management becomes extremely complex and chaotic, making it difficult to accurately assess whether the scope of permissions is the same for different corporate roles. The organizational management permissions corresponding to different roles are intertwined, and the same entity may be managed by multiple different corporate roles, resulting in unclear and ambiguous definitions of the scope of permissions.
[0003] Given this complex and chaotic situation, accurately determining the scope of permissions for each enterprise role has become a key concern during the process of setting up permissions. Summary of the Invention
[0004] In view of this, this application provides a permission management method, apparatus, device and readable storage medium to solve the shortcomings of the prior art in that the scope of permission is not clearly defined.
[0005] To achieve the above objectives, the following solution is proposed:
[0006] An access control method, comprising:
[0007] In response to the user's operation of configuring role permissions, construct the target role and determine whether customized permission configuration is required for the target role;
[0008] If so, respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram;
[0009] If not, determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationships between the second organizations, construct a network relationship diagram corresponding to the target role and set the data management permissions of the target role for each second organization in the network relationship diagram.
[0010] Optionally, the response to the user's selection operation in the permission configuration interface, determining all first organizations of the target role, includes:
[0011] In response to the user's selection operation on the permission configuration interface, the target affiliated organization and target permission type of the target role are determined. Based on the target permission type and the target affiliated organization, all first organizations of the target role are determined; wherein, the target permission type is used to indicate the selection range of the first organizations of the corresponding target role.
[0012] Optionally, determining all first organizational structures of the target role based on the target permission type and the target affiliated organization includes:
[0013] When the target permission type indicates that the first organization selection scope covers all organizations, each organization whose business type is consistent with the target affiliated organization is identified as each first organization.
[0014] or,
[0015] When the target permission type indicates that the selection scope of the first organization is a subordinate branch organization, each first organization is selected from each subordinate organization of the target belonging organization;
[0016] or,
[0017] When the target permission type indicates that the first organizational selection scope is a subordinate organization, the target affiliated organization is determined to be the first organizational organization;
[0018] or,
[0019] When the target permission type indicates that the selection scope of the first organization is the superior branch organization, each first organization is selected from each superior organization of the target belonging organization.
[0020] Optionally, when the target permission type indicates that the selection scope of the first organizational organization is a subordinate branch organization, each first organizational organization is selected from the subordinate organizations of the target parent organization, including:
[0021] When the target permission type indicates that the first organizational structure selection scope is a lower-level branch organization, the target number of levels is determined in response to the user's operation of setting the organizational structure selection level.
[0022] Based on the subordinate relationship of the target affiliated organization, the subordinate organizations of the target affiliated organization are investigated downwards, and the subordinate organizations that meet the target number of levels are selected as the first organizational organizations.
[0023] Optional, also includes:
[0024] In response to a user's marking operation on the permission configuration interface, when the target belonging organization is the first organization of the target role, the system determines whether the target role has the permission to manage other roles in the first organization based on the marking operation; if not, the system restricts the permissions of the target role.
[0025] Optionally, the response to the user's selection operation in the permission configuration interface, determining all first organizations of the target role, includes:
[0026] In response to the user's selection of an organization on the permission configuration interface, all organizations selected by the user will be designated as the primary organizations.
[0027] Optionally, determining all second organizations corresponding to the permission domain includes:
[0028] When the scope of authority is a functional scope, each organization belonging to the functional scope is regarded as a second organization.
[0029] or,
[0030] When the scope of authority is the business domain, each organization belonging to the business domain is regarded as a second organization.
[0031] or,
[0032] When the scope of authority is the entire scope, all organizations are treated as individual second organizations.
[0033] An access control device, comprising:
[0034] The construction module is used to respond to the user's operation of configuring role permissions, construct the target role, and determine whether customized permission configuration is required for the target role; if yes, the determination module is called; if no, the setting module is called.
[0035] The determination module is used to respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram;
[0036] The setting module is used to determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationships between the second organizations, a network relationship diagram corresponding to the target role is constructed, and the data management permissions of the target role to each second organization in the network relationship diagram are set.
[0037] A permission management device, including a memory and a processor;
[0038] The memory is used to store programs;
[0039] The processor is used to execute the program and implement the various steps of the above-described permission management method.
[0040] A readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described permission management method.
[0041] As can be seen from the above technical solution, the permission management method provided in this application can respond to the user's operation of configuring role permissions, construct a target role, and determine whether customized permission configuration is required for the target role. Based on this, this application can provide different permission setting methods for different user permission setting needs, improve the user experience, and avoid permission confusion caused by the same permission setting method. Subsequently, if customized permission configuration is required for the target role, the method responds to the user's selection operation in the permission configuration interface, determines all first organizations of the target role, and when the target role corresponds to more than two first organizations, traces the superior organization of each first organization upwards according to the subordinate relationship of each organization until each first organization belongs to the same superior organization, constructing a tree relationship diagram containing each first organization and each superior organization; and sets the data management permissions of the target role for each first organization in the tree relationship diagram. Based on this, this application utilizes the subordinate relationship of organizations to sort out the permissions of each first organization. The hierarchical relationships between structures are visually represented by a tree diagram, clarifying the organizational distribution and coverage of the target role's data management permissions, and further defining the target role's permission scope. If customized permission configuration for the target role is not required, the permission domain of the target role is determined, along with all the corresponding second organizations. Based on the hierarchical relationships between the second organizations, a network-like relationship diagram is constructed for the target role, and the target role's data management permissions for each second organization in the network-like relationship diagram are set. Based on this, this application can convert the target role's permission scope from the permission domain to each second organization using the user-provided permission domain, further clarifying the target role's permission scope. This guides users to complete permission configuration simply by setting the permission domain, further accelerating the permission management process. Simultaneously, the network-like relationship diagram visually represents the hierarchical relationships between the second organizations, intuitively indicating the scope of the target role's data management permissions. As can be seen, this application can provide customized permission configuration methods, and by constructing tree diagrams and network diagrams, it can intuitively represent the permission management scope of a specific role, thereby making the permission scope of a specific role more intuitive and further simplifying the difficulty of permission management and permission differentiation. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0043] Figure 1 This is a flowchart of a permission management method disclosed in an embodiment of this application;
[0044] Figure 2 This is a block diagram of a permission management device disclosed in an embodiment of this application;
[0045] Figure 3 This is a hardware structure block diagram of a permission management device disclosed in an embodiment of this application. Detailed Implementation
[0046] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0047] This application provides a permission management method, which can be applied to various enterprise management systems or management platforms, as well as to various computer terminals or smart terminals. The executing entity can be the processor or server of the computer terminal or smart terminal. The flowchart of the permission management method is shown below. Figure 1 As shown, it specifically includes:
[0048] Next, combine Figure 1 The access control method described in this application is detailed, including the following steps:
[0049] Step S1: Respond to the user's operation of configuring role permissions, construct the target role, and determine whether customized permission configuration is required for the target role; if yes, proceed to step S2; if no, proceed to step S3.
[0050] Specifically, it can respond to a user's operation of creating a role in the permission configuration interface, construct the target role, and determine the creation time of the target role and the identifier of the user who created it;
[0051] Based on the user's selected actions, it can be determined whether customized permission configurations are needed for the target role.
[0052] For example, if a user selects to configure the first organization in the permission configuration interface, it is determined that customized permission configuration is required for the target role, and step S2 can be executed.
[0053] If the user selects a permission domain in the permission configuration interface, it indicates that no customized permission configuration is required for the target role, and step S3 can be executed.
[0054] The same target role can correspond to one or more different organizational members.
[0055] Step S2: Respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram.
[0056] Specifically, this can be achieved in various ways by responding to the user's selection operation in the permission configuration interface and determining all first organizations of the target role.
[0057] For example, it can respond to the user's operation of setting the organization selection method in the permission configuration interface and filter the first organization from various organizations;
[0058] It can also respond to the user's direct selection of an organization in the permission configuration interface, and set the organization selected by the user as the primary organization.
[0059] After identifying the primary organizations corresponding to the target role, the number of primary organizations corresponding to the target role can be determined.
[0060] When there are at least two such organizations, the superior organization of each primary organization can be found based on the subordinate relationship of each organization, until the same superior organization containing all the primary organizations is identified.
[0061] Among them, a knowledge graph can be set in advance, which records multiple organizations and the subordinate relationships between them.
[0062] A tree-like relationship diagram can be constructed based on the subordinate relationships between each primary organization and the found superior organizations.
[0063] You can configure the target role's data management permissions for each primary organization in the tree-structured relationship diagram.
[0064] A tree-like relationship diagram can contain multiple child nodes and a root node. The root node can be a superior organization corresponding to each first organization; the superior organization can be a common superior organization of each first organization.
[0065] Each child node can contain each first organization, as well as the common superior organization of any two first organizations.
[0066] Different target roles can correspond to different primary organizational structures.
[0067] The same organization can correspond to different target roles.
[0068] The target role's data management permissions for the first organization indicate that the target role can manage all member data and business data within the corresponding first organization.
[0069] Step S3: Determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationships between the second organizations, construct a network relationship diagram corresponding to the target role and set the data management permissions of the target role for each second organization in the network relationship diagram.
[0070] Specifically, the scope of permissions for the target role can be determined based on the role's positioning.
[0071] Different target roles can correspond to different permission domains.
[0072] The scope and distinction of the permission domains can be set according to the actual needs of the enterprise. For example, enterprises related to commodity operation can divide the permission domains into the whole domain, functional domains and business domains; enterprises related to software development can divide the permission domains into the whole domain, front-end domain and back-end domain.
[0073] It should be noted that the first organizational structure refers to the organizational structure corresponding to the target role when customized permission configuration is used; while the second organizational structure refers to the organizational structure corresponding to the target role when customized permission configuration is not required.
[0074] The primary and secondary organizations with different roles can be the same organization.
[0075] As can be seen from the above technical solution, the permission management method provided in this application can respond to the user's operation of configuring role permissions, construct a target role, and determine whether customized permission configuration is required for the target role. Based on this, this application can provide different permission setting methods for different user permission setting needs, improve the user experience, and avoid permission confusion caused by the same permission setting method. Subsequently, if customized permission configuration is required for the target role, the method responds to the user's selection operation in the permission configuration interface, determines all first organizations of the target role, and when the target role corresponds to more than two first organizations, traces the superior organization of each first organization upwards according to the subordinate relationship of each organization until each first organization belongs to the same superior organization, constructing a tree relationship diagram containing each first organization and each superior organization; and sets the data management permissions of the target role for each first organization in the tree relationship diagram. Based on this, this application utilizes the subordinate relationship of organizations to sort out the permissions of each first organization. The hierarchical relationships between structures are visually represented by a tree diagram, clarifying the organizational distribution and coverage of the target role's data management permissions, and further defining the target role's permission scope. If customized permission configuration for the target role is not required, the permission domain of the target role is determined, along with all the corresponding second organizations. Based on the hierarchical relationships between the second organizations, a network-like relationship diagram is constructed for the target role, and the target role's data management permissions for each second organization in the network-like relationship diagram are set. Based on this, this application can convert the target role's permission scope from the permission domain to each second organization using the user-provided permission domain, further clarifying the target role's permission scope. This guides users to complete permission configuration simply by setting the permission domain, further accelerating the permission management process. Simultaneously, the network-like relationship diagram visually represents the hierarchical relationships between the second organizations, intuitively indicating the scope of the target role's data management permissions. As can be seen, this application can provide customized permission configuration methods, and by constructing tree diagrams and network diagrams, it can intuitively represent the permission management scope of a specific role, thereby making the permission scope of a specific role more intuitive and further simplifying the difficulty of permission management and permission differentiation.
[0076] Furthermore, in response to the user's selection of a first role on the permission configuration interface, a tree-structured main diagram corresponding to the first role can be rendered and displayed. This tree-structured main diagram is marked with the permission organization corresponding to the first role to indicate the permission scope of the first role. The first role can be a role that has been configured with data management permissions.
[0077] The first role has data management permissions for various authorized organizations.
[0078] Furthermore, in response to the user's operation of selecting a second role in the permission configuration interface, the tree-structured relationship theme diagram corresponding to the second role is rendered and displayed. In response to the user's operation of configuring new permissions for the second role, the new permissions for the second role are determined. Based on the new permissions, the tree-structured relationship theme diagram of the second role is revised to complete the permission update for the second role.
[0079] As can be seen from the above technical solution, this application can realize permission configuration through the permission configuration interface, which has high reusability, high maintainability, low cost, and fast permission configuration speed.
[0080] In some embodiments of this application, to further meet the permission configuration needs of different users, this application provides two methods for setting the first organizational structure. Next, the process of determining all first organizational structures for the target role in response to the user's selection operation on the permission configuration interface in step S2 will be described in detail, as follows:
[0081] The first type
[0082] S20. Responding to the user's selection operation on the permission configuration interface, determine the target affiliated organization and target permission type of the target role, and based on the target permission type and the target affiliated organization, determine all first organizations of the target role; wherein, the target permission type is used to indicate the selection range of the first organizations corresponding to the target role.
[0083] Specifically, this application can provide an organizational structure filtering method. That is, it can respond to a user's operation of selecting the affiliated organization and permission type on the permission configuration interface, and determine the target affiliated organization and target permission type for a target role. The target permission type can be used to indicate the selectable range of the first organizational structure for the corresponding target role.
[0084] Based on the target's permission type, the selectable range can be determined, and based on the target's affiliated organization, the first organization corresponding to the target role can be selected from the selectable range.
[0085] The second type
[0086] S21. Respond to the user's operation of selecting an organization on the permission configuration interface, and set all the organizations selected by the user as the primary organizations.
[0087] Specifically, this application can provide an advanced customization method. That is, in response to the user's operation of directly selecting the first organization in the permission configuration interface, each user-defined organization is used as the first organization.
[0088] As can be seen from the above technical solution, this embodiment provides two ways to respond to the user's selection operation in the permission configuration interface and determine the available first organizations for the target role. Through the above methods, different personalized permission configuration methods can be provided for different user needs, thereby further improving the user experience. At the same time, the first method can filter the matching first organizations from the selectable range, reducing the difficulty for users to find the first organization from a variety of organizations and simplifying the permission configuration.
[0089] In some embodiments of this application, different target permission types may correspond to different first organizational structure filtering methods. Next, the first organizational structure filtering methods corresponding to different target permission types will be provided in detail, that is, the process of determining all first organizational structures of the target role based on the target permission type and the target affiliated organization in step S20 will be described in detail as follows:
[0090] The first type
[0091] S200: When the target permission type indicates that the selection scope of the first organization covers all organizations, each organization whose business type is consistent with the target affiliated organization is identified as the first organization.
[0092] Specifically, when the target permission type indicates that the selectable range of permissions for the target role is all organizations, the business types of all organizations can be determined, and each organization with the same business type as the target's affiliated organization can be designated as the target role's first organization.
[0093] The second type
[0094] S201 When the target permission type indicates that the selection scope of the first organization is a subordinate branch organization, select each first organization from each subordinate organization of the target belonging organization.
[0095] Specifically, when the target permission type indicates that the selectable range of permissions for the target role is a subordinate branch organization, multiple first organizations can be selected from the various subordinate organizations of the target's parent organization.
[0096] For example, the target organization of the target role can be a district branch, and its subordinate organizations can be Beizhen Sub-branch, Nanzhen Sub-branch, Xizhen Sub-branch, etc., and Beizhen Sub-branch, Nanzhen Sub-branch, Xizhen Sub-branch, etc. can be regarded as the target role's primary organizational organizations.
[0097] The third type
[0098] S202. When the target permission type indicates that the first organization selection range is a subordinate organization, the target affiliated organization is determined to be the first organization.
[0099] Specifically, when the target permission type indicates that the selectable range of permissions for the target role is the affiliated organization, the target's affiliated organization can be directly selected as the first organization.
[0100] The fourth type
[0101] S203. When the target permission type indicates that the selection range of the first organization is the superior branch organization, select each first organization from each superior organization of the target belonging organization.
[0102] Specifically, when the target permission type indicates that the selectable range of permissions for the target role is the superior branch organization, multiple first organizations can be selected from the various superior organizations of the target's parent organization.
[0103] As can be seen from the above technical solutions, this embodiment provides four optional methods for determining all first organizations of the target role based on the target permission type and the target affiliated organization. Through the above methods, different target permission types can be provided to meet different user needs and improve the applicability of this application.
[0104] In some embodiments of this application, the process of selecting each first organization from each subordinate organization of the target belonging organization in step S201 when the target permission type indicates that the selection scope of the first organization is a subordinate branch organization is described in detail. The steps are as follows:
[0105] S2010. When the target permission type indicates that the first organizational structure selection range is a lower-level branch organization, respond to the user's operation of setting the organizational structure selection level and determine the target level number.
[0106] Specifically, considering that some target roles do not have data management permissions for all subordinate branches, it is possible to try to restrict the permissions of target roles by utilizing the number of target levels.
[0107] The target hierarchy number can be used to indicate the number of levels covered by each primary organization corresponding to the target role.
[0108] S2011. Based on the subordinate relationship of the target affiliated organization, the subordinate organizations of the target affiliated organization are checked downwards, and the subordinate organizations that meet the target number of levels are selected as each first organization.
[0109] Specifically, based on the subordinate relationship of the target organization, the subordinate organizations of the target organization can be determined, and organizations that meet the target number of levels can be selected from the subordinate organizations as the first organizational organizations.
[0110] For example, the target organization of the target role can be the municipal branch, the subordinate organization of the municipal branch can be the district branch, and the subordinate organizations of the district branch can be the North Town Branch, the South Town Branch, the West Town Branch, etc. When the target level is 2, the district branch, the North Town Branch, the South Town Branch, the West Town Branch, etc. can be regarded as the primary organizational organizations of the target role.
[0111] As can be seen from the above technical solution, this embodiment provides an optional method for selecting each first organization from each of the subordinate organizations of the target affiliated organization when the target permission type indicates that the selection range of the first organization is a subordinate branch organization. The above method can further utilize the target hierarchy to select the first organization from multiple organizations, thereby improving the operability and flexibility of permission configuration.
[0112] Similarly, step S203, when the target permission type indicates that the selection scope of the first organization is the superior branch organization, the process of selecting each first organization from each superior organization of the target belonging organization may include:
[0113] When the target permission type indicates that the first organizational structure selection scope is the superior branch organization, the target number of levels is determined in response to the user's operation of setting the organizational structure selection level.
[0114] Based on the subordinate relationship of the target affiliated organization, trace back to the superior organization of the target affiliated organization, and select the superior organization that meets the target number of levels as each first organization.
[0115] In some embodiments of this application, considering that some target roles only have the authority to manage personal data, an authority restriction process for the target role can be added when the target's affiliated organization is the target role's first organizational organization. The process will now be described in detail, with the following steps:
[0116] S2020: In response to the user's marking operation on the permission configuration interface, when the target belonging organization is the first organization of the target role, determine whether the target role has the permission to manage other roles in the first organization based on the marking operation; if not, restrict the permissions of the target role.
[0117] Specifically, in response to a user's marking operation on the permission configuration interface, when the target affiliated organization is the first organization of the target role, the system assesses whether the target role only has the permission to modify personal data based on the marking operation. If so, the target role's permission is limited to personal data management permission; otherwise, it indicates that the target role has the permission to manage all user data in the corresponding target affiliated organization.
[0118] As can be seen from the above technical solution, compared with the previous embodiment, this embodiment adds an optional method for limiting the permissions of the target role. Through the above method, the permissions of the target role can be adjusted to personal data management permissions to meet the permission requirements of different roles.
[0119] In some embodiments of this application, considering that different permission domains have different second organizational structures, the process of determining all second organizational structures corresponding to the permission domain in step S3 will be described in detail, and the steps are as follows:
[0120] The first type
[0121] When the scope of authority is a functional scope, each organization belonging to the functional scope is regarded as a second organization.
[0122] Specifically, if the domain of authority is a functional domain, then all organizations within the functional domain can be considered as individual secondary organizations.
[0123] The second type
[0124] When the scope of authority is the business domain, each organization belonging to the business domain is regarded as a second organization.
[0125] Specifically, if the domain of authority is the business domain, then all organizations within the business domain can be considered as individual secondary organizations.
[0126] The third type
[0127] When the scope of authority is the entire scope, all organizations are treated as individual second organizations.
[0128] Specifically, if the scope of authority is the entire scope, then all organizations in the business scope and all organizations in the functional scope can be regarded as the various second organizations.
[0129] As can be seen from the above technical solutions, this embodiment provides three optional methods for determining all second organizations corresponding to the permission domain. Through the above methods, different second organizations can be configured for different permission domains, thereby improving the reliability and accuracy of permission configuration of this application.
[0130] Next, we will combine Figure 2 The permission management device provided in this application is described in detail. The permission management device described below can be compared with the permission management method described above.
[0131] See Figure 2 It can be observed that the access control device may include:
[0132] The construction module 10 is used to respond to the user's operation of configuring role permissions, construct the target role, and determine whether customized permission configuration is required for the target role; if yes, the determination module 20 is called; if no, the setting module 30 is called.
[0133] The determination module 20 is used to respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram;
[0134] The setting module 30 is used to determine the permission domain of the target role and all the second organizations corresponding to the permission domain, construct a network relationship diagram corresponding to the target role based on the subordinate relationship between the various second organizations, and set the data management permissions of the target role to each second organization in the network relationship diagram.
[0135] Furthermore, module 20 may include:
[0136] The target attribution organization utilization unit is used to respond to the user's selection operation on the permission configuration interface, determine the target attribution organization and target permission type of the target role, and determine all first organizations of the target role based on the target permission type and the target attribution organization; wherein, the target permission type is used to indicate the selection range of the first organizations corresponding to the target role.
[0137] Furthermore, the target attribution agency's utilization unit may include:
[0138] The business type utilization component is used to determine each organization whose business type is consistent with the target affiliated organization as each first organization when the target permission type indicates that the first organization selection scope covers all organizations.
[0139] The subordinate organization selection component is used to select each first organization from each subordinate organization of the target belonging organization when the target permission type indicates that the selection scope of the first organization is a subordinate branch organization;
[0140] The subordinate organization selection component is used to determine the target affiliated organization as the first organizational organization when the target permission type indicates that the first organizational organization selection range is subordinate organizations;
[0141] The parent organization component is used to select each first organization from each parent organization of the target belonging organization when the target permission type indicates that the first organization selection range is a parent branch organization.
[0142] Furthermore, the components selected by the lower-level organization may include:
[0143] The target hierarchy number determination subcomponent is used to determine the target hierarchy number in response to the user's operation of setting the organization selection hierarchy when the target permission type indicates that the first organization selection range is a lower-level branch organization;
[0144] The target hierarchy utilizes a sub-component to search downwards for subordinate organizations of the target affiliated organization based on the subordinate relationship of the target affiliated organization, and selects subordinate organizations that meet the target hierarchy as each first organizational organization.
[0145] Furthermore, the affiliation selection component may include:
[0146] The permission restriction subcomponent is used to respond to the user's marking operation in the permission configuration interface. When the target belonging organization is the first organization of the target role, it determines whether the target role has the permission to manage other roles in the first organization based on the marking operation; if not, it restricts the permissions of the target role.
[0147] Furthermore, module 20 may also include:
[0148] The organization selection unit is used to respond to the user's operation of selecting an organization on the permission configuration interface, and to set all the organizations selected by the user as the primary organizations.
[0149] Furthermore, the setting module 30 may include:
[0150] The first setting unit is used to designate each organization belonging to the functional domain as a second organization when the domain of authority is a functional domain.
[0151] The second setting unit is used to designate each organization belonging to the business domain as a second organization when the domain of authority is a business domain.
[0152] The third setting unit is used to treat all organizations as individual second organizations when the permission domain is the entire domain.
[0153] The access control device provided in this application embodiment can be applied to access control devices, such as PC terminals, cloud platforms, servers, and server clusters. Optionally, Figure 3 The hardware structure block diagram of the access control device is shown below. Figure 3The hardware structure of the access control device may include: at least one processor 1, at least one communication interface 2, at least one memory 3, and at least one communication bus 4;
[0154] In this embodiment of the application, the number of processor 1, communication interface 2, memory 3, and communication bus 4 is at least one, and processor 1, communication interface 2, and memory 3 communicate with each other through communication bus 4;
[0155] Processor 1 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.
[0156] Memory 3 may include high-speed RAM, and may also include non-volatile memory, such as at least one disk storage device;
[0157] The memory stores a program, which the processor can call. The program is used for:
[0158] In response to the user's operation of configuring role permissions, construct the target role and determine whether customized permission configuration is required for the target role;
[0159] If so, respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram;
[0160] If not, determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationships between the second organizations, construct a network relationship diagram corresponding to the target role and set the data management permissions of the target role for each second organization in the network relationship diagram.
[0161] Optionally, the refined and extended functions of the program can be referred to the above description.
[0162] This application embodiment also provides a readable storage medium that can store a program suitable for execution by a processor, the program being used for:
[0163] In response to the user's operation of configuring role permissions, construct the target role and determine whether customized permission configuration is required for the target role;
[0164] If so, respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram;
[0165] If not, determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationships between the second organizations, construct a network relationship diagram corresponding to the target role and set the data management permissions of the target role for each second organization in the network relationship diagram.
[0166] Optionally, the refined and extended functions of the program can be referred to the above description.
[0167] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0168] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0169] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. The various embodiments of this application can be combined with each other. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for managing access permissions, characterized in that, include: In response to the user's operation of configuring role permissions, construct the target role and determine whether customized permission configuration is required for the target role; If so, respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until all first organizations belong to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization; set the data management permissions of the target role for each first organization in the tree relationship diagram; If not, determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationships between the second organizations, construct a network relationship diagram corresponding to the target role and set the data management permissions of the target role for each second organization in the network relationship diagram. The response user's selection operation in the permission configuration interface determines all first-level organizations of the target role, including: In response to the user's selection operation on the permission configuration interface, determine the target organization and target permission type of the target role; When the target permission type indicates that the first organization selection scope covers all organizations, each organization whose business type is consistent with the target affiliated organization is identified as each first organization. or, When the target permission type indicates that the selection scope of the first organization is a subordinate branch organization, each first organization is selected from each subordinate organization of the target belonging organization; or, When the target permission type indicates that the first organizational selection scope is a subordinate organization, the target affiliated organization is determined to be the first organizational organization; or, When the target permission type indicates that the selection scope of the first organization is the superior branch organization, each first organization is selected from each superior organization of the target belonging organization.
2. The access control method according to claim 1, characterized in that, When the target permission type indicates that the selection scope of the first organizational organization is a subordinate branch organization, each first organizational organization is selected from the subordinate organizations of the target parent organization, including: When the target permission type indicates that the first organizational structure selection scope is a lower-level branch organization, the target number of levels is determined in response to the user's operation of setting the organizational structure selection level. Based on the subordinate relationship of the target affiliated organization, the subordinate organizations of the target affiliated organization are investigated downwards, and the subordinate organizations that meet the target number of levels are selected as the first organizational organizations.
3. The access control method according to claim 1, characterized in that, Also includes: In response to a user's marking operation on the permission configuration interface, when the target belonging organization is the first organization of the target role, determine whether the target role has the permission to manage other roles in the first organization based on the marking operation; If not, then access restrictions will be imposed on the target role.
4. The access control method according to claim 1, characterized in that, The response user's selection operation in the permission configuration interface determines all first-level organizations of the target role, including: In response to the user's selection of an organization on the permission configuration interface, all organizations selected by the user will be designated as the primary organizations.
5. The access control method according to claim 1, characterized in that, The determination of all second organizations corresponding to the permission domain includes: When the scope of authority is a functional scope, each organization belonging to the functional scope is regarded as a second organization. or, When the scope of authority is the business domain, each organization belonging to the business domain is regarded as a second organization. or, When the scope of authority is the entire scope, all organizations are treated as individual second organizations.
6. A permission management device, characterized in that, include: The module is used to respond to user operations on configuring role permissions, construct the target role, and determine whether customized permission configuration is required for the target role. If yes, then call the determination module; otherwise, call the settings module. The determination module is used to respond to the user's selection operation in the permission configuration interface, determine all first organizations of the target role, and when the target role corresponds to more than two first organizations, trace the superior organization of each first organization upwards according to the subordinate relationship of each organization until each first organization belongs to the same superior organization, and construct a tree relationship diagram containing each first organization and each superior organization. Set the data management permissions of the target role for each first organization in the tree-structured relationship diagram; The setting module is used to determine the permission domain of the target role and all the second organizations corresponding to the permission domain. Based on the subordinate relationship between the second organizations, a network relationship diagram corresponding to the target role is constructed, and the data management permissions of the target role to each second organization in the network relationship diagram are set. The determining module includes: The target attribution organization utilization unit is used to respond to the user's selection operation on the permission configuration interface and determine the target attribution organization and target permission type of the target role; When the target permission type indicates that the selection scope of the first organization covers all organizations, each organization whose business type is consistent with that of the target affiliated organization is identified as a first organization; or, when the target permission type indicates that the selection scope of the first organization is a subordinate branch organization, each first organization is selected from the subordinate organizations of the target affiliated organization; or, when the target permission type indicates that the selection scope of the first organization is a subordinate organization, the target affiliated organization is identified as a first organization; or, when the target permission type indicates that the selection scope of the first organization is a superior branch organization, each first organization is selected from the superior organizations of the target affiliated organization.
7. A permission management device, characterized in that, Including memory and processor; The memory is used to store programs; The processor is used to execute the program to implement the various steps of the permission management method as described in any one of claims 1-5.
8. A readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements each step of the permission management method as described in any one of claims 1-5.
Citation Information
Patent Citations
Multi-hierarchy user permission management method
CN106713340A
Authority control method and device, computer equipment and storage medium
CN113821777A
Data authority control method and device based on tree structure and electronic equipment
CN117195266A