Permission data processing method and device

By using distributed locks and task queues in the permission management system, multiple data cache construction tasks are integrated and executed within a preset time period, the construction errors and system pressure problems caused by a large number of data permission changes in a short time are solved, and the correctness of user permission data and system performance are improved.

CN119939613APending Publication Date: 2025-05-06BEIJING JINGDONG TUOXIAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311466996.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the permission management system, when a large number of data permission changes occur in a short period of time, data permission construction errors may be caused and put a lot of pressure on the system and database.

Method used

The server cluster is locked through distributed locks, and the data cache construction task is generated and stored in the task queue. Multiple data cache construction tasks are integrated into one target task and executed only within the preset time period to avoid update errors caused by the task time being too close.

Benefits of technology

It reduces the number of executions of data cache construction tasks, avoids data update errors caused by too close task time, ensures the correctness of user permission data, and reduces the pressure on the system and database.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939613A_ABST
    Figure CN119939613A_ABST
Patent Text Reader

Abstract

The invention discloses a permission data processing method and device, and relates to the technical field of information security. A specific embodiment of the method comprises the following steps: in response to a monitored data permission change operation for a target application, writing changed permission change data into a database, generating a data cache construction task, and storing the data cache construction task into a task queue corresponding to the target application; locking each server in the server cluster through a distributed lock, locking the successfully locked server as a task execution server, starting a thread of the task execution server, and pulling a plurality of data cache construction tasks in a preset time period from a task queue; and integrating the plurality of data cache construction tasks to obtain a target data cache construction task, executing the target data cache construction task, pulling permission change data from the database, and performing full permission data change operation on all objects under the target application. According to the embodiment, the problem of data updating errors caused by too short task time can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a permission data processing method and device. Background Art

[0002] In the permission management system of the backend system, data permission requests are not only more frequent than functional permissions, but also require a longer request duration. In order to improve the response speed of the data permission interface, the user's data permissions are generally saved in the cache in advance. When the system's permission configuration changes, the user's data permission cache will also be rebuilt so that the user can query the latest data permissions.

[0003] In the process of implementing the present invention, the inventors found that there are at least the following problems in the prior art: this operation may cause data permission construction errors in the scenario where a large number of data permission changes occur in a short period of time. For example, if two changes build the cache almost at the same time, the cache built for the first time will overwrite the cache built for the second time, which will cause problems with the permissions used by the user. At the same time, a large number of data cache builds in a short period of time will also cause great pressure on the permission management system and database. Summary of the invention

[0004] In view of this, an embodiment of the present invention provides a permission data processing method and device, which can at least solve the problem of update errors caused by changing user permission data too recently in the prior art.

[0005] To achieve the above objective, according to one aspect of an embodiment of the present invention, a method for processing rights data is provided, comprising:

[0006] In response to monitoring a data permission change operation for a target application, writing the changed permission change data into a database, and generating a data cache building task to be stored in a task queue corresponding to the target application;

[0007] Each server in the server cluster is locked by a distributed lock, and the successfully locked server is locked as a task execution server, and the thread of the task execution server is started to pull multiple data cache construction tasks within a preset time period from the task queue;

[0008] The multiple data cache construction tasks are integrated and processed to obtain a target data cache construction task and execute it to pull permission change data from the database and perform a full permission data change operation on all objects under the target application.

[0009] Optionally, after performing the full permission data change operation on all objects under the target application, the method further includes:

[0010] In response to monitoring that there is a new data cache construction task in the task queue, a waiting operation is performed to pull and process multiple data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached;

[0011] In response to monitoring that there is no new data cache construction task in the task queue, the thread of the task execution server is closed and the distributed lock is released.

[0012] Optionally, the data cache construction task includes an object identification and permission data change task, and the integration processing of multiple data cache construction tasks includes:

[0013] The permission data change tasks with the same object identifier in the multiple data cache construction tasks are integrated, and the permission data change task with the latest generation time is used as the target permission data change task with the same object identifier.

[0014] Optionally, writing the modified permission change data into the database includes:

[0015] Writing multiple permission change data of the same object identifier into the permission change data set corresponding to the same object identifier in the database in chronological order; or

[0016] The original authority data corresponding to the same object identifier in the database is replaced with the modified authority change data corresponding to the same object identifier.

[0017] To achieve the above object, according to another aspect of an embodiment of the present invention, a rights data processing device is provided, comprising:

[0018] A task generation module, configured to respond to monitoring a data permission change operation for a target application, write the changed permission change data into a database, and generate a data cache construction task to be stored in a task queue corresponding to the target application;

[0019] The task pulling module is used to lock each server in the server cluster through a distributed lock, lock the successfully locked server as a task execution server, and start the thread of the task execution server to pull multiple data cache construction tasks within a preset time period from the task queue;

[0020] The task integration execution module is used to integrate the multiple data cache construction tasks, obtain the target data cache construction task and execute it, so as to pull the permission change data from the database and perform a full permission data change operation on all objects under the target application.

[0021] Optionally, the device further includes a task re-execution module, configured to:

[0022] In response to monitoring that there is a new data cache construction task in the task queue, a waiting operation is performed to pull and process multiple data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached;

[0023] In response to monitoring that there is no new data cache construction task in the task queue, the thread of the task execution server is closed and the distributed lock is released.

[0024] Optionally, the data cache construction task includes an object identification and permission data change task, and the task integration execution module is used to:

[0025] The permission data change tasks with the same object identifier in the multiple data cache construction tasks are integrated, and the permission data change task with the latest generation time is used as the target permission data change task with the same object identifier.

[0026] Optionally, the task generation module is used to:

[0027] Writing multiple permission change data of the same object identifier into the permission change data set corresponding to the same object identifier in the database in chronological order; or

[0028] The original authority data corresponding to the same object identifier in the database is replaced with the modified authority change data corresponding to the same object identifier.

[0029] To achieve the above objective, according to another aspect of an embodiment of the present invention, a rights data processing electronic device is provided.

[0030] The electronic device of the embodiment of the present invention includes: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement any of the above-mentioned permission data processing methods.

[0031] To achieve the above objective, according to another aspect of an embodiment of the present invention, a computer-readable medium is provided, on which a computer program is stored, and when the program is executed by a processor, any of the above-mentioned permission data processing methods is implemented.

[0032] According to the solution provided by the present invention, one embodiment of the above invention has the following advantages or beneficial effects: in a scenario where permission cache needs to be frequently built in a permission management system, multiple data cache building tasks for the same application are integrated and executed once, thereby reducing the number of executions of data cache building tasks, avoiding the problem of data update errors caused by task times being too close, ensuring the correctness of updating user permission data, and reducing the pressure on the system and database.

[0033] The further effects of the above-mentioned non-conventional optional manner will be described below in conjunction with the specific implementation manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings are used to better understand the present invention and do not constitute an improper limitation of the present invention.

[0035] Figure 1 This is a schematic diagram of the main flow of a method for processing permission data according to an embodiment of the present invention;

[0036] Figure 2 is a flowchart of an optional permission data processing method according to an embodiment of the present invention;

[0037] Figure 3 is a flowchart of a specific permission data processing method according to an embodiment of the present invention;

[0038] Figure 4 is a schematic diagram of main modules of a rights data processing device according to an embodiment of the present invention;

[0039] Figure 5 is an exemplary system architecture diagram to which embodiments of the present invention may be applied;

[0040] Figure 6 It is a schematic diagram of the structure of a computer system of a mobile device or a server suitable for implementing an embodiment of the present invention. DETAILED DESCRIPTION

[0041] The following is a description of exemplary embodiments of the present invention in conjunction with the accompanying drawings, including various details of the embodiments of the present invention to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for clarity and conciseness, the description of well-known functions and structures is omitted in the following description.

[0042] In the technical solution of the present invention, the collection, collection, update, analysis, processing, use, transmission, storage and other aspects of user personal information involved are in compliance with the provisions of relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken for user personal information to prevent illegal access to user personal information data and maintain the security of user personal information, network security and national security.

[0043] See also Figure 1 , which shows a main flow chart of a permission data processing method provided by an embodiment of the present invention, comprising the following steps:

[0044] S101: In response to monitoring a data permission change operation for a target application, writing the changed permission change data into a database, and generating a data cache construction task to be stored in a task queue corresponding to the target application;

[0045] S102: Lock each server in the server cluster through a distributed lock, lock the successfully locked server as a task execution server, and start the thread of the task execution server to pull multiple data cache construction tasks within a preset time period from the task queue;

[0046] S103: Integrate the multiple data cache construction tasks to obtain and execute the target data cache construction task, so as to pull the permission change data from the database and perform a full permission data change operation on all objects under the target application.

[0047] In the above implementation, for step S101, a monitoring mechanism is set in the permission management system of the background system, so that when it is monitored that the data permissions in the permission management system have changed, the permission change data is first written into the database, and a data cache construction task is generated and placed in the task queue.

[0048] In actual operation, considering that there are multiple applications in the permission management system, different applications may include permission data of multiple users, so the permission management system may receive data permission change operations for multiple different applications at the same time. In order to distinguish the permission change data of these different applications, the set task queues can be for different applications, for example, application A-task queue a, task B-task queue B. In this solution, the application ID is set. The application ID is the unique ID of the application reconfigured by the authentication system. The application ID can be transparently transmitted from the front end when the permission is changed.

[0049] This solution considers Redis task queues. Compared with ordinary task queues, Redis task queues have the following differences: 1. Data persistence: Redis task queues use Redis as a message broker, so tasks can be persistently stored in Redis, and tasks will not be lost even if the system restarts or fails. 2. High performance: Redis is an in-memory database with fast read and write operations and high concurrency, which enables Redis task queues to handle a large number of tasks and distribute and execute tasks in real time. 3. Priority support: Redis task queues usually support task priority settings to ensure that important tasks are executed first. 4. Multiple task models: Redis task queues support multiple task models, such as delayed tasks, cyclic tasks, and delayed tasks. These models can be selected according to specific needs, increasing the flexibility and scalability of task scheduling. Therefore, compared with ordinary task queues, Redis task queues have higher performance, better data persistence, and more functional options, and are suitable for scenarios that require efficient, reliable, and flexible task scheduling systems.

[0050] For step S102, this solution sets up a server cluster, and there are multiple servers under the cluster. After the data cache construction task is placed in the Reids task queue, multiple servers under the server cluster are attempted to be locked through distributed locks. If the lock is successful, it means that the server can execute the data cache construction task. If the lock fails, it means that other servers are currently executing the cache construction task and no operation is performed. The server that is successfully locked is used as the task execution server.

[0051] Through distributed locks, only one thread executes a certain code at the same time. In this solution, a thread is set for each server in advance, and the threads between different servers are independent of each other. After determining the execution task server, the thread of the execution task server can be started to pull multiple data cache construction tasks within a certain time period (for example, three minutes) from the Redis task queue, assuming that they include {task 1, task 2, task 3, task 4, task 5}.

[0052] For step S103, before executing the data cache construction task, the final state of the data has been confirmed. Therefore, the permission data queried by multiple data cache construction tasks are actually consistent. Therefore, it is only necessary to integrate and execute these data cache construction tasks once. Specifically, the permission data change tasks with the same object identifier in the multiple data cache construction tasks are integrated, and the permission data change task with the latest generation time is used as the target permission data change task for the same object identifier.

[0053] For example, in the above {task 1, task 2, task 3, task 4, task 5}, application A includes 4 users XYZQ, task 1 is to change the permissions (such as user name) of user X from X1 to X2, task 2 is to change the permissions of user Y from Y1 to Y2, task 3 is to change the permissions of user X from X1 to X3, task 4 is to change the permissions of user Q from Q1 to Q2, and task 5 is to change the permissions of user Q from Q1 to Q3.

[0054] Therefore, for user X, there are two tasks, task 1 and task 3. Task 3 is generated more recently, so the target permission data change task for user X is changed from X1 to X3. Similarly, for user Q, the target permission data change task is changed from Q1 to Q3. For user Y, there is only one task 2, and no change is required for user Z. Therefore, the final integrated target data cache construction task is {user X-changed from X1 to X3, user Y-changed from Y1 to Y2, user Z unchanged, user Q-changed from Q1 to Q3}.

[0055] By integrating multiple data cache build tasks into one target data cache build task, multiple data cache build tasks within a certain period of time only execute permission cache build once. In actual operation, permission change data does not only include the above example values, but may be a more complex string or include multiple pieces of information. Therefore, to execute the target data cache build task, permission change data needs to be pulled from the database.

[0056] In addition, considering that the scope of users affected by a change in a certain permission cannot be determined, in order to simplify the code logic, it is decided to use a full change. Therefore, it is necessary to perform a full permission data change operation on all users under application A. Specifically, the permission data of user X is changed from X1 to X3, and the permission data of user Y is changed from Y1 to Y2. User Z remains unchanged, and the permission data of user Q is changed from Q1 to Q3.

[0057] The method provided in the above embodiment builds a simple task queue based on Redis. When the permission data of the application user changes frequently, a data cache construction task is generated and stored in the Redis task queue for caching. When the task starts to be executed, multiple data cache construction tasks within a certain time period are pulled from the Redis task queue and integrated for execution. Only one execution can reduce the number of task executions, solves the problem of permission data update errors caused by the existing change time being too close, reduces the pressure on the system and database, and ensures the correctness of the final construction of the user permission data.

[0058] See also Figure 2 , shows a schematic flow chart of an optional permission data processing method according to an embodiment of the present invention, comprising the following steps:

[0059] S201: In response to monitoring a data permission change operation for a target application, writing the changed permission change data into a database, and generating a data cache construction task to be stored in a task queue corresponding to the target application;

[0060] S202: Lock each server in the server cluster through a distributed lock, lock the successfully locked server as a task execution server, and start the thread of the task execution server to pull multiple data cache construction tasks within a preset time period from the task queue;

[0061] S203: Integrate the multiple data cache construction tasks to obtain a target data cache construction task and execute it to pull permission change data from the database and perform a full permission data change operation on all objects under the target application;

[0062] S204: in response to monitoring that there is a new data cache construction task in the task queue, executing a waiting operation, so as to pull and process a plurality of data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached;

[0063] S205: In response to monitoring that there is no new data cache construction task in the task queue, closing the thread of the task execution server and releasing the distributed lock.

[0064] In the above embodiment, for steps S201 to S203, see Figure 1 The description shown is not repeated here.

[0065] In the above implementation, for steps S204 and S205, after the task execution server pulls the data cache construction task from the Redis task queue, new data cache construction tasks may be added. Therefore, after the task execution server completes the target data cache construction task, it is necessary to check again whether there are new tasks added to the Redis task queue.

[0066] If there is a new task in the Redis task queue, it is determined whether the execution time point has been reached. For example, taking the aforementioned three minutes as an example, three minutes is a cycle. After the task execution server completes a data cache construction task within three minutes, it monitors that a new task has been added to the Redis task queue, and then executes a waiting operation until the next three-minute execution time point (i.e., the three-minute deadline) is reached, and the data cache construction task within the next three minutes is processed to build the permission cache again.

[0067] However, if there is no new task in the Redis task queue, the thread of the task server will be closed, and the distributed lock operation will be released, waiting for the next data permission building task to be triggered.

[0068] The method provided in the above embodiment avoids frequent locking and releasing of locks. After the current server is locked, even if the current task is executed, the lock is only allowed to be released if no new task is added to the task queue. Otherwise, it can only wait.

[0069] See also Figure 3 , shows a schematic flow chart of a specific permission data processing method according to an embodiment of the present invention, comprising the following steps:

[0070] S301: In response to monitoring a data permission change operation for a target application, write the changed permission change data into a database, and generate a data cache construction task to be stored in a task queue corresponding to the target application; wherein the data cache construction task includes an object identifier and a permission data change task;

[0071] S302: Lock each server in the server cluster through a distributed lock, lock the successfully locked server as a task execution server, and start the thread of the task execution server to pull multiple data cache construction tasks within a preset time period from the task queue;

[0072] S303: Integrate the permission data change tasks with the same object identifier in the multiple data cache construction tasks, and use the permission data change task with the latest generation time as the target permission data change task with the same object identifier, thereby obtaining the target data cache construction task;

[0073] S304: executing a target data cache construction task to pull permission change data from a database and perform a full permission data change operation on all objects under the target application;

[0074] S305: In response to monitoring that there is a new data cache construction task in the task queue, executing a waiting operation, so as to pull and process multiple data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached;

[0075] S306: In response to monitoring that there is no new data cache construction task in the task queue, closing the thread of the task execution server and releasing the distributed lock.

[0076] In the above implementation, the database may store permission data of different users under different applications. To facilitate data rollback, permission change data sets may be set for different user IDs. Considering that the user IDs under different applications may be the same, the user permission change data in the database can be partitioned according to the application ID. Each partition only stores the user permission change data set under its application, and each permission change data set stores multiple permission change data of the user ID. However, some applications may not require a rollback operation, so only the permission data corresponding to the user ID in the partition can be replaced with the modified permission change data, such as replacing the permission data corresponding to user X from X1 to X3.

[0077] See also Figure 4 , which shows a schematic diagram of main modules of a permission data processing device 400 provided in an embodiment of the present invention, including:

[0078] The task generation module 401 is used to respond to monitoring the data permission change operation for the target application, write the changed permission change data into the database, and generate a data cache construction task to store it in the task queue corresponding to the target application;

[0079] The task pulling module 402 is used to lock each server in the server cluster through a distributed lock, lock the successfully locked server as a task execution server, and start the thread of the task execution server to pull multiple data cache construction tasks within a preset time period from the task queue;

[0080] The task integration execution module 403 is used to integrate the multiple data cache construction tasks, obtain the target data cache construction task and execute it, so as to pull the permission change data from the database and perform a full permission data change operation on all objects under the target application.

[0081] The implementation device of the present invention also includes a task re-execution module, which is used to:

[0082] In response to monitoring that there is a new data cache construction task in the task queue, a waiting operation is performed to pull and process multiple data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached;

[0083] In response to monitoring that there is no new data cache construction task in the task queue, the thread of the task execution server is closed and the distributed lock is released.

[0084] In the implementation device of the present invention, the data cache construction task includes object identification and permission data change tasks, and the task integration execution module 403 is used to:

[0085] The permission data change tasks with the same object identifier in the multiple data cache construction tasks are integrated, and the permission data change task with the latest generation time is used as the target permission data change task with the same object identifier.

[0086] In the implementation device of the present invention, the task generation module 401 is used to:

[0087] Writing multiple permission change data of the same object identifier into the permission change data set corresponding to the same object identifier in the database in chronological order; or

[0088] The original authority data corresponding to the same object identifier in the database is replaced with the modified authority change data corresponding to the same object identifier.

[0089] In addition, the specific implementation content of the device described in the embodiment of the present invention has been described in detail in the method described above, so the repeated content will not be described again here.

[0090] Figure 5 An exemplary system architecture 500 to which embodiments of the present invention may be applied is shown, including terminal devices 501 , 502 , 503 , a network 504 and a server 505 (only an example).

[0091] Terminal devices 501, 502, 503 can be various electronic devices with display screens and supporting web browsing, and various communication client applications are installed. Users can use terminal devices 501, 502, 503 to interact with server 505 through network 504 to receive or send messages, etc.

[0092] The network 504 is used to provide a medium for communication links between the terminal devices 501, 502, 503 and the server 505. The network 504 may include various connection types, such as wired, wireless communication links or optical fiber cables.

[0093] The server 505 may be a server that provides various services. It should be noted that the method provided in the embodiment of the present invention is generally executed by the server 505 , and accordingly, the device is generally set in the server 505 .

[0094] It should be understood that Figure 5 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.

[0095] Reference below Figure 6 , which shows a schematic diagram of the structure of a computer system 600 of a terminal device suitable for implementing an embodiment of the present invention. Figure 6The terminal device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0096] like Figure 6 As shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage part 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the system 600 are also stored. The CPU 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0097] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed, so that a computer program read therefrom is installed into the storage section 608 as needed.

[0098] In particular, according to the embodiments disclosed in the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above-mentioned functions defined in the system of the present invention are executed.

[0099] It should be noted that the computer-readable medium shown in the present invention may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present invention, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0100] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present invention. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0101] The modules involved in the embodiments of the present invention may be implemented by software or hardware. The modules described may also be set in a processor, for example, it may be described as: a processor includes a task generation module, a task pull module, and a task integration execution module. The names of these modules do not constitute a limitation on the modules themselves in some cases, for example, the task pull module may also be described as a "server determination module".

[0102] As another aspect, the present invention further provides a computer-readable medium, which may be included in the device described in the above embodiment; or may exist independently without being assembled into the device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by a device, the device executes any of the above-mentioned permission data processing methods.

[0103] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions may occur depending on design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for processing authority data, characterized in that: include: In response to monitoring a data permission change operation for a target application, writing the changed permission change data into a database, and generating a data cache building task to be stored in a task queue corresponding to the target application; Each server in the server cluster is locked by a distributed lock, and the successfully locked server is locked as a task execution server, and the thread of the task execution server is started to pull multiple data cache construction tasks within a preset time period from the task queue; The multiple data cache construction tasks are integrated and processed to obtain a target data cache construction task and execute it to pull permission change data from the database and perform a full permission data change operation on all objects under the target application.

2. The method according to claim 1, characterized in that After performing a full permission data change operation on all objects under the target application, the method further includes: In response to monitoring that there is a new data cache construction task in the task queue, a waiting operation is performed to pull and process multiple data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached; In response to monitoring that there is no new data cache construction task in the task queue, the thread of the task execution server is closed and the distributed lock is released.

3. The method according to claim 1 or 2, characterized in that: The data cache construction task includes object identification and permission data change tasks. The integration of multiple data cache construction tasks includes: The permission data change tasks with the same object identifier in the multiple data cache construction tasks are integrated, and the permission data change task with the latest generation time is used as the target permission data change task with the same object identifier.

4. The method according to claim 1, characterized in that: The step of writing the changed permission change data into the database includes: Writing multiple permission change data of the same object identifier into the permission change data set corresponding to the same object identifier in the database in chronological order; or The original authority data corresponding to the same object identifier in the database is replaced with the modified authority change data corresponding to the same object identifier.

5. A rights data processing device, characterized in that: include: A task generation module, configured to respond to monitoring a data permission change operation for a target application, write the changed permission change data into a database, and generate a data cache construction task to be stored in a task queue corresponding to the target application; The task pulling module is used to lock each server in the server cluster through a distributed lock, lock the successfully locked server as a task execution server, and start the thread of the task execution server to pull multiple data cache construction tasks within a preset time period from the task queue; The task integration execution module is used to integrate the multiple data cache construction tasks, obtain the target data cache construction task and execute it, so as to pull the permission change data from the database and perform a full permission data change operation on all objects under the target application.

6. The device according to claim 5, characterized in that The device also includes a task re-execution module, which is used to: In response to monitoring that there is a new data cache construction task in the task queue, a waiting operation is performed to pull and process multiple data cache construction tasks within the preset time period from the task queue when a deadline of the next preset time period is reached; In response to monitoring that there is no new data cache construction task in the task queue, the thread of the task execution server is closed and the distributed lock is released.

7. The device according to claim 5 or 6, characterized in that The data cache construction task includes object identification and permission data change tasks, and the task integration execution module is used to: The permission data change tasks with the same object identifier in the multiple data cache construction tasks are integrated, and the permission data change task with the latest generation time is used as the target permission data change task with the same object identifier.

8. The device according to claim 5, characterized in that The task generation module is used to: Writing multiple permission change data of the same object identifier into the permission change data set corresponding to the same object identifier in the database in chronological order; or The original authority data corresponding to the same object identifier in the database is replaced with the modified authority change data corresponding to the same object identifier.

9. An electronic device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.

10. A computer readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.