Authority control method and system based on cloud platform

By implementing a two-level service product permission control method on the cloud platform, the personalized needs and fine-grained control problems of cloud platform when managing user access and permission control are solved, and effective permission management and security guarantees for cloud platform services are achieved.

CN119989308APending Publication Date: 2025-05-13SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510039381.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When cloud platforms manage and control access and management of cloud resources by different users, it is difficult to meet personalized needs, and the existing permission control methods lack fine-grainedness, making it difficult to effectively prevent unauthorized access.

Method used

The two-level service product permission control method based on the cloud platform is adopted to control the service products that users can access through the first-level service product permissions, and fine-grained control of menus and buttons at all levels of service product through the second-level service product permissions to ensure that users can only access and perform operations authorized by the administrator.

Benefits of technology

It realizes fine-grained permission control over cloud platform services, ensures that only authorized users can access and use cloud platform services, protects sensitive information from being leaked, simplifies the user management process, and supports the customization and scalability requirements of cloud platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989308A_ABST
    Figure CN119989308A_ABST
Patent Text Reader

Abstract

The invention provides an authority control method and system based on a cloud platform. For each user, two levels of service product permissions are set on the cloud platform; displaying the service list of each service product to the first user; and when a first user accesses a first service product in the service list, judging whether the first user has the authority of accessing the first service product according to the first-level service product authority corresponding to the first user, if so, displaying a page comprising the first service product to the first user, and if not, displaying the first service product to the first user. Returning tree structure data according to the second-level service product authority corresponding to the first user; and when the first user clicks a menu or a button on the page of the first service product, judging whether the first user has an access permission according to the tree structure data, and if so, executing a corresponding operation. According to the invention, more effective authority control can be carried out for different users, so that individual requirements of different users are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present invention relate to network communication technology, and in particular, to a permission control method and system based on a cloud platform. Background Art

[0002] As more and more applications and services are deployed by enterprises or individuals on cloud platforms, the management of cloud resources becomes increasingly complex. At the same time, different users may have different needs and management methods for cloud resources. Therefore, the cloud services provided by cloud platforms to users need to be customized and scalable to meet the personalized needs of different users.

[0003] Therefore, it is necessary to perform personalized permission control for different users based on the cloud platform in order to meet the personalized needs of different users. Summary of the invention

[0004] One or more embodiments of the present invention describe a cloud platform-based permission control method and system, which can perform more effective permission control for different users, thereby meeting the personalized needs of different users.

[0005] According to a first aspect, a permission control method based on a cloud platform is provided, the method comprising:

[0006] For each user, two levels of service product permissions that the user can access are set on the cloud platform; the first level of service product permissions include: permissions to at least one service product that the user is allowed to access; the second level of service product permissions include: permissions to menus at all levels of service products under a service product that the user is allowed to access and button permissions for service products;

[0007] When the first user logs in to access the cloud platform, a service list of each service product is displayed to the first user;

[0008] When a first user accesses a first service product in the service list, the access is intercepted, and it is determined whether the first user has permission to access the first service product according to the first-level service product permission corresponding to the first user. If yes, tree structure data is returned according to the second-level service product permission corresponding to the first user, and the tree structure data only includes menu data of the first service product to which the first user has access permission and button data of the first service product to which the first user has access permission, and the first service product page including menu and button permissions in the tree structure data is displayed to the user;

[0009] When the first user clicks a menu or a button on the first service product page, judging whether the first user has access rights according to the tree structure data, and if so, performing a corresponding operation, and if not, denying the first user access;

[0010] When the first user directly enters the service address in the browser to access, it is determined whether the service address corresponds to at least one service product that the user is allowed to access according to the first-level service product authority. If yes, the access is performed; otherwise, the access is intercepted and denied;

[0011] When the first user directly enters the menu page address in the browser, it is determined based on the first-level service product permissions and the second-level service product permissions whether the menu page address corresponds to at least one service product that the user is allowed to access but does not correspond to a menu that the user is allowed to access. If so, it is intercepted and access is denied.

[0012] The method further includes: setting a permission relationship between at least one of a service product, a menu, a button, and an operation and a service product interface on the cloud platform, the permission relationship reflecting whether the service product interface is allowed to be called;

[0013] After displaying the first service product page to the first user, it further includes: when the first user calls an interface through at least one of the service products, menus, buttons and operations in the page, judging whether the first user is allowed to call the interface according to the permission relationship; if so, executing the interface calling operation; if not, rejecting the first user's calling request.

[0014] The data of the service product includes: a unique ID of the service product, a service product type, a default path, and at least one of an interface list;

[0015] and / or,

[0016] The menu data includes: at least one of a unique ID, a service product ID, a menu name, a menu page path, a parent menu, and an interface list;

[0017] and / or,

[0018] The button data includes at least one of a unique ID, a menu ID, and an interface list.

[0019] The method includes: when the first user visits the first service product page, the front-end framework executes the "when the first user clicks a menu or a button on the page of the first service product, judging whether the first user has access rights according to the tree structure data" through the routing guard configuration.

[0020] According to the second aspect, a cloud platform-based permission control system is provided, the system comprising: a service catalog unified management module, a permission management module, a service product management module and a front-end framework module; wherein,

[0021] A unified service catalog management module is used to manage various service products, maintain the names of service products, addresses of service products, menu names of service products, menu addresses, menu button names, and menu button operations; and, when a first user logs in to access the cloud platform, display a service list of each service product to the first user;

[0022] The permission management module is used to set two levels of service product permissions that the user can access for each user; wherein the first level service product permissions include: permissions for at least one service product that the user is allowed to access; the second level service product permissions include: permissions for menus of service products at all levels under a service product that the user is allowed to access and button permissions for service products; when receiving an authentication request, judging whether the first user has permission to access the first service product according to the first level service product permissions corresponding to the first user, if yes, returning tree structure data according to the second level service product permissions corresponding to the first user, the tree structure data only including menu data of the first service product that the first user has access rights to and button data of the first service product that the first user has access rights to, and displaying the menu data included in the tree structure data to the first user through the front-end framework module a first service product page with menu and button permissions; when the first user clicks a menu or a button on the first service product page, judging whether the first user has access permissions according to the tree structure data, and if so, executing the corresponding operation, and if not, denying the first user's access; when the first user directly enters the service address in the browser for access, judging whether the service address corresponds to at least one service product that the user is allowed to access according to the first-level service product permissions, and if so, executing the access, otherwise intercepting and denying the access; when the first user directly enters the menu page address in the browser, judging whether the menu page address corresponds to at least one service product that the user is allowed to access but does not correspond to the menu that the user is allowed to access according to the first-level service product permissions and the second-level service product permissions, and if so, intercepting and denying the access;

[0023] A service product management module, used to maintain at least one of the following information: product name, product address, product menu name, product menu address, product button name, product button operation, and product interface list of the service product, and register the maintained information with the service catalog unified management module when the application of the service product is started;

[0024] The front-end framework module is used to intercept the access when the first user accesses the first service product in the service list, and request authentication from the authority management module.

[0025] The permission management module is further used to set a permission relationship between at least one of a service product, a menu, a button, and an operation and a service product interface, and the permission relationship reflects whether the service product interface is allowed to be called;

[0026] After the permission management module displays the first service product page to the first user, when the first user calls an interface through at least one of the service products, menus, buttons and operations in the page, the permission management module determines whether the first user is allowed to call the interface based on the permission relationship. If yes, the interface calling operation is executed; if not, the first user's calling request is rejected.

[0027] The data of the service product includes: a unique ID of the service product, a service product type, a default path, and at least one of an interface list;

[0028] and / or,

[0029] The menu data includes: at least one of a unique ID, a service product ID, a menu name, a menu page path, a parent menu, and an interface list;

[0030] and / or,

[0031] The button data includes at least one of a unique ID, a menu ID, and an interface list.

[0032] When the first user visits the first service product page, the front-end framework module triggers the permission management module through the routing guard configuration to execute the "when the first user clicks a menu or a button on the page of the first service product, determine whether the first user has access rights based on the tree structure data."

[0033] The service catalog unified management module and the authority management module are arranged in the cloud platform;

[0034] The service product management module and the front-end framework module are arranged in each service product.

[0035] According to a third aspect, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in any embodiment of the present invention is implemented.

[0036] The cloud platform-based permission control method and system provided by the embodiments of the present invention have the following beneficial effects:

[0037] 1. Two levels of service product permissions are set. Through the first level of service product permissions, the cloud platform can control the service products that users can access, for example, different users are allowed to access different service products; through the second level of service product permissions, more fine-grained permission control can be achieved. The cloud platform can control the menus and buttons of service products under a service product that users are allowed to access, and achieve menu and button-level permission control. Therefore, for accessible products, users can only view and execute product operation buttons or product menus opened by administrators, thereby meeting the customization and scalability requirements of cloud services opened by the cloud platform.

[0038] 2. In the embodiments of the present invention, fine-grained permission control is used to ensure that only authorized users can access services on the cloud platform, preventing unauthorized access; at the same time, data permission control ensures that users can only access and execute authorized service products and operations, protecting sensitive information from being leaked. For the cloud platform itself, by centrally managing user permissions, cloud platform administrators can more easily add, modify, and delete users and their permissions, thereby simplifying the user management process; through fine-grained permission control, permission control policies can be flexibly adjusted according to user and business conditions to adapt to different application scenarios and user groups. With the development of the cloud platform and the expansion of the service catalog, the fine-grained permission control system can be easily expanded to accommodate new services and users. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0040] Figure 1 It is a schematic diagram of a system architecture applied in one embodiment of the present invention.

[0041] Figure 2 It is a flow chart of a cloud platform-based permission control method in one embodiment of the present invention.

[0042] Figure 3 It is a structural diagram of a cloud platform-based authority control system in one embodiment of the present invention.

[0043] Figure 4 It is a flow chart of service product rights management in one embodiment of the present invention.

[0044] Figure 5 The flowchart is a flowchart of the permission control for user access to the service directory in one embodiment of the present invention. DETAILED DESCRIPTION

[0045] The solution provided by the present invention is described below in conjunction with the accompanying drawings.

[0046] First of all, it should be noted that the terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "the" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates otherwise.

[0047] It should be understood that the term "and / or" used in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0048] In order to facilitate understanding of the method provided by the present invention, the system architecture involved and applicable to the present invention is first described. Figure 1 As shown in , the system includes a cloud platform and multiple product services, wherein the cloud platform controls when providing service products to users and provides respective permission controls for each service product.

[0049] It should be understood that Figure 1 The number of cloud platforms and service products in the figure is only for reference. Any number can be selected and deployed according to the implementation requirements.

[0050] Figure 2 FIG. 1 is a flowchart of a cloud platform-based permission control method in one embodiment of the present invention. Figure 1 and Figure 2 , the method comprising:

[0051] Step 201: For each user, two levels of service product permissions that the user can access are pre-set on the cloud platform; wherein the first level of service product permissions include: permissions to at least one service product that the user is allowed to access; the second level of service product permissions include: permissions to service product menus at all levels under a service product that the user is allowed to access and button permissions for service products.

[0052] Step 203: When the first user logs in to access the cloud platform, a service list of each service product is displayed to the first user.

[0053] For example, only the service list of each service product to which the first user has access rights is displayed to the first user.

[0054] Step 205: When the first user accesses the first service product in the service list, the access is intercepted.

[0055] Step 207: Determine whether the first user has the permission to access the first service product according to the first-level service product permission corresponding to the first user. If yes, execute step 211; if no, execute step 209.

[0056] Step 209: Deny the first user's access and end the current process.

[0057] Step 211: Return tree structure data based on the second-level service product permissions corresponding to the first user, the tree structure data only including menu data of the first service product to which the first user has access rights and button data of the first service product to which the first user has access rights, and display the first service product page containing menu and button permissions in the tree structure data to the first user.

[0058] Step 213: When the first user clicks a menu or a button on the first service product page, it is determined whether the first user has access rights based on the tree structure data. If so, step 215 is executed; otherwise, step 209 is executed.

[0059] Step 215: Execute corresponding operations.

[0060] Step 217: When the first user directly enters the service address in the browser for access, it is determined based on the first-level service product permissions whether the service address corresponds to at least one service product that the user is allowed to access. If so, the access is executed; otherwise, the access is intercepted and denied.

[0061] Step 219: When the first user directly enters the menu page address in the browser, based on the first-level service product permissions and the second-level service product permissions, determine whether the menu page address corresponds to at least one service product that the user is allowed to access but does not correspond to a menu that the user is allowed to access. If so, intercept and deny access.

[0062] According to the above Figure 2 It can be seen from the process shown that in the embodiment of the present invention, two levels of service product permissions are set. Through the first level of service product permissions, the cloud platform can control the service products that users are allowed to access, for example, different users are allowed to access different service products; through the second level of service product permissions, more fine-grained permission control can be achieved. The cloud platform can control the menus of service products at all levels and buttons of service products under a service product that users can access, and implement menu and button level permission control. Therefore, for accessible products, users can only view and execute product operation buttons or operation menus opened for them by the administrator, thereby meeting the customization and scalability requirements of cloud services opened by the cloud platform.

[0063] Moreover, in the embodiment of the present invention, when the user does not go through the service platform but directly enters the service address and the menu page address in the browser, access control can also be performed according to the above-mentioned two-level service product permissions, thereby further meeting the customization and scalability requirements of the cloud services opened by the cloud platform.

[0064] In the embodiment of the present invention, through fine-grained permission control, it is ensured that only authorized users can access the services on the cloud platform, preventing unauthorized access; at the same time, data permission control ensures that users can only access and execute authorized service products and operations, protecting sensitive information from being leaked. For the cloud platform itself, by centrally managing user permissions, administrators of the cloud platform can more easily add, modify, and delete users and their permissions, thereby simplifying the user management process; through fine-grained permission control, permission control policies can be flexibly adjusted according to user and business conditions to adapt to different application scenarios and user groups. With the development of the cloud platform and the expansion of the service catalog, the fine-grained permission control system can be easily expanded to adapt to new services and users.

[0065] In one embodiment of the present invention, two types of relationships can be maintained: one is the permission relationship between users and products, menus, buttons, and operations, including read-only, read-write, and no permission; the other is the relationship between products, menus, buttons, operations, and product interfaces. Figure 2 The process shown reflects the above relationship 1. For the above relationship 2, the method further includes: Step 200: setting a permission relationship between at least one of a service product, menu, button and operation and a service product interface on the cloud platform, the permission relationship reflecting whether the service product interface is allowed to be called;

[0066] After the first service product page is displayed to the first user in step 211, the permission control method based on the cloud platform may further include:

[0067] Step 212: When the first user calls an interface through at least one of the service products, menus, buttons and operations in the page, determine whether the first user is allowed to call the interface based on the permission relationship. If yes, execute the interface calling operation; if not, reject the first user's calling request.

[0068] By executing the above steps 200 and 212, the permission relationship between products, menus, buttons, operations and product interfaces can be further controlled. Only authorized products, menus, buttons and operations can call related product interfaces, further increasing the flexibility, scalability and personalization of permission control.

[0069] In an embodiment of the present invention, the data of the service product includes: at least one of a unique ID of the service product, a service product type, a default path, and an interface list.

[0070] In an embodiment of the present invention, the menu data includes at least one of a unique ID, a service product ID, a menu name, a menu page path, a parent menu, and an interface list.

[0071] In an embodiment of the present invention, the button data includes at least one of a unique ID, a menu ID, and an interface list.

[0072] In an embodiment of the present invention, when a first user visits a first service product page, the front-end framework executes the "returning tree structure data according to the second-level service product permissions corresponding to the first user, the tree structure data only containing menu data of the first service product to which the first user has access rights and button data of the first service product to which the first user has access rights, and displaying the first service product page containing menu and button permissions in the tree structure data to the user" through the routing guard configuration, and "when the first user clicks on a menu or a button on the page of the first service product, judging whether the first user has access rights based on the tree structure data".

[0073] In the embodiment of the present invention, the administrator account is used to set the service product permissions that users can access on a unified cloud platform, and the functions of users accessing the product can be controlled in a fine-grained manner, such as page viewing permissions, button operation permissions, etc. When a user logs in to access the cloud platform, he can only see the service product list that the administrator has opened access permissions for him from the service list; when the user accesses other products through browser input, it will be prompted that he has no permission to access; for accessible products, the user can only view and execute the product menus and operation buttons opened by the administrator for him. The customization and scalability requirements of the cloud platform are met.

[0074] One embodiment of the present invention also proposes a cloud platform-based permission control system, see Figure 3 The system includes: a service catalog unified management module 301, a rights management module 302, a service product management module 303 and a front-end framework module 304; wherein,

[0075] The service catalog unified management module 301 is used to manage various service products, maintain the names of service products, addresses of service products, menu names of service products, menu addresses, menu button names, and menu button operations; and, when the first user logs in to access the cloud platform, display the service list of each service product to the first user;

[0076] The permission management module 302 is used to set two levels of service product permissions that the user can access for each user; wherein the first level service product permissions include: permissions for at least one service product that the user is allowed to access; the second level service product permissions include: permissions for service product menus at all levels and button permissions for service products under a service product that the user is allowed to access; when an authentication request is received, it is determined whether the first user has the permission to access the first service product based on the first level service product permissions corresponding to the first user. If yes, tree structure data is returned based on the second level service product permissions corresponding to the first user, and the tree structure data only includes menu data of the first service product that the first user has access rights to and button data of the first service product that the first user has access rights to, and the menus and buttons included in the tree structure data are displayed to the first user through the front-end framework module 304. the first service product page with permissions; when the first user clicks a menu or a button on the first service product page, judging whether the first user has access rights according to the tree structure data, and if so, executing the corresponding operation, and if not, denying the first user's access; the permission management module 302 is also used for judging whether the service address corresponds to at least one service product that the user is allowed to access according to the first-level service product permissions when the first user directly enters the service address in the browser for access, and if so, executing the access, otherwise intercepting and denying the access; when the first user directly enters the menu page address in the browser, judging whether the menu page address corresponds to at least one service product that the user is allowed to access but does not correspond to the menu that the user is allowed to access according to the first-level service product permissions and the second-level service product permissions, and if so, intercepting and denying the access;

[0077] The service product management module 303 is used to maintain at least one of the following information: product name, product address, product menu name, product menu address, product button name, product button operation, and product interface list of the service product, and register the maintained information with the service catalog unified management module 301 when the application of the service product is started;

[0078] The front-end framework module 304 is used to intercept the access when the first user accesses the first service product in the service list, and request authentication from the authority management module 302 .

[0079] In one embodiment of the system of the present invention, the permission management module 302 is further used to set a permission relationship between at least one of a service product, a menu, a button, and an operation and a service product interface, and the permission relationship reflects whether the service product interface is allowed to be called;

[0080] After the permission management module 302 displays the first service product page to the first user, when the first user calls an interface through at least one of the service products, menus, buttons and operations in the page, it determines whether the first user is allowed to call the interface based on the permission relationship. If yes, the interface calling operation is executed; if not, the calling request of the first user is rejected.

[0081] In one embodiment of the system of the present invention, when the first user visits the first service product page, the front-end framework module 304 triggers the permission management module 302 through the routing guard configuration to execute the "return tree structure data according to the second-level service product permissions corresponding to the first user, the tree structure data only contains menu data of the first service product to which the first user has access rights and button data of the first service product to which the first user has access rights, and the first service product page containing menu and button permissions in the tree structure data is displayed to the first user through the front-end framework module 304" and "when the first user clicks on a menu or a button on the page of the first service product, determine whether the first user has access rights based on the tree structure data."

[0082] In one embodiment of the system of the present invention, the service catalog unified management module 301 and the rights management module 302 are set in the cloud platform;

[0083] The service product management module 303 and the front-end framework module 304 are provided in each service product.

[0084] In another embodiment of the system of the present invention, the following modules are included:

[0085] 1. Unified management module for service catalog: This module mainly manages the name of service products, the address of service products, the menu name of service products, menu address, menu button name, menu button operation and other information. The data requirements for this module are as follows:

[0086] Service product data: including unique ID, product type, default path, interface list and other information;

[0087] Menu data: contains unique ID, product ID, menu name, menu page path, parent menu, interface list and other information;

[0088] For button data: contains unique ID, menu ID, interface list and other information;

[0089] 2. Permission management module: This module maintains two types of relationships: one is the permission relationship between users and products, menus, buttons, and operations, including read-only, read-write, and no permission; the other is the relationship between products, menus, buttons, operations, and product interfaces;

[0090] 3. Front-end framework module: This module maintains the name, menu and other information of service products by defining routing guards. In addition, it intercepts requests when users access URLs and sends authentication requests to the service catalog unified management module. The data requirements of this module are as follows:

[0091] Menu path, ID of the product to which the menu belongs, type of product to which the menu belongs, name of the authentication method

[0092] 4. Product management module: This module has two main functions. One is to maintain the product name, address, menu, button and other information through MOCK data, and automatically register with the service directory unified management module when the product application is started; the other is to intercept service requests and send authentication requests to the permission management module.

[0093] See also Figure 4 , service product permission management is as follows:

[0094] 1. The service product backend introduces a product management module, and maintains information such as product name, product address, product menu name, product menu address, product button name, product button operation, product interface list, etc. in the product management module. When the product application is started, the module automatically registers with the service catalog unified management module;

[0095] 2. The service catalog unified management module records product-related information and sends permission data to the permission management module;

[0096] 3. When the administrator authorizes the user to have access to the service catalog, the administrator selects the relevant products and their menus, buttons and interfaces through the unified management module of the service catalog for fine-grained authorization;

[0097] 4. When a user visits the service product page, the front-end framework module intercepts the browser URL request and sends an authentication request to the service catalog unified management module.

[0098] See also Figure 5 In another embodiment of the present invention, the permission control method based on the cloud platform includes:

[0099] Step 1: After the user logs in to the system, query the list of service products owned by the user and enter the unified user console page.

[0100] Step 2: Select a service product from the service catalog list to access. The front-end framework intercepts the browser URL and queries the back-end whether the user has the authority to access the product. If the user has the authority, the tree structure data of the menu, button and other information of the product owned by the user will be returned; if the user does not have the authority, the user will be directly redirected to the 403 page. This step is also followed when the user directly enters the product URL in the browser. The tree structure data only contains the menu and button data that the user has the authority to access.

[0101] Step 3: After authentication in step 2, the front-end framework parses the tree structure data returned by the back-end and loads the corresponding menu page and button to display the product.

[0102] Step 4: Click other menus or buttons of the product to perform a second check on the menu or button permissions; when accessing the menu, call the backend for authentication based on the menu path and authentication method recorded in the routing guard. If there is permission, return the corresponding tree data and load it for display. If there is no permission, jump to the 403 page again; when accessing the button, if it is to open a new page, check whether you have the permission to the product page according to step 2. If it is a request for the backend interface, the product management module on the backend will intercept and check whether the user has the permission, and then decide whether to execute the relevant interface.

[0103] It can be seen that each embodiment of the present invention has the following beneficial effects:

[0104] 1. Improve security. Prevent unauthorized access, protect sensitive operations from being executed, and key data from being leaked or abused. Through fine-grained permission control, ensure that only authorized users can access services on the cloud platform to prevent unauthorized access; at the same time, data permission control ensures that users can only access and execute authorized service products and operations, protecting sensitive information from being leaked.

[0105] 2. Enhance manageability and ease of use. By centrally managing user permissions, cloud platform administrators can more easily add, modify, and delete users and their permissions, thereby simplifying the user management process.

[0106] 3. Enhanced flexibility and scalability. Through fine-grained permission control, permission control policies can be flexibly adjusted according to user and business conditions to adapt to different application scenarios and user groups. With the development of cloud platforms and the expansion of service catalogs, fine-grained permission control systems can be easily expanded to adapt to new services and users.

[0107] An embodiment of the present invention provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute a method in any one of the embodiments in the specification.

[0108] An embodiment of the present invention provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method in any embodiment of the specification is implemented.

[0109] It is to be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the device of the embodiment of the present invention. In other embodiments of the specification, the above-mentioned device may include more or fewer components than those shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0110] The various embodiments of the present invention are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0111] Those skilled in the art should be aware that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, widgets, or any combination thereof. When implemented by software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0112] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.

Claims

1. A permission control method based on a cloud platform, characterized in that: The method includes: For each user, two levels of service product permissions that the user can access are set on the cloud platform; the first level of service product permissions include: permissions to at least one service product that the user is allowed to access; the second level of service product permissions include: permissions to menus at all levels of service products under a service product that the user is allowed to access and button permissions for service products; When the first user logs in to access the cloud platform, a service list of each service product is displayed to the first user; When a first user accesses a first service product in the service list, the access is intercepted, and it is determined whether the first user has permission to access the first service product according to the first-level service product permission corresponding to the first user. If yes, tree structure data is returned according to the second-level service product permission corresponding to the first user, and the tree structure data only includes menu data of the first service product to which the first user has permission to access and button data of the first service product to which the first user has permission to access, and the first service product page including menu and button permissions in the tree structure data is displayed to the first user; When the first user clicks a menu or a button on the first service product page, judging whether the first user has access rights according to the tree structure data, and if so, performing a corresponding operation, and if not, denying the first user access; When the first user directly enters the service address in the browser to access, it is determined whether the service address corresponds to at least one service product that the user is allowed to access according to the first-level service product authority. If yes, the access is performed; otherwise, the access is intercepted and denied; When the first user directly enters the menu page address in the browser, it is determined based on the first-level service product permissions and the second-level service product permissions whether the menu page address corresponds to at least one service product that the user is allowed to access but does not correspond to a menu that the user is allowed to access. If so, it is intercepted and access is denied.

2. The method according to claim 1, characterized in that The method further includes: setting a permission relationship between at least one of a service product, a menu, a button, and an operation and a service product interface on the cloud platform, the permission relationship reflecting whether the service product interface is allowed to be called; After displaying the first service product page to the first user, it further includes: when the first user calls an interface through at least one of the service products, menus, buttons and operations in the page, judging whether the first user is allowed to call the interface according to the permission relationship; if so, executing the interface calling operation; if not, rejecting the first user's calling request.

3. The method according to claim 1, characterized in that The data of the service product includes: a unique ID of the service product, a service product type, a default path, and at least one of an interface list; and / or, The menu data includes: at least one of a unique ID, a service product ID, a menu name, a menu page path, a parent menu, and an interface list; and / or, The button data includes at least one of a unique ID, a menu ID, and an interface list.

4. The method according to claim 1, characterized in that The method includes: when the first user visits the first service product page, the front-end framework executes the "returning tree structure data according to the second-level service product permissions corresponding to the first user, the tree structure data only contains menu data of the first service product to which the first user has access rights and button data of the first service product to which the first user has access rights, and displaying the first service product page containing menu and button permissions in the tree structure data to the first user" and "when the first user clicks on a menu or a button on the page of the first service product, judging whether the first user has access rights according to the tree structure data" through the routing guard configuration.

5. The permission control system based on the cloud platform is characterized by: The system includes: a service catalog unified management module, a rights management module, a service product management module and a front-end framework module; A unified service catalog management module is used to manage various service products, maintain the names of service products, addresses of service products, menu names of service products, menu addresses, menu button names, and menu button operations; and, when a first user logs in to access the cloud platform, display a service list of each service product to the first user; The permission management module is used to set two levels of service product permissions that the user can access for each user; wherein the first level service product permissions include: permissions for at least one service product that the user is allowed to access; the second level service product permissions include: permissions for menus of service products at all levels under a service product that the user is allowed to access and button permissions for service products; when receiving an authentication request, judging whether the first user has permission to access the first service product according to the first level service product permissions corresponding to the first user, if yes, returning tree structure data according to the second level service product permissions corresponding to the first user, the tree structure data only including menu data of the first service product that the first user has access rights to and button data of the first service product that the first user has access rights to, and displaying the menu data included in the tree structure data to the first user through the front-end framework module a first service product page with menu and button permissions; when the first user clicks a menu or a button on the first service product page, judging whether the first user has access permissions according to the tree structure data, and if so, executing the corresponding operation, and if not, denying the first user's access; when the first user directly enters the service address in the browser for access, judging whether the service address corresponds to at least one service product that the user is allowed to access according to the first-level service product permissions, and if so, executing the access, otherwise intercepting and denying the access; when the first user directly enters the menu page address in the browser, judging whether the menu page address corresponds to at least one service product that the user is allowed to access but does not correspond to the menu that the user is allowed to access according to the first-level service product permissions and the second-level service product permissions, and if so, intercepting and denying the access; A service product management module, used to maintain at least one of the following information: product name, product address, product menu name, product menu address, product button name, product button operation, and product interface list of the service product, and register the maintained information with the service catalog unified management module when the application of the service product is started; The front-end framework module is used to intercept the access when the first user accesses the first service product in the service list, and request authentication from the authority management module.

6. The system according to claim 5, characterized in that The permission management module is further used to set a permission relationship between at least one of a service product, a menu, a button, and an operation and a service product interface, and the permission relationship reflects whether the service product interface is allowed to be called; After the permission management module displays the first service product page to the first user, when the first user calls an interface through at least one of the service products, menus, buttons and operations in the page, the permission management module determines whether the first user is allowed to call the interface based on the permission relationship. If yes, the interface calling operation is executed; if not, the first user's calling request is rejected.

7. The system according to claim 5, characterized in that The data of the service product includes: a unique ID of the service product, a service product type, a default path, and at least one of an interface list; and / or, The menu data includes: at least one of a unique ID, a service product ID, a menu name, a menu page path, a parent menu, and an interface list; and / or, The button data includes at least one of a unique ID, a menu ID, and an interface list.

8. The system according to claim 5, characterized in that When the first user visits the first service product page, the front-end framework module triggers the permission management module through the routing guard configuration to execute the "return tree structure data according to the second-level service product permissions corresponding to the first user, the tree structure data only contains menu data of the first service product to which the first user has access rights and button data of the first service product to which the first user has access rights, and display the first service product page containing menu and button permissions in the tree structure data to the first user through the front-end framework module" and "when the first user clicks on a menu or a button on the page of the first service product, determine whether the first user has access rights based on the tree structure data".

9. The system according to claim 5, characterized in that The service catalog unified management module and the authority management module are arranged in the cloud platform; The service product management module and the front-end framework module are arranged in each service product.

10. A computing device, comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method according to any one of claims 1 to 4 is implemented.