Permission verification method, filter, front-end server and storage medium

By setting filters between the front-end server and the back-end server, intercepting and verifying interface requests, the problem of the inability to effectively prevent users from illegally calling back-end interfaces in the existing technology is solved, and the rapid verification and unified management of interface permissions is realized, which improves the efficiency of permission control.

CN119989388AActive Publication Date: 2025-05-13SHENZHEN SMARTCITY TECH DEV GRP CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510464948.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-13
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

The prior art cannot effectively prevent users from illegally calling back-end interfaces in user function permission control, and the back-end business code is complex and scattered, making it difficult to uniformly manage and control interface permissions.

Method used

By setting filters between the front-end server and the back-end server, intercepting and verifying interface requests, determining the matching set of interface permissions for the interface request, and determining the target access permissions of the target interface based on the preset relationship between the interface and the interface access permissions. If the permissions match, sending the interface request to the back-end server.

Benefits of technology

It realizes rapid verification and unified management of interface permissions, improves the efficiency of permission control, avoids direct modification of back-end code, and reduces the risk of illegal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989388A_ABST
    Figure CN119989388A_ABST
Patent Text Reader

Abstract

The invention discloses a permission verification method, a filter, a front-end server and a storage medium, and relates to the technical field of permission control, and the permission verification method applied to the filter comprises the following steps: intercepting an interface request sent by the front-end server, the interface request is generated by the front-end server in response to a triggering operation for a target page element in the menu interface; determining an interface permission set matched with the interface request; determining a target access permission of a target interface indicated by the interface request according to a preset association relationship between the interface and the interface access permission; and under the condition that the interface permission set contains the target access permission, sending the interface request to a back-end server. According to the method and the device, the incidence relation between the interface and the interface access permission is configured outside the back-end server, so that the permission control of the back-end interface is realized, and the permission control efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of permission control, and in particular to a permission verification method, a filter, a front-end server and a storage medium. Background Art

[0002] In terms of user function permission control, it is usually based on the RBAC (Role-Based Access Control) model, which implements page function permission control through the user-role-menu association relationship. However, this solution only guarantees menu access permission control at the front-end level and cannot effectively prevent users from illegally calling the corresponding back-end interface.

[0003] In order to prevent users from making illegal calls, developers usually add permission verification code to the backend business code to verify the permissions of the backend interface. However, the backend business code is large and complex, and the permission verification logic for different backend interfaces is different. Each permission verification code is stored in each backend interface code, making it difficult for developers to uniformly manage and control interface permissions, which is inefficient. Summary of the invention

[0004] The main purpose of this application is to provide a permission verification method, filter, front-end server and storage medium, aiming to solve the technical problem of how to improve the efficiency of permission control.

[0005] To achieve the above purpose, the present application proposes a permission verification method, which is applied to a filter and includes: Intercepting an interface request sent by a front-end server, wherein the interface request is generated by the front-end server in response to a trigger operation on a target page element in a menu interface; Determine an interface permission set that matches the interface request; Determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission; In a case where the interface permission set includes the target access permission, the interface request is sent to a backend server.

[0006] In one embodiment, the method further comprises: When the backend interface of the backend server is updated, the association relationship between the interface and the interface access rights is modified according to the change of the backend interface.

[0007] In one embodiment, the step of determining the interface permission set that matches the interface request includes: Determine the role information corresponding to the interface request; The interface permission set is determined according to the role information.

[0008] In one embodiment, the step of determining the interface permission set according to the role information includes: Determine a page element permission set based on the role information; The interface permission set is determined according to the page element permission set.

[0009] In one embodiment, after the step of intercepting the interface request sent by the front-end server, the method further includes: Determine a target interface indicated by the interface request; In the case where the preset interface library does not include the target interface, processing the interface request according to a preset rule; In the case where the interface library includes the target interface, the step of determining the interface permission set of the user according to the interface request is performed.

[0010] To achieve the above purpose, the present application proposes a permission verification method, which is applied to a front-end server and includes: Displaying a menu page, wherein the menu page includes at least one page element; In response to a triggering operation on a target page element in the menu page, generating an interface request; The interface request is sent to a back-end server, wherein a filter is provided between the back-end server and the front-end server, the filter is used to intercept the interface request and determine a set of interface permissions that matches the interface request, and determine a target access permission of a target interface indicated by the interface request according to an association between a preset interface and an interface access permission, and when the interface permission set includes the target access permission, the interface request is sent to the back-end server.

[0011] In one embodiment, after the step of displaying the menu page, the method further includes: Determine, according to the acquired user identifier, a page element permission set that matches the user identifier, and determine the page elements included in the page element permission set as operable page elements; Displaying the operable page element in the menu page; or, In the menu page, the operable page elements and other elements in the menu page are displayed separately.

[0012] In addition, to achieve the above purpose, the present application also proposes a permission verification device, which is applied to the filter and includes: A request interception module, used to intercept an interface request sent by a front-end server, wherein the interface request is generated by the front-end server in response to a trigger operation on a target page element in a menu interface; A set determination module, used to determine the interface permission set that matches the interface request; The permission determination module is used to determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission; The request sending module is used to send the interface request to the backend server when the interface permission set includes the target access permission.

[0013] In addition, to achieve the above purpose, the present application also proposes a permission verification device, which is applied to a front-end server and includes: A display module, used for displaying a menu page, wherein the menu page includes at least one page element; A generating module, used for generating an interface request in response to a triggering operation on a target page element in the menu page; A sending module is used to send the interface request to the back-end server, wherein a filter is set between the back-end server and the front-end server, and the filter is used to intercept the interface request and determine the interface permission set that matches the interface request, and determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission, and send the interface request to the back-end server when the interface permission set contains the target access permission.

[0014] In addition, to achieve the above objectives, the present application also proposes a filter, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the permission verification method described above.

[0015] In addition, to achieve the above-mentioned purpose, the present application also proposes a front-end server, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the permission verification method described above.

[0016] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the permission verification method described above are implemented.

[0017] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps of the permission verification method described above are implemented.

[0018] One or more technical solutions proposed in this application have at least the following technical effects: intercepting the interface request generated and sent by the front-end server in response to the triggering operation for the target page element in the menu interface through a filter; since the interface request can reflect the relevant information of the user who triggered the request, the interface permission set matching the request can be determined based on the interface request, and the interface permission set can indicate the back-end interface that the user has the right to access; and then through the interface association relationship between the preset interface and the interface access right, the target access right of the target interface indicated by the interface request is determined, and the target access right reflects the access right required for the user to request the target interface; and then the interface permission can be quickly verified by matching the interface permission set and the target access right. If the interface permission set contains the target access right, it means that the user has the right to access the target interface, and the interface request can be sent to the back-end server to complete the response to the interface request triggered by the user. This application realizes the unified management and control of interface access rights by setting the association relationship between the interface and the interface access right, so that the efficiency of permission control is improved. In addition, this application can perform permission verification through a filter independent of the back-end server, without modifying the back-end code, thereby improving the efficiency of permission verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0020] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 A flowchart of the first embodiment of the method for verifying the application permissions is provided; Figure 2 This is a general schematic diagram of the interface authority control provided in Example 2 of the present application; Figure 3 A schematic diagram of the permission verification process applied to a filter provided in Embodiment 3 of the present application; Figure 4 This is a schematic diagram of the module structure of a permission verification device for this application; Figure 5 A schematic diagram of the module structure of another permission verification device for this application; Figure 6 A schematic diagram of the device structure of the hardware operating environment of the filter involved in the permission verification method in the embodiment of the present application; Figure 7 This is a schematic diagram of the device structure of the hardware operating environment of the front-end server involved in the permission verification method in the embodiment of the present application. DETAILED DESCRIPTION

[0022] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0023] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0024] Since the common backend interface permission control solutions are currently implemented based on annotations, annotations are added to the corresponding backend interfaces with permission character parameters. This method of adding annotations to the interface is very invasive to the business code, especially when permission control is required for an already developed application system. It is necessary to add annotations to all interfaces that require permission, which not only brings a lot of workload and reduces the efficiency of permission control, but also easily affects the stability of the original system and violates the open-closed principle.

[0025] The present application provides a solution, which is applied to filters. First, the interface request generated and sent by the front-end server in response to the trigger operation for the target page element in the menu interface is intercepted; since the interface request can reflect the relevant information of the user who triggered the request, the interface permission set matching the request can be determined based on the interface request, and the interface permission set can indicate the back-end interface that the user has the right to access; then, the target access right of the target interface indicated by the interface request is determined through the interface association relationship between the preset interface and the interface access right, and the target access right reflects the access right required for the user to request the target interface; then, the interface permission can be quickly verified by matching the interface permission set and the target access right. If the interface permission set contains the target access right, it means that the user has the right to access the target interface, and it is determined that the permission verification of the interface request passes, and the interface request can be sent to the back-end server to complete the response to the interface request triggered by the user. The present application manages the association relationship between the interface and the interface access right through a filter independent of the back-end server, and the permission control of the back-end interface can be completed without coupling with the business back-end code, thereby improving the efficiency of permission control.

[0026] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, personal computer, mobile phone, etc., or a front-end server that can realize the above functions.

[0027] The following uses the filter as an example to illustrate this embodiment and the following embodiments. Based on this, the present application embodiment provides a permission verification method, referring to Figure 1 , Figure 1 This is a flowchart of the first embodiment of the permission verification method of this application.

[0028] In this embodiment, the permission verification method includes steps S10 to S40: Step S10, intercepting an interface request sent by the front-end server, wherein the interface request is generated by the front-end server in response to a trigger operation on a target page element in the menu interface; In one feasible embodiment, [1] a menu page is displayed through a front-end server, and the menu page can be any interactive interface including page elements; then the front-end server generates an interface request for the back-end interface corresponding to the target page element in response to the user's trigger operation on the menu page, and sends the interface request to the back-end server, expecting a response from the back-end server. However, a filter is set between the front-end server and the back-end server, and the filter is used to intercept the interface request sent by the front-end server to the back-end server, verify the interface authority of the user who triggers the interface request, and prevent the user from illegally calling the back-end interface. The filter successfully separates the interface authority check from the back-end business code, which facilitates the unified management and control of interface authorities and improves the authority control efficiency.

[0029] Exemplarily, the filter may be deployed on a gateway.

[0030] Step S20, determining the interface permission set that matches the interface request; In a feasible embodiment, after intercepting the interface request sent by the front-end server, the filter determines which interfaces the current user has access to based on the user information in the interface request, and obtains an interface permission set for subsequent interface permission verification. The interface permission set can be expressed in the form of data, queues, linked lists, etc.

[0031] Exemplarily, the filter is configured with a rights management table, which stores the mapping relationship between the user ID and the backend interface to which the user has access rights. The filter can determine the permission characters of the backend interface that the user can access by matching the user ID, and then obtain the interface permission set.

[0032] Step S30, determining the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission; It should be noted that the association relationship between the interface and the interface access rights can be presented in the form of a database table, etc., to facilitate users to configure and manage them.

[0033] In a feasible embodiment, after intercepting the interface request sent by the front-end server, the filter can determine the target interface indicated in the interface request based on the request address and request method in the interface request; and then can determine the access rights of the target interface based on the association between the preset interface and the interface access rights.

[0034] Exemplarily, before the permission check, the user needs to enter an interface comparison table on the filter, and match the request address, request method and backend interface one by one, so that the filter can determine the target interface indicated by the interface request. For example, after intercepting the interface request sent by the front-end server, the filter parses the request address and request method from it; then, according to the interface comparison table, it determines whether the request address has a unique corresponding backend interface, and if so, it determines it as the target interface of the interface request; if not, it further matches according to the request method to determine the target interface; then, according to the association between the preset interface and the interface access rights, the target access rights of the target interface can be determined. The matching order of the above request addresses and request methods is not fixed.

[0035] Exemplarily, a page path identifier can be further extracted from the request address, and a permission character can be assigned to the path identifier. For example, for the homepage of the ordering system, the user has access rights to all back-end interfaces corresponding to the triggered operations in the page. Interface requests for the same page in the URL often have the same part, which is determined as the page path identifier, such as http: / / order.com / home, and a permission character is assigned to the identifier. After intercepting the interface request, the filter first filters the request method, and then extracts the page path identifier from the request address. If the page path identifier has a unique corresponding permission character, the permission character is determined as the target access permission character of the target interface, thereby realizing permission management of all interfaces in the page, thereby improving the efficiency of permission control.

[0036] Exemplarily, the target interface can also be determined based on the request header information (such as Content-Type, etc.) in the interface request. For example, a resource interface comparison table is configured in the filter, and the filter can determine a unique target interface based on the data resource expected to be obtained in the request header information.

[0037] It is understandable that when the backend interface changes, users can adjust the interface permissions by modifying the association between the interface and the interface access rights without modifying the business code, thereby achieving non-intrusive interface permission control and improving the efficiency of permission control.

[0038] Step S40: When the interface permission set includes the target access permission, an interface request is sent to the backend server.

[0039] If the interface permission set matched by the interface request contains the access rights of the target interface, it indicates that the user who triggered the interface request has the right to access the corresponding backend interface. Therefore, when the interface permission set contains the target access rights, the filter determines that the permission check of the intercepted interface request has passed, and forwards the interface request to the backend server, so that the backend server responds to the interface request sent by the front-end server.

[0040] This embodiment provides a permission verification method, which performs permission verification on intercepted interface requests through filters to reduce the risk of users illegally accessing the back-end interface; and manages the association between the interface and the interface access rights through a filter independent of the back-end server, avoiding direct modification of the corresponding back-end business code, thereby achieving unified management and non-intrusive control of back-end interface permissions, thereby improving the efficiency of permission control.

[0041] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated later. On this basis, step S20 includes: Step S21, determining the role information of the interface request; Exemplarily, after intercepting the interface request sent by the front-end server, the filter can determine the user ID by parsing the authentication information of the interface request, and then query the user role comparison table to determine the user's current role information based on the user ID; it can also read the session information in the interface request, and then determine the user's role information from historical session data based on the session information.

[0042] Step S22: Determine the interface permission set according to the role information.

[0043] In a feasible embodiment, the backend interfaces that the current role has access to can be determined based on the user's role information; and then the interface permission set of the current role can be determined based on the association relationship between the preset role and the interface access permission, and it can be determined as the interface permission set of the current user. The association relationship between the role and the interface access permission can be stored in the form of a database table or the like.

[0044] For example, in addition to role information, you can further obtain attribute information of the current interface request (such as geographic location, operation time, etc.), and determine the interface permission set based on the user's role information, attribute information and preset permission rules. For example, the permission rules stipulate that ordinary employees (role information) only have the right to access the query interface (target interface) during non-working hours (attribute information). Then, after intercepting the interface request sent by the employee to the back-end server through the front-end server during non-working hours, the filter will perform a permission query and find that it only has the right to access the query interface. The interface request to access the query interface will be forwarded to the back-end server, other interface requests will not be responded to, and a prompt message will be sent to the front-end server.

[0045] In this embodiment, by introducing role information, the interface permissions of different users belonging to the same role can be managed uniformly, which simplifies the configuration and update process of permissions for each user, thereby improving the efficiency of permission control.

[0046] In a feasible implementation manner, step S22 includes: Step S24, determining a page element permission set according to the role information; It should be noted that the page element permission set refers to a set of triggering permissions that a user has for page elements of a menu page of a front-end server.

[0047] Step S25, determining the interface permission set according to the page element permission set.

[0048] In a feasible embodiment, based on the role to which the current user belongs and the page elements that the current role can trigger, the permission characters of the page elements that the current user can trigger are determined to obtain a page element permission set; then, based on the page element permission set and the association between the page element and the interface access rights, the permission characters of the back-end interface that the current user can access are determined to obtain an interface permission set, thereby realizing the binding of the page elements of the front-end server and the back-end interface of the back-end server.

[0049] For example, please refer to Figure 2 , Figure 2 The present invention provides an overall schematic diagram of interface permission control. Each user has a corresponding role. The menu page of the current user can be determined based on the user's role information. The menu page includes a directory, a function menu and a page element. The directory and the function menu can be switched by clicking on the front-end layout elements without interacting with the back-end server. The page elements are bound to the back-end interface. The page elements that the current user can trigger can be determined based on the user's role information, and then the back-end interface that the user can access can be determined. That is, the interface permission can be determined based on the page element permission, and finally an association relationship between user-role-page element-interface is formed.

[0050] In this implementation, the interface permissions are quickly determined by binding the front-end page elements and the back-end interface. Based on the adjustment of the page element permissions, the interface permissions will also be adjusted accordingly without the need for users to manually adjust them separately, thus ensuring the consistency of the page element permissions and the interface permissions, while improving the efficiency of permission control.

[0051] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the first and second embodiments above can be referred to the above introduction, and will not be described in detail later. On this basis, the permission verification method also includes: Step A10: When the backend interface of the backend server is updated, the association relationship between the interface and the interface access rights is modified according to the change of the backend interface.

[0052] In a feasible embodiment, the filter monitors the backend interface configuration of the backend server, and when a backend interface update is detected, the association between the interface and the interface access rights is automatically modified according to the changes in the backend interface, such as addition, deletion, interface name modification, etc.

[0053] Exemplarily, when the backend interface is changed to be deleted or the interface name is modified, the corresponding backend interface in the association relationship is automatically deleted or the name of the corresponding backend interface in the association relationship is modified.

[0054] Exemplarily, when a backend interface is changed to be newly added, the corresponding backend interface is automatically added to the association relationship, and the access permission character of the interface is randomly generated; subsequent users can query the association relationship to assign the access permission character of the newly added port to the user or role.

[0055] In this embodiment, the interface permissions are automatically updated by modifying the association between the interface and the interface access rights. There is no need to adjust the backend business code, and there is no need to recompile and deploy the business code, which reduces the user's configuration time and improves the control efficiency of the interface permissions.

[0056] In a feasible implementation manner, after step S10, the method further includes: Step S01, determining the target interface indicated by the interface request; Step S02, when the preset interface library does not contain the target interface, the interface request is processed according to the preset rules; Exemplarily, the preset interface library includes the backend interface that has been entered in the filter. According to the preset processing rules, during the development and testing phase of the server, the filter intercepts the interface request for the unentered backend interface, skips the permission check for the interface request, and forwards it to the backend server normally, so that the developer can carry out related development and testing work normally; during the operation phase of the server, the filter intercepts the interface request for the unentered backend interface, indicating that there may be a user trying to make an illegal attack on the backend server. Therefore, the filter can reject the access request and output an alarm message. This embodiment does not specifically limit how to set the processing rules.

[0057] Step S03: When the interface library contains the target interface, a step of determining an interface permission set that matches the interface request is executed.

[0058] For example, to help understand the implementation process of the permission verification method applied to the filter obtained by combining this embodiment with the above-mentioned embodiment 1, please refer to Figure 3 Specifically: the filter executes step S101 to intercept the interface request sent by the front-end server; S102 to determine the target interface according to the request address and request method in the interface request; S103 to determine whether the preset interface library contains the target interface; if the interface library does not contain the target interface, the filter executes step S104 to process the interface request according to the preset rules, including skipping the check, denying access, etc.; if the interface library contains the target interface, the filter executes step S105 to determine the interface permission set that matches the interface request, and the interface permission set contains the permission characters of the back-end interface that the user can access; S106 to determine the interface permission set that matches the interface request according to the preset rules. The association relationship between the interface and the interface access permission character determines the access permission character of the target interface; S107, determines whether the user's interface permission set contains the access permission character; when the user's interface permission set does not contain the access permission character, that is, the permission check fails, the filter executes step S108, outputs a prompt message, and prompts the management personnel that there is currently no permission to access, so as to conduct timely investigation; when the user's interface permission set contains the access permission character, that is, the permission check passes, the filter executes step S109, sends the intercepted interface request to the back-end server, so that the back-end server responds to the interface request, and sends the response information to the front-end server.

[0059] In this implementation, by determining in advance whether the target interface is included in the backend server, and then determining whether to perform permission verification based on the determination result, the workload of the filter is reduced and the working efficiency of the filter is improved.

[0060] Based on the first embodiment, the second embodiment and / or the third embodiment of the present application, in the fourth embodiment of the present application, the same or similar contents as those in the first embodiment, the second embodiment and the third embodiment can be referred to the above description, and will not be repeated in the following. The following takes the front-end server as the execution subject as an example to illustrate this embodiment. On this basis, the permission verification method includes steps E10~E30: Step E10, displaying a menu page, wherein the menu page includes at least one page element; In a feasible embodiment, in order to facilitate user operation, the front-end server displays a menu page, which refers to an interactive interface including at least one page element, and the page element refers to the interactive elements on the web page or application interface, including but not limited to menus, buttons, links, etc. within the page.

[0061] Step E20, generating an interface request in response to a trigger operation on a target page element in the menu page; Exemplarily, the front-end server uses event monitoring technology to capture the user's triggering operations on the page elements in the menu page, such as clicking, dragging and dropping, sliding, etc., and determines the page elements triggered by the user as the target page elements. Then, based on the relevant configuration of the target page elements and the data resources provided by the user, an interface request is generated. The interface request includes the request address, request method, request header and request body (data resources), etc.

[0062] Step E30, sending an interface request to the back-end server, wherein a filter is set between the back-end server and the front-end server, the filter is used to intercept the interface request and determine the interface permission set that matches the interface request, determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission, and send the interface request to the back-end server when the interface permission set includes the target access permission.

[0063] In this embodiment, the front-end server generates an interface request based on the user's trigger operation on the page element, converts the user operation into a form that can be understood by the machine, and sends the interface request to the back-end server to facilitate the back-end server to respond to the user operation.

[0064] In a feasible implementation manner, after step E10, the method further includes: Step E11, determining a page element permission set that matches the user identifier according to the acquired user identifier, and determining the page elements included in the page element permission set as operable page elements; In one feasible embodiment, the user ID of the current user is obtained based on the user's login information; then based on the user ID, the page elements that the current user can access or operate are determined from a preset user permission library to obtain the page element permission set of the current user.

[0065] Exemplarily, role information can also be introduced to divide users into roles, and the same role can access or operate the same page elements. The front-end server determines the role information of the current user based on the acquired user identifier, and then determines the page element permission set of the current user based on the role information. This form of association based on user-role-page element facilitates the permission management of page elements for different users. It only needs to modify the page element permission corresponding to the role to complete the adjustment of the page element permissions of all users belonging to the role, thereby improving the control efficiency of page element permissions.

[0066] Step E12, displaying operable page elements in the menu page; or, Step E13: In the menu page, distinguish and display the operable page elements and other elements in the menu page.

[0067] Exemplarily, the front-end server determines the operable page elements that the current user is authorized to trigger or interact with based on the page element permission set, and renders these operable page elements, so that all page elements on the current menu interface can be triggered or interacted with by the current user; alternatively, the operable page elements are rendered in a color, size, etc. that is different from other page elements in the menu page, thereby distinguishing the operable page elements displayed in the menu page from other elements in the menu page, so that the user can judge whether they have permission to interact by the way the page elements are displayed in the display interface.

[0068] Exemplarily, before sending an interface request, the user's page element triggering permission can be verified through the page element permission set. For example, the mobile phone number query webpage displays a name input box, a query button, and a new button, and the second permission character corresponding to the query button is a. The front-end server determines the user's page element permission set for the webpage based on the identification information of the user logging into the webpage. If there is no character a in the list, the user's triggering operation on the query button will not be responded to; if the list contains character a, the front-end server will convert the triggering operation for the query button into an interface request, and send the interface request to the back-end server, so that the back-end server responds to the interface request. By verifying the user's page element triggering permission through the front-end server, it is ensured that only users with corresponding permissions can trigger specific functions, thereby realizing access control for front-end page elements.

[0069] In this implementation, by providing a customized display interface for the user, it is convenient for the user to clearly understand the permissions he or she has and perform related operations, thereby improving the user experience.

[0070] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the permission verification method of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0071] The present application also provides a permission verification device, please refer to Figure 4 , the permission verification device is applied to the filter, and the device includes: A request interception module 10, used to intercept an interface request sent by a front-end server, wherein the interface request is generated by the front-end server in response to a trigger operation on a target page element in a menu interface; A set determination module 20, used to determine the interface permission set that matches the interface request; The permission determination module 30 is used to determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission; The request sending module 40 is used to send an interface request to a backend server when the interface permission set includes the target access permission.

[0072] The permission verification device provided in the embodiment of the present application adopts the permission verification method in the above embodiment, which can solve the technical problem of how to improve the efficiency of permission control. Compared with the prior art, the beneficial effects of the permission verification device provided in the present application are the same as the beneficial effects of the permission verification method provided in the above embodiment, and other technical features in the permission verification device are the same as the features disclosed in the above embodiment method, which will not be repeated here.

[0073] The present application also provides another permission verification device, please refer to Figure 5 , the permission verification device is applied to the filter, and the device includes: A display module 50, used to display a menu page, wherein the menu page includes at least one page element; A generating module 60, for generating an interface request in response to a triggering operation on a target page element in a menu page; The sending module 70 is used to send an interface request to a back-end server, wherein a filter is provided between the back-end server and the front-end server, the filter is used to intercept the interface request and determine the interface permission set that matches the interface request, determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission, and send the interface request to the back-end server when the interface permission set includes the target access permission.

[0074] The permission verification device provided in the embodiment of the present application adopts the permission verification method in the above embodiment, which can solve the technical problem of how to improve the efficiency of permission control. Compared with the prior art, the beneficial effects of the permission verification device provided in the present application are the same as the beneficial effects of the permission verification method provided in the above embodiment, and other technical features in the permission verification device are the same as the features disclosed in the above embodiment method, which will not be repeated here.

[0075] An embodiment of the present application provides a filter, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the permission verification method in the above-mentioned embodiment one.

[0076] Reference below Figure 6 , which shows a schematic diagram of the structure of the filter suitable for implementing the embodiment of the present application. The filter in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions: tablet computers), PMPs (Portable Media Players: portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The filter shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0077] like Figure 6As shown, the filter may include a processing device 1001 (e.g., a central processing unit, a graphics processor, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 to a random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the filter are also stored. The processing device 1001, ROM1002, and RAM1004 are connected to each other via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. Communication device 1009 can allow the filter to communicate with other devices wirelessly or wired to exchange data. Although the filter with various systems is shown in the figure, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or have alternatively.

[0078] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0079] The filter provided in the embodiment of the present application adopts the permission verification method in the above embodiment, which can solve the technical problem of how to improve the efficiency of permission control. Compared with the prior art, the beneficial effects of the filter provided in the present application are the same as the beneficial effects of the permission verification method provided in the above embodiment, and the other technical features in the filter are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.

[0080] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0081] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0082] An embodiment of the present application also provides a front-end server, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the permission verification method in the above-mentioned embodiment one.

[0083] Reference below Figure 7 , which shows a schematic diagram of the structure of a front-end server suitable for implementing an embodiment of the present application. The front-end server in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions: tablet computers), PMPs (Portable Media Players: portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The front-end server shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0084] like Figure 7As shown, the front-end server may include a processing device 2001 (e.g., a central processing unit, a graphics processor, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 2002 or a program loaded from a storage device 2003 to a random access memory (RAM: Random Access Memory) 2004. Various programs and data required for the operation of the front-end server are also stored in RAM2004. The processing device 2001, ROM2002, and RAM2004 are connected to each other via a bus 2005. An input / output (I / O) interface 2006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 2006: an input device 2007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 2008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 2003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 2009. Communication device 2009 can allow front-end server to carry out wireless or wired communication with other equipment to exchange data.Although the figure shows the front-end server with various systems, it should be understood that it is not required to implement or have all the systems shown.Can implement or have more or less systems alternatively.

[0085] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 2003, or installed from a ROM 2002. When the computer program is executed by the processing device 2001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0086] The front-end server provided in the embodiment of the present application adopts the permission verification method in the above embodiment, which can solve the technical problem of how to improve the efficiency of permission control. Compared with the prior art, the beneficial effects of the front-end server provided in the present application are the same as the beneficial effects of the permission verification method provided in the above embodiment, and the other technical features in the front-end server are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.

[0087] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0088] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0089] An embodiment of the present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, wherein the computer-readable program instructions are used to execute the permission verification method in the above-mentioned embodiment.

[0090] The computer-readable storage medium provided in the embodiment of the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM: Random Access Memory), a read-only memory (ROM: Read Only Memory), an erasable programmable read-only memory (EPROM: Erasable Programmable Read Only Memory or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM: CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency: Radio Frequency), etc., or any suitable combination of the above.

[0091] The computer-readable storage medium may be included in the filter and / or the front-end server; or may exist independently without being assembled into the filter and / or the front-end server.

[0092] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the filter, the filter: intercepts the interface request sent by the front-end server, wherein the interface request is generated by the front-end server in response to a trigger operation on a target page element in a menu interface; determines the interface permission set that matches the interface request; determines the target access permission of the target interface indicated by the interface request based on the association relationship between the preset interface and the interface access permission; and sends the interface request to the back-end server when the interface permission set includes the target access permission.

[0093] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the front-end server, the front-end server: displays a menu page, wherein the menu page includes at least one page element; generates an interface request in response to a trigger operation on a target page element in the menu page; sends the interface request to the back-end server, wherein a filter is set between the back-end server and the front-end server, the filter is used to intercept the interface request and determine the interface permission set that matches the interface request, determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission, and send the interface request to the back-end server when the interface permission set includes the target access permission.

[0094] Computer program code for performing the operations of the present application may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0095] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0096] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.

[0097] The readable storage medium provided in the embodiment of the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned permission verification method, and can solve the technical problem of how to improve the efficiency of permission control. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in the present application are the same as the beneficial effects of the permission verification method provided in the above-mentioned embodiment, and will not be repeated here.

[0098] An embodiment of the present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned permission verification method when executed by a processor.

[0099] The computer program product provided in the embodiment of the present application can solve the technical problem of how to improve the efficiency of permission control. Compared with the prior art, the beneficial effects of the computer program product provided in the present application are the same as the beneficial effects of the permission verification method provided in the above embodiment, which will not be repeated here.

[0100] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.

Claims

1. A permission verification method, characterized in that: The permission verification method is applied to a filter, and the method includes: Intercepting an interface request sent by a front-end server, wherein the interface request is generated by the front-end server in response to a trigger operation on a target page element in a menu interface; Determine an interface permission set that matches the interface request; Determine the target access permission of the target interface indicated by the interface request according to the association relationship between the preset interface and the interface access permission; In a case where the interface permission set includes the target access permission, the interface request is sent to a backend server.

2. The permission verification method according to claim 1, characterized in that: The method further comprises: When the backend interface of the backend server is updated, the association relationship between the interface and the interface access rights is modified according to the change of the backend interface.

3. The permission verification method according to claim 1, characterized in that: The step of determining the interface permission set that matches the interface request comprises: Determine the role information corresponding to the interface request; The interface permission set is determined according to the role information.

4. The permission verification method according to claim 3, characterized in that: The step of determining the interface permission set according to the role information comprises: Determine a page element permission set based on the role information; The interface permission set is determined according to the page element permission set.

5. The permission verification method according to claim 1, characterized in that: After the step of intercepting the interface request sent by the front-end server, the method further includes: Determine a target interface indicated by the interface request; In the case where the preset interface library does not include the target interface, processing the interface request according to a preset rule; In the case where the interface library contains the target interface, the step of determining the interface permission set that matches the interface request is performed.

6. A permission verification method, characterized in that: The permission verification method is applied to the front-end server, and the method includes: Displaying a menu page, wherein the menu page includes at least one page element; In response to a triggering operation on a target page element in the menu page, generating an interface request; The interface request is sent to a back-end server, wherein a filter is provided between the back-end server and the front-end server, the filter is used to intercept the interface request and determine a set of interface permissions that matches the interface request, and determine a target access permission of a target interface indicated by the interface request according to an association between a preset interface and an interface access permission, and when the interface permission set includes the target access permission, the interface request is sent to the back-end server.

7. The permission verification method according to claim 6, characterized in that: After the step of displaying the menu page, the method further includes: Determine, according to the acquired user identifier, a page element permission set that matches the user identifier, and determine the page elements included in the page element permission set as operable page elements; Displaying the operable page element in the menu page; or, In the menu page, the operable page elements and other elements in the menu page are displayed separately.

8. A filter, characterized in that: The filter comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the permission verification method according to any one of claims 1 to 5.

9. A front-end server, characterized in that: The front-end server comprises: a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the permission verification method as described in any one of claims 6 to 7.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the permission verification method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Background authority management system and management method

    CN111475803A

  • Data access permission control method and device

    CN112383534A

  • Interface authority verification method and system, electronic equipment, and storage medium

    CN113672896A

  • Interface authority control method and device and electronic equipment

    CN116257293A