Data authority management method and device, equipment and storage medium

By configuring data permission rules for each role and providing configuration windows, the complexity and maintenance difficulty of traditional permission control systems are solved, and the fast, secure and flexible data permission management of the contract management system is achieved.

CN120030516APending Publication Date: 2025-05-23CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510122763.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

When facing changes in the business environment and multi-dimensional combination requirements, traditional permission control systems often face problems such as high code complexity, time-consuming configuration and difficult to maintain.

Method used

By configuring corresponding data permission rules for each role according to the predefined role, controlling the user's query permissions for specific contract data in the contract data table, and providing a configuration window for editing and configuring rules.

Benefits of technology

It simplifies the complexity of data permission management, reduces configuration time-consuming, makes the contract management system easy to maintain, and can quickly and safely adapt to the business department's requirements for contract database management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030516A_ABST
    Figure CN120030516A_ABST
Patent Text Reader

Abstract

The invention provides a data permission management method and device, equipment and a storage medium, and the method comprises the steps: configuring a corresponding data permission rule for each role according to predefined roles, the data permission rules being used for controlling the query permission of a user for specific contract data in a contract data table, and the query permission being used for controlling the query permission of the user for the specific contract data in the contract data table; and in response to a trigger operation of an editing control for a target data permission rule, displaying a configuration window of the target data permission rule, and receiving a configuration operation for at least one configuration item in the configuration window to obtain an updated data permission rule. By adopting the technical scheme, a large number of custom codes do not need to be written, the complexity of data authority management is simplified, the configuration time consumption is reduced, and the contract management system is easy to maintain and can quickly and safely adapt to the requirements of business departments on contract database management and control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data processing, and in particular to a data authority management method, device, equipment and storage medium. Background Art

[0002] As the business environment continues to change, the authority management of contract data becomes particularly important, because contract data covers multiple types such as sales contracts, purchase contracts, and lease contracts, and involves different roles such as sales managers and department heads. In addition, authority management also needs to take into account the combined requirements of multiple dimensions such as departments and projects. Especially when business requirements change frequently, traditional authority control systems often face problems such as high code complexity, time-consuming configuration, and difficulty in maintenance. Summary of the invention

[0003] In order to solve the above technical problems, the embodiments of the present disclosure provide a data permission management method, apparatus, device and storage medium.

[0004] In a first aspect, the present disclosure provides a data rights management method, the method comprising:

[0005] According to the pre-defined roles, corresponding data permission rules are configured for each role; wherein the data permission rules are used to control the user's query authority for specific contract data in the contract data table;

[0006] In response to a triggering operation on an editing control of a target data permission rule, displaying a configuration window of the target data permission rule;

[0007] A configuration operation for at least one configuration item in the configuration window is received to obtain an updated data permission rule.

[0008] In an optional implementation, the predefined role includes a target role, and the configuring corresponding data permission rules for each role according to the predefined role includes:

[0009] In response to the configuration operation of the data permission rule for the target role, displaying a configuration window for the data permission rule;

[0010] Receive configuration operations for each configuration item in the configuration window, and configure corresponding data permission rules for the target role.

[0011] In an optional implementation manner, the method further includes:

[0012] Establish a mapping relationship between users and roles.

[0013] In an optional implementation manner, after establishing the mapping relationship between the user and the role, the method further includes:

[0014] Receiving a data query request for target contract data from a target user, and obtaining a user ID of the target user;

[0015] Determine a target role corresponding to the user identifier;

[0016] Determine a data permission rule set corresponding to the target user according to the target role;

[0017] Querying the contract data set that complies with the data permission rule set from the contract database;

[0018] If the target contract data belongs to the contract data in the contract data set, the target contract data is returned to the client for query by the target user.

[0019] In an optional implementation manner, the user includes a target user, and the establishing of a mapping relationship between the user and the role includes:

[0020] In response to the role configuration operation for the target user, at least one role is configured for the target user.

[0021] In an optional implementation, the configuration items include permission name, permission code, rule mode and rule details.

[0022] In an optional implementation manner, the attributes of the role include at least one of the following: contract type, project manager, approved, and project team; and the predefined roles support adding new roles or deleting existing roles.

[0023] In a second aspect, the present disclosure provides a data rights management device, the device comprising:

[0024] The first configuration module is used to configure corresponding data permission rules for each role according to pre-defined roles; wherein the data permission rules are used to control the user's query permission for specific contract data in the contract data table;

[0025] A display module, configured to display a configuration window of the target data permission rule in response to a triggering operation on an editing control of the target data permission rule;

[0026] The second configuration module is used to receive a configuration operation for at least one configuration item in the configuration window and obtain an updated data permission rule.

[0027] In a third aspect, the present disclosure provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions are executed on a terminal device, the terminal device implements the above method.

[0028] In a fourth aspect, the present disclosure provides a data authority management device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above method when executing the computer program.

[0029] In a fifth aspect, the present disclosure provides a computer program product, wherein the computer program product comprises a computer program / instructions, and the computer program / instructions implement the above method when executed by a processor.

[0030] Compared with the prior art, the technical solution provided by the embodiments of the present disclosure has at least the following advantages:

[0031] The disclosed embodiment provides a data permission management method, which configures corresponding data permission rules for each role according to predefined roles, wherein the data permission rules are used to control the user's query rights to specific contract data in the contract data table, and in response to the trigger operation of the editing control for the target data permission rule, displays the configuration window of the target data permission rule, receives the configuration operation for at least one configuration item in the configuration window, and obtains the updated data permission rule. With the above technical solution, the contract management system can allocate and configure corresponding data permission rules for each role according to the predefined roles to control the user's query rights to specific contract data in the contract data table, and can edit the target data permission rule through the configuration operation of at least one configuration item in the configuration window of the target data permission rule, without writing a large amount of custom code, simplifying the complexity of data permission management, reducing configuration time, and making the contract management system not only easy to maintain, but also able to quickly and safely adapt to the requirements of business departments for contract database management and control. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0033] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0034] Figure 1 A flowchart of a data authority management method provided by an embodiment of the present disclosure;

[0035] Figure 2 A schematic diagram of a data authority management page provided in an embodiment of the present disclosure;

[0036] Figure 3 A schematic diagram of another data authority management page provided in an embodiment of the present disclosure;

[0037] Figure 4 A schematic diagram of another data authority management page provided in an embodiment of the present disclosure;

[0038] Figure 5 A schematic diagram of the structure of a data authority management device provided in an embodiment of the present disclosure;

[0039] Figure 6 A schematic diagram of the structure of a data authority management device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0040] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0041] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0042] In order to simplify the complexity of data permission management, reduce configuration time, and make the contract management system not only easy to maintain but also able to quickly and safely adapt to the requirements of business departments for contract database management and control, the embodiment of the present disclosure provides a data permission management method.

[0043] Specifically, according to the predefined roles, corresponding data permission rules are configured for each role, wherein the data permission rules are used to control the user's query rights to specific contract data in the contract data table, and in response to the trigger operation of the editing control for the target data permission rule, the configuration window of the target data permission rule is displayed, and the configuration operation for at least one configuration item in the configuration window is received to obtain the updated data permission rule. By adopting the above technical scheme, the contract management system can allocate and configure corresponding data permission rules for each role according to the predefined roles to control the user's query rights to specific contract data in the contract data table, and the target data permission rule can be edited through the configuration operation of at least one configuration item in the configuration window of the target data permission rule, without writing a large amount of custom code, simplifying the complexity of data permission management, reducing configuration time, and making the contract management system not only easy to maintain, but also able to quickly and safely adapt to the requirements of business departments for contract database management and control.

[0044] Based on this, the embodiment of the present disclosure provides a data rights management method, and proposes a standard, fast, efficient and flexible data rights management method in the contract management system through configuration and simple code iteration. The method aims to minimize the workload and development time, which not only simplifies the complexity of rights management, but also improves the response speed and security of the contract management system, and is applicable to a variety of contract management scenarios. Figure 1 , is a flow chart of a data authority management method provided by an embodiment of the present disclosure, the method comprising:

[0045] S101: According to pre-defined roles, corresponding data permission rules are configured for each role; wherein the data permission rules are used to control the user's query authority to specific contract data in the contract data table.

[0046] The data authority management method provided by the embodiment of the present disclosure is applied to a contract management system. Specifically, the contract management system can be used as a key tool for managing and tracking the contract life cycle.

[0047] Among them, the role is the basic unit of contract data permission management. Each role represents a group of users with similar permissions. By defining different roles, fine-grained permission control can be achieved to ensure that only authorized personnel can access the corresponding data. Specifically, the attributes of the role include at least one of the following: contract type, project manager, approved, and project team.

[0048] Contract type refers to the category name for classifying contracts according to their nature, content, purpose, and other characteristics. For example, contracts can be divided into sales contracts, purchase contracts, and so on. If the attribute of a role is contract type, then the corresponding role is a role specifically set up for a specific type of contract data. Project manager refers to the core person in project management who is responsible for leading, organizing, planning, coordinating, and controlling the entire process of a project from initiation to completion to ensure that the project goals are achieved. If the attribute of a role is project manager, then the corresponding role is a role specifically set up for the contract data corresponding to the project that the project manager is responsible for.

[0049] Approved refers to all approved contract data. If the attribute of the role is Approved, then the corresponding role is a role specifically set for all approved contract data. A project team is a team formed to achieve specific project goals, consisting of members with different skills and expertise. If the attribute of the role is Project Team, then the corresponding role is a role specifically set for the contract data corresponding to the project team.

[0050] Data permission rules refer to a set of criteria that clearly define the user's query permissions for specific contract data in the contract data table. A contract data table refers to a table in the database that is specifically used to store contract-related information. Specifically, the contract data table contains multiple fields or columns related to the contract, which may include the contract number, contract name, signing date, information about the two parties to the contract, contract status, etc. Specific contract data refers to the data corresponding to a specific data row in the contract data table.

[0051] In the embodiment of the present disclosure, the contract management system can configure corresponding data permission rules for each role according to predefined roles to control the user's query permission for specific contract data in the contract data table.

[0052] To facilitate understanding, taking the predefined roles including the target role as an example, corresponding data permission rules are configured for each role according to the predefined roles, including: in response to the configuration operation of the data permission rules for the target role, a configuration window of the data permission rules is displayed, configuration operations for each configuration item in the configuration window are received, and corresponding data permission rules are configured for the target role.

[0053] The target role refers to any of the predefined roles. The configuration operation of data permission rules refers to formulating detailed data permission rules for the target role, clarifying which roles can query specific contract data in the contract data table. The configuration window refers to the interface for setting data permission rules for the target role. Specifically, the configuration window can be presented in the form of a pop-up window or a page.

[0054] Configuration items refer to specific settings used to define data permission rules. Specifically, configuration items include permission name, permission code, rule method, and rule details.

[0055] The permission name refers to the name used to describe the data permission rule. Specifically, the permission name can be used as an option in the configuration window, allowing operation and maintenance personnel to associate data permissions with roles. The permission code refers to the unique identifier corresponding to the permission name, which is used as the primary key code associated with the contract management system to ensure that each data permission rule has a unique identifier. The rule method is to define data permission rules based on the contract basic data table (such as the purchase contract master table, the sales contract master table, the approval data table, etc.). For example, when the rule method is the approval data table, it indicates that the corresponding data permission rules are set for the approval data table. The rule details refer to the specific conditions set for each data permission rule, which can be expressed using SQL statements. For example, "Sales Manager = 'Xiao A'" means that only when the value of the field "Sales Manager" is "Xiao A", the relevant contract data is visible to a specific user. The configuration operation of the configuration item refers to the specific operation of performing relevant configuration on the configuration item, such as configuring a corresponding name for the permission name.

[0056] In the disclosed embodiment, after receiving the configuration operation of the data permission rules for the target role, the contract management system displays the configuration window of the data permission rules in the form of a pop-up window or a page, and displays each configuration item in the configuration window. After receiving the configuration operation for each configuration item in the configuration window, the corresponding data permission rules are configured for the target role.

[0057] For example, Figure 2 This is a schematic diagram of a data permission management page provided by an embodiment of the present disclosure. Taking the target role as contract management-project manager as an example, after the user clicks contract management-project manager, he can click Figure 2 Add controls as shown to configure the data permission rules for the target role.

[0058] Furthermore, after configuring corresponding data permission rules for each role, a mapping relationship between users and roles is established.

[0059] In the disclosed embodiment, by establishing a mapping relationship between users and roles, each user can be assigned to at least one role to determine which users can perform which operations.

[0060] For ease of understanding, taking the user including the target user as an example, establishing a mapping relationship between the user and the role includes: in response to a role configuration operation for the target user, configuring at least one role for the target user.

[0061] The role configuration operation for the target user refers to configuring a corresponding role for the target user in the contract management system.

[0062] In the embodiment of the present disclosure, after receiving the role configuration operation for the target user, the contract management system configures at least one role for the target user, thereby determining which contract data in the contract data table the target user has query authority for.

[0063] For example, Figure 3 As shown, Figure 3 A schematic diagram of another data permission management page provided for an embodiment of the present disclosure, in which the operation and maintenance personnel can click on the control 301 to display a drop-down box including various roles, and select the corresponding role for the target user from the drop-down box. This process is a role configuration operation for the target user to implement the role configuration for the target user.

[0064] In actual applications, assuming that the role configured for the target user is "Contract Management-Public Cloud Contract", the data permission rule corresponding to "Contract Management-Shared Cloud Contract" is: Permission name: Public Cloud Contract, Permission code: 111, Rule method: Sales Contract Permission; Rule details: third_grade_type = 10, then for the target user, only the contract data in the sales contract table that meets third_grade_type = 10 can be queried. This strict data permission control mechanism enhances security, ensures data security and privacy protection, and prevents unauthorized users from accessing.

[0065] In addition, the predefined roles support adding new roles or deleting existing roles. Specifically, the user can add new roles through the control of adding new roles in the permission management page, and delete existing roles through the control of deleting existing roles in the permission management page. It is also possible to add new roles or delete existing roles from other platforms, and then obtain the updated roles through the interface.

[0066] S102: In response to a triggering operation on an editing control of a target data permission rule, a configuration window of the target data permission rule is displayed.

[0067] Among them, the editing control refers to the component or element used to edit the target data permission rules. The configuration window refers to the configuration interface for the target data permission rules. Specifically, the configuration window can be presented in the form of a pop-up window or a page. The triggering operation of the editing control can include gesture operations on the editing control (such as clicking, long pressing, double-clicking, etc.), language control operations, or expression control operations, etc.

[0068] In the disclosed embodiment, after receiving a trigger operation on an editing control of a target data permission rule, the contract management system displays a configuration window of the target data permission rule in the form of a pop-up window or a page, and displays each configuration item in the configuration window.

[0069] For example, continue to refer to Figure 2 Taking the target permission rule as a public cloud contract as an example, the operation and maintenance personnel can click the edit control corresponding to the public cloud contract to display Figure 4 The pop-up window shown, Figure 4 A schematic diagram of another data permission management page provided for an embodiment of the present disclosure displays a configuration window for a public cloud contract in the form of a pop-up window, and displays various configuration items (i.e., permission name, permission code, rule method, and rule details) in the configuration window.

[0070] S103: Receive a configuration operation for at least one configuration item in the configuration window, and obtain an updated data permission rule.

[0071] The configuration operation of a configuration item refers to a specific operation for performing relevant configuration on the configuration item, such as configuring a new rule mode for the current rule mode.

[0072] In the embodiment of the present disclosure, after receiving a configuration operation for at least one configuration item in the configuration window, such as a configuration operation for a rule mode, the contract management system obtains an updated data permission rule.

[0073] For example, taking the configuration operation for the rule mode as an example, continue to refer to Figure 4 The operation and maintenance personnel can click the control 401 to display a drop-down box including various rule modes, and select the corresponding rule mode from the drop-down box to configure the rule mode.

[0074] In the data permission management method provided by the embodiment of the present disclosure, a corresponding data permission rule is configured for each role according to a predefined role, wherein the data permission rule is used to control the user's query permission for specific contract data in the contract data table, and in response to a trigger operation on the editing control of the target data permission rule, the configuration window of the target data permission rule is displayed, and a configuration operation on at least one configuration item in the configuration window is received to obtain an updated data permission rule. By adopting the above technical scheme, the contract management system can allocate and configure corresponding data permission rules for each role according to the predefined role to control the user's query permission for specific contract data in the contract data table, and the target data permission rule can be edited through the configuration operation of at least one configuration item in the configuration window of the target data permission rule, without writing a large amount of custom code, simplifying the complexity of data permission management, reducing configuration time, and making the contract management system not only easy to maintain, but also able to quickly and safely adapt to the requirements of business departments for contract database management and control.

[0075] It can be seen that through the embodiments of the present disclosure, rapid deployment is achieved through preset permission templates and an intuitive user interface, and administrators can quickly set new data permission rules without writing a large amount of custom code. The contract management system is low-intrusive, keeps the main business logic unchanged, and adds the permission management function as an independent module to reduce interference with the existing contract management system. At the same time, its easy scalability enables it to support the flexible addition of new roles and adjustment of data permission rules of existing roles to meet changing business needs.

[0076] In some embodiments, after establishing a mapping relationship between users and roles, it also includes: receiving a data query request from a target user for target contract data, obtaining a user identifier of the target user, determining a target role corresponding to the user identifier, and determining a data permission rule set corresponding to the target user based on the target role, querying a contract data set that complies with the data permission rule set from a contract database; if the target contract data belongs to contract data in the contract data set, returning the target contract data to the client for query by the target user.

[0077] The target contract data may be any contract data in any contract data table in the contract database. A data query request for the target contract data refers to an operation instruction initiated to obtain specific information related to the target contract data. A user identifier refers to a symbol, code or information set used to uniquely identify the identity of each user in the contract management system. The target role refers to the role configured by the user identifier. The data permission rule set includes at least one data permission rule. A contract database refers to a database system specifically used to store, manage and retrieve contract-related information. A contract data set is constructed from contract data that conforms to the data permission rule set.

[0078] In the disclosed embodiment, the contract management system may adopt the AOP (Aspect-Oriented Programming) approach to intercept and parse the data query request after receiving a data query request from a target user for target contract data, obtain the user ID of the target user, and search for a data permission rule set corresponding to the target user based on the target role to which the user ID belongs. The contract data set that complies with the data permission rule set is queried from the contract database. If the target contract data belongs to the contract data set, the target contract data is returned to the client for query by the target user to ensure that the returned result complies with the permission setting.

[0079] For example, if the target user's user ID is "Xiao C" and he is granted all contract permissions of "Xiao E", the query statement is as follows:

[0080] SELECT contract code FROM sales contract WHERE sales person in charge = 'Xiao E'. Thus, even if "Xiao C" is not the original sales person in charge, all sales contracts that "Xiao E" is in charge of can be queried.

[0081] It can be seen that the embodiments of the present disclosure enhance security through a strict data permission control mechanism, ensure data security and privacy protection, and prevent unauthorized users from accessing the data.

[0082] Based on the above method embodiment, the present disclosure also provides a data authority management device, referring to Figure 5 , is a schematic diagram of the structure of a data authority management device provided by an embodiment of the present disclosure, the device comprising:

[0083] The first configuration module 501 is used to configure corresponding data permission rules for each role according to predefined roles; wherein the data permission rules are used to control the user's query permission for specific contract data in the contract data table;

[0084] Display module 502, for displaying a configuration window of the target data permission rule in response to a triggering operation on an editing control of the target data permission rule;

[0085] The second configuration module 503 is used to receive a configuration operation for at least one configuration item in the configuration window and obtain an updated data permission rule.

[0086] In an optional implementation manner, the predefined role includes a target role, and the first configuration module 501 includes:

[0087] A display submodule, configured to display a configuration window of a data permission rule in response to a configuration operation of the data permission rule for the target role;

[0088] The configuration submodule is used to receive configuration operations for each configuration item in the configuration window and configure corresponding data permission rules for the target role.

[0089] In an optional implementation, the device further includes:

[0090] A module is created to establish a mapping relationship between users and roles.

[0091] In an optional implementation, the device further includes:

[0092] An acquisition module, configured to receive a data query request from a target user for target contract data, and acquire a user ID of the target user;

[0093] A first determination module, used to determine a target role corresponding to the user identifier;

[0094] A second determination module is used to determine a data permission rule set corresponding to the target user according to the target role;

[0095] A query module, used to query the contract data set that meets the data permission rule set from the contract database;

[0096] The returning module is used to return the target contract data to the client for query by the target user if the target contract data belongs to the contract data in the contract data set.

[0097] In an optional implementation manner, the user includes a target user, and the establishing module is specifically configured to:

[0098] In response to the role configuration operation for the target user, at least one role is configured for the target user.

[0099] In an optional implementation, the configuration items include permission name, permission code, rule mode and rule details.

[0100] In an optional implementation manner, the attributes of the role include at least one of the following: contract type, project manager, approved, and project team; and the predefined roles support adding new roles or deleting existing roles.

[0101] In the data permission management device provided by the embodiment of the present disclosure, corresponding data permission rules are configured for each role according to the predefined roles, wherein the data permission rules are used to control the user's query rights to specific contract data in the contract data table, and in response to the trigger operation of the editing control for the target data permission rule, the configuration window of the target data permission rule is displayed, and the configuration operation for at least one configuration item in the configuration window is received to obtain the updated data permission rule. With the above technical solution, the contract management system can allocate and configure corresponding data permission rules for each role according to the predefined roles to control the user's query rights to specific contract data in the contract data table, and the target data permission rule can be edited through the configuration operation of at least one configuration item in the configuration window of the target data permission rule, without writing a large amount of custom code, simplifying the complexity of data permission management, reducing configuration time, and making the contract management system not only easy to maintain, but also able to quickly and safely adapt to the requirements of business departments for contract database management and control.

[0102] In addition to the above-mentioned method and apparatus, the embodiments of the present disclosure further provide a computer-readable storage medium, in which instructions are stored. When the instructions are executed on a terminal device, the terminal device implements the data authority management method described in the embodiments of the present disclosure.

[0103] The embodiments of the present disclosure also provide a computer program product, which includes a computer program / instructions. When the computer program / instructions are executed by a processor, the data authority management method described in the embodiments of the present disclosure is implemented.

[0104] In addition, the present disclosure also provides a data rights management device, see Figure 6 As shown, it may include:

[0105] Processor 601, memory 602, input device 603 and output device 604. The number of processors 601 in the data rights management device can be one or more. Figure 6 In some embodiments of the present disclosure, the processor 601, the memory 602, the input device 603 and the output device 604 may be connected via a bus or other means, wherein: Figure 6 The example of connecting through bus is taken in the following.

[0106] The memory 602 can be used to store software programs and modules. The processor 601 executes various functional applications and data processing of the data authority management device by running the software programs and modules stored in the memory 602. The memory 602 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc. In addition, the memory 602 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. The input device 603 can be used to receive input digital or character information, and generate signal input related to user settings and function control of the data authority management device.

[0107] Specifically in this embodiment, the processor 601 will load the executable files corresponding to the processes of one or more applications into the memory 602 according to the following instructions, and the processor 601 will run the applications stored in the memory 602, thereby realizing the various functions of the above-mentioned data permission management device.

[0108] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0109] The above description is only a specific embodiment of the present disclosure, so that those skilled in the art can understand or implement the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to the embodiments described herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data rights management method, characterized in that: The method comprises: According to the pre-defined roles, corresponding data permission rules are configured for each role; wherein the data permission rules are used to control the user's query authority for specific contract data in the contract data table; In response to a triggering operation on an editing control of a target data permission rule, displaying a configuration window of the target data permission rule; A configuration operation for at least one configuration item in the configuration window is received to obtain an updated data permission rule.

2. The method according to claim 1, characterized in that The predefined roles include target roles, and the corresponding data permission rules are configured for each role according to the predefined roles, including: In response to the configuration operation of the data permission rule for the target role, displaying a configuration window for the data permission rule; Receive configuration operations for each configuration item in the configuration window, and configure corresponding data permission rules for the target role.

3. The method according to claim 1, characterized in that The method further comprises: Establish a mapping relationship between users and roles.

4. The method according to claim 3, characterized in that After the mapping relationship between the user and the role is established, the following steps are also included: Receiving a data query request from a target user for target contract data, and obtaining a user ID of the target user; Determine a target role corresponding to the user identifier; According to the target role, determine a data permission rule set corresponding to the target user; Querying the contract data set that complies with the data permission rule set from the contract database; If the target contract data belongs to the contract data in the contract data set, the target contract data is returned to the client for query by the target user.

5. The method according to claim 3, characterized in that: The user includes a target user, and the step of establishing a mapping relationship between the user and the role includes: In response to the role configuration operation for the target user, at least one role is configured for the target user.

6. The method according to claim 1 or claim 2, characterized in that: The configuration items include permission name, permission code, rule method and rule details.

7. The method according to claim 1, characterized in that The attributes of the role include at least one of the following: contract type, project manager, approved, and project team; the predefined roles support adding new roles or deleting existing roles.

8. A data rights management device, characterized in that: The device comprises: The first configuration module is used to configure corresponding data permission rules for each role according to pre-defined roles; wherein the data permission rules are used to control the user's query permission for specific contract data in the contract data table; A display module, configured to display a configuration window of the target data permission rule in response to a triggering operation on an editing control of the target data permission rule; The second configuration module is used to receive a configuration operation for at least one configuration item in the configuration window and obtain an updated data permission rule.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed on a terminal device, the terminal device implements the method according to any one of claims 1 to 7.

10. A data rights management device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.