Role application method and device, permission system and medium
By introducing role application methods in the permission system, users can apply for target roles independently. The system automatically calculates target roles through functional points, solving the difficulties of users when applying for roles independently, reducing the work burden of administrators, and improving the information security of the system.
Patent Information
- Application Number
- CN202510362117.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-06
AI Technical Summary
The existing permission system has difficulties when users apply for roles independently, especially when there are many roles or if the user does not understand the permissions of each role, it is difficult for users to choose the right role.
By introducing role application methods in the permission system, users can apply for target roles independently. The system automatically calculates target roles through functional points, reduces the work burden of administrators, and provides multiple ways to help users understand and select the roles they need to apply for.
It realizes the user's independent application role, reduces the work burden of administrators, solves the difficulties of users when applying for roles independently, and improves the information security of the system.
Smart Images

Figure CN120105376A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of data processing technology, relates to the Internet, and particularly to a permission management, specifically a role application method, device, permission system and medium. Background Art
[0002] A role in a permission system is a collection of permissions. It packages multiple specific system permissions into a logical unit to simplify the management and allocation of permissions. When a system user has a role, he or she has a series of permissions corresponding to the role.
[0003] The existing permission system provides users with roles by having administrators assign roles to users. For larger companies, due to the large number of employees, it is obviously difficult for administrators to assign roles to each user. Summary of the invention
[0004] The purpose of this application is to provide a role application method, device, permission system and medium to solve the problems pointed out in the above background technology.
[0005] In a first aspect, the present application provides a role application method, which is applied to a permission system, and the method includes: when a first user needs to apply for a target role, determining the target role; receiving a role application work order corresponding to the target role issued by the first user; receiving the approval result of the role application work order from the second user, so that the first user can successfully apply for the target role when the approval result is passed.
[0006] In this application, a role application method is provided, which allows a user (corresponding to the first user) to apply for a specific role (corresponding to the target role) to an administrator (corresponding to the second user) on his own initiative, and obtain the corresponding role after approval by the administrator, thereby enabling users to apply for roles on their own initiative and reducing the workload of the administrator.
[0007] In an implementation of the first aspect, determining the target role includes: calculating a first function point that the first user does not have permission to access; determining a target function point that the first user needs to access based on the first function point; and recommending the target role to the first user based on the target function point.
[0008] In this implementation, a method for determining the target role is provided, in which the permission system automatically calculates the target role through function points, which can not only satisfy the user's application for permission when he only knows which function points he needs to access, but also meet the information security requirements of authorization in the smallest possible scope. It solves the problem that when the number of roles in the permission system is large or the user does not understand the permissions of each role, the user is faced with the dilemma of not being able to choose a role.
[0009] In an implementation of the first aspect, all function points are stored in the permission system; the calculation of the first function point that the first user does not have the permission to access includes: determining whether the first user has an existing role; when it is determined that the first user does not have the existing role, taking all the function points as the first function points; when it is determined that the first user has the existing role, querying the second function point associated with the existing role; the second function point is a function point that the first user has the permission to access; and obtaining the first function point based on all the function points and the second function point.
[0010] In an implementation of the first aspect, determining the target function point that the first user needs to access based on the first function point includes: presenting the first function point to the first user so that the first user directly selects the target function point from the first function points; or when the first user accesses a first function point for which he has no authority, automatically selecting the first function point as the target function point.
[0011] In an implementation of the first aspect, the target function point is stored in a function point list; recommending the target role to the first user based on the target function point includes: searching for all candidate roles associated with the target function point in the function point list; traversing all the candidate roles, and calculating the number of function points of the target function point covered by each candidate role in the function point list, recorded as the first number, and calculating the number of function points of other function points covered by each candidate role except the target function point in the function point list, recorded as the second number; taking the candidate role with the largest first number and the smallest second number as the candidate role; the priority of the first number is higher than the second number; removing the target function point associated with the candidate role from the function point list; repeating the above steps until the function point list does not contain any of the target function points; and recommending the candidate role to the first user as the target role.
[0012] In an implementation manner of the first aspect, the determining the target role includes: displaying to the first user a role selected by the first user that is owned by a third user but not owned by the first user, so that the first user acquires the target role therefrom.
[0013] In this implementation, a method for determining the target role is provided, which is used in scenarios where it is clear that others have role permissions. By applying for roles owned by others (i.e. copying other people's roles), users can quickly apply for corresponding permissions when they do not understand the business.
[0014] In an implementation manner of the first aspect, the determining the target role includes: receiving a request instruction from the first user, to determine the target role based on the request instruction.
[0015] In this implementation, a method for determining a target role is provided, which is applied in a scenario where it is clear that a certain role has permissions, and the permissions corresponding to the role are obtained by directly applying for the role.
[0016] In a second aspect, the present application provides a role application device, which is applied to a permission system, and the device includes: a determination module, which is used to determine the target role when a first user needs to apply for the target role; a receiving module, which is used to receive a role application work order corresponding to the target role issued by the first user; and an application module, which is used to receive the approval result of the second user on the role application work order, so that the first user can successfully apply for the target role when the approval result is passed.
[0017] In a third aspect, the present application provides a permission system, which includes: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory, so that the permission system executes the above-mentioned role application method.
[0018] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the above-mentioned role application method when executed by a permission system.
[0019] As described above, the role application method, device, permission system and medium described in this application have the following beneficial effects:
[0020] (1) Compared with the prior art, the present application provides a method for users to apply for roles independently, which helps users understand and assists in selecting the roles they need to apply for through multiple channels and in a visual manner, thereby solving the difficulties encountered by users in applying for roles independently, providing users with multiple choices, and no longer forcing users to know the roles and their functions.
[0021] (2) The role application method provided by this application does not force users to understand all roles and their functions, so that administrators can maintain roles while reducing the need to disseminate role information to company employees, thereby allowing administrators to maintain more roles to manage system permissions. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 Shown is a flow chart of the role application method described in an embodiment of the present application.
[0023] Figure 2 Shown is a flowchart of determining a target role according to an embodiment of the present application.
[0024] Figure 3 Shown is a flowchart of calculating a first function point that a first user does not have permission to access as described in an embodiment of the present application.
[0025] Figure 4 Shown is a flowchart of recommending a target role for a first user based on a target function point as described in an embodiment of the present application.
[0026] Figure 5 Shown is a schematic diagram of the structure of the role application device described in an embodiment of the present application. DETAILED DESCRIPTION
[0027] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.
[0028] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application, and thus the drawings only show components related to the present application rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed at will, and the component layout may also be more complicated.
[0029] See also Figures 1 to 5 . The following embodiments of the present application provide a role application method, device, permission system and medium. Compared with the prior art, the present application provides a method for users to apply for roles independently, which helps users understand and assists in selecting the roles they need to apply for through multiple channels and in a visual manner, solves the difficulties encountered by users in applying for roles independently, provides users with multiple choices, and no longer forces users to know the roles and their functions; the role application method provided by the present application does not force users to understand all roles and their functions, so that administrators can reduce the need to disseminate role information to company employees while maintaining roles, thereby allowing administrators to maintain more roles to manage system permissions.
[0030] The role application method provided in this application can be applied to at least the following scenarios:
[0031] Scenario 1:
[0032] As the company grows and the system functions become more diverse, administrators will create more new roles to package and categorize new permissions. As the company's staff increases and positions become more specialized, administrators will split existing roles into multiple roles to cope with the refinement of personnel functions and prevent system users from obtaining permissions that are not within their functions.
[0033] Scenario 2:
[0034] When a new employee joins the company or the employee's job content changes, the system user will need new permissions to operate the corresponding functions in the system in order to complete the work. At this time, the user can apply for the required role from the administrator on his own.
[0035] The explanations of the professional terms appearing in this application are as follows:
[0036] 1. Menu: A visual interface element presented to users in the permission system. It is usually displayed in a tree structure on the system interface to guide users to access different functional modules and operation pages.
[0037] 2. Page resources: In the system managed by the permission system, the specific web pages or interface function points that users can access on the operation interface. It can be a menu, web page or button.
[0038] 3. Function point: The smallest independent unit of a specific function possessed by the system, usually composed of multiple page resources.
[0039] Case: The "Delete Account" function point usually includes the "Account List Page" and "Delete Account Button" page resources.
[0040] 4. Permission: User access or operation permission to specific resources or functions in the permission system.
[0041] 5. Role: A role is a collection of permissions, which means that a role has permission to access multiple functional points.
[0042] Example: The "Account Administrator" role has permission to access the "Create Account", "Modify Account", "Query Account", and "Delete Account" function points.
[0043] The technical solutions in the embodiments of the present application will be described in detail below in conjunction with the drawings in the embodiments of the present application.
[0044] like Figure 1 As shown, in one embodiment, the present application provides a role application method, which is applied in a permission system, and the method includes:
[0045] Step S1: When a first user needs to apply for a target role, the target role is determined.
[0046] It should be noted that the first user refers to the user who needs to apply for a role.
[0047] like Figure 2 As shown, in one embodiment, determining the target role includes:
[0048] Step S11: Calculate a first function point that the first user does not have permission to access.
[0049] like Figure 3 As shown, in one embodiment, the permission system stores all function points; and the calculating of the first function point that the first user does not have permission to access includes:
[0050] Step S111: Determine whether the first user already has a role.
[0051] It should be noted that the already owned role is a role that the first user already has.
[0052] In one embodiment, it is determined whether the first user already has a role by querying a database.
[0053] Specifically, the database is stored in the authority system, which stores successful role application records; for example, a user successfully applies for a role.
[0054] In one embodiment, the database exists in the form of a table.
[0055] It should be noted that, before applying for the target role, the first user may have certain roles (corresponding to the already owned roles), or may not have any roles, that is, according to the judgment of step S111, there may be already owned roles, or there may not be any.
[0056] When it is determined that the first user does not have the role already possessed (ie, the determination result is no), step S112 is executed.
[0057] Step S112: taking all the function points as the first function points.
[0058] When it is determined that the first user already has the role (ie, the determination result is yes), the following steps S113 and S114 are executed.
[0059] Step S113: query the second function point associated with the existing role.
[0060] Specifically, the second function point is a function point that the first user has permission to access.
[0061] It should be noted that the permission system not only stores all function points, but also stores all roles, the permission corresponding to each role, the menu corresponding to each permission, the function point corresponding to each menu, and the page resource corresponding to each function point. Therefore, in step S113, the permission system can automatically query the function point associated with the role already owned by the first user, that is, the second function point.
[0062] Step S114: Acquire the first function point according to all the function points and the second function point.
[0063] Specifically, among all the function points, the second function point is eliminated, and the first function point is obtained.
[0064] Step S12: determining a target function point that the first user needs to access based on the first function point.
[0065] In one embodiment, determining the target function point that the first user needs to access based on the first function point includes: presenting the first function point to the first user, so that the first user directly selects the target function point from the first function point.
[0066] In one embodiment, the first function point is displayed in a tree and / or table format.
[0067] Specifically, the first function point is intuitively presented to the first user, so that the first user directly selects the target function point from the first function point.
[0068] It should be noted that it is easier to understand functional points than to understand roles. For example, for the role of warehouse manager, users usually do not know how many pages this role can access, or whether they are suitable to apply for this role, but users usually know that they need to query inventory information and need to enter a page to query inventory.
[0069] In one embodiment, determining the target function point that the first user needs to access based on the first function point includes: when the first user accesses a first function point for which he has no authority, automatically selecting the first function point as the target function point.
[0070] In one embodiment, when a first user accesses a first function point for which he has no authority, automatically selecting the first function point as the target function point includes: the authority system gives a prompt to jump to the recommended role based on the function point, and checks the function point by default, thereby automatically selecting the first function point as the target function point.
[0071] It should be noted that the first user may also choose to uncheck the above function points.
[0072] Step S13: recommending the target role to the first user according to the target function point.
[0073] like Figure 4 As shown, in one embodiment, the target function point is stored in a function point list; and recommending the target role to the first user according to the target function point includes:
[0074] Step S131: Find all candidate roles associated with the target function point in the function point list.
[0075] Step S132, traverse all the candidate roles, and calculate the number of function points of the target function points in the function point list covered by each candidate role, recorded as the first number, and calculate the number of function points of other function points covered by each candidate role except the target function point in the function point list, recorded as the second number; the candidate role with the largest first number and the smallest second number is selected as the candidate role.
[0076] In this embodiment, the priority of the first number is higher than that of the second number.
[0077] That is, when selecting the role to be selected based on the first number and the second number, first ensure that the first number is the largest, and then find the one with the smallest second number from the largest first numbers. The corresponding alternative role is the role to be selected. In this way, the conflict that the first number is the largest but the second number is not the smallest (or the second number is the smallest but the first number is not the largest) can be avoided.
[0078] Step S133: remove the target function point associated with the candidate role from the function point list.
[0079] Step S134, repeat the above steps until the function point list does not contain any of the target function points.
[0080] Step S135: recommend the candidate role as the target role to the first user.
[0081] It should be noted that, through the above steps S131 to S135, on the one hand, it is ensured that the number of target roles recommended for the first user is minimal under the premise that the target roles can access all the functional points that the first user wants to access; on the other hand, it is avoided that the first user has more unnecessary permissions.
[0082] The working principle of step S131 to step S135 is further explained below through a specific embodiment.
[0083] In one embodiment, the target function points in the function point list include: function point a, function point b, function point c, function point d, function point e, and function point f.
[0084] Through step S131, all candidate roles associated with the target function point are found to include: role A, role B, role C, and role D.
[0085] Among them, role A not only covers function points a, b, and f in the target function points, but also covers function point g; role B not only covers function points c, d, and e in the target function points, but also covers function points h, i, and m; role C not only covers function points a, d, and f in the target function points, but also covers function points j, k, and l; role D not only covers function points e in the target function points, but also covers function points g and n.
[0086] After step S132, the first number corresponding to character A is 3, and the second number is 1; the first number corresponding to character B is 3, and the second number is 3; the first number corresponding to character C is 3, and the second number is 3; the first number corresponding to character D is 1, and the second number is 2, so character A is selected.
[0087] In step S133, the target function points associated with role A, namely function point a, function point b, and function point f, are removed from the function point list, and the obtained function point list only includes function point c, function point d, and function point e.
[0088] Repeat the above steps, that is, after step S131, the candidate roles include: role B, role C, and role D; after step S132, the first number corresponding to role B is 3, and the second number is 3; the first number corresponding to role C is 1, and the second number is 3; the first number corresponding to role D is 1, and the second number is 2, so role B is selected as the candidate role; after step S133, in the function point list, after the target function points associated with role B, namely function point c, function point d, and function point e are removed, the function point list does not contain any target function points.
[0089] Finally, character A and character B are recommended to the first user as target characters.
[0090] In one embodiment, determining the target role includes: showing the first user a role selected by the first user that is owned by a third user but not owned by the first user, so that the first user can obtain the target role therefrom.
[0091] It should be noted that in this embodiment, a method for determining the target role is provided, which is used in scenarios where it is clear that others (i.e., a third user) have role permissions. By applying for roles owned by others (i.e., copying roles of others), the method can quickly apply for corresponding permissions when the user does not understand the business.
[0092] In one embodiment, the determining the target role includes: receiving a request instruction from the first user, so as to determine the target role based on the request instruction.
[0093] It should be noted that, in this embodiment, a method for determining a target role is provided, which is applied in a scenario where it is clear that a certain role has permissions, and the permissions corresponding to the role are obtained by directly applying for the role.
[0094] Specifically, the first user directly initiates a request instruction corresponding to the application target role on the authority system, so that the authority system directly determines the target role according to the request instruction.
[0095] In one embodiment, the request instruction is a search instruction.
[0096] In one embodiment, the search instruction at least includes but is not limited to: a role name and / or a role code.
[0097] Specifically, the first user knows that the role has certain permissions, and directly searches on the permission system according to the role name and / or role code of the role to determine the role.
[0098] Step S2: receiving a role application work order corresponding to the target role sent by the first user.
[0099] Step S3: receiving the approval result of the second user on the role application work order, so that when the approval result is passed, the first user successfully applies for the target role.
[0100] It should be noted that the second user is a user in the permission system who approves the role application work order, such as the administrator mentioned in the article.
[0101] The protection scope of the role application method described in the embodiment of the present application is not limited to the execution order of the steps listed in this embodiment. All solutions implemented by adding, reducing or replacing steps in the prior art based on the principles of the present application are included in the protection scope of the present application.
[0102] An embodiment of the present invention further provides a permission system, which includes: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory, so that the permission system executes the above-mentioned role application method.
[0103] The embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by the permission system, the above-mentioned role application method is implemented.
[0104] A person of ordinary skill in the art can understand that all or part of the steps in the method for implementing the above-mentioned embodiment can be completed by instructing a processor through a program, and the program can be stored in a computer-readable storage medium, and the storage medium is a non-transitory medium, such as a random access memory, a read-only memory, a flash memory, a hard disk, a solid-state hard disk, a magnetic tape, a floppy disk, an optical disc, and any combination thereof. The above-mentioned storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a digital video disc (DVD)), or a semiconductor medium (for example, a solid-state disk (SSD)), etc.
[0105] The embodiment of the present application also provides a role application device, which can implement the role application method described in the present application, but the implementation device of the role application method described in the present application includes but is not limited to the structure of the role application device listed in this embodiment. All structural deformations and replacements of the prior art made according to the principles of the present application are included in the protection scope of the present application.
[0106] like Figure 5 As shown, in one embodiment, the present invention provides a role application device, which is applied to a permission system, and the device includes:
[0107] The determination module 51 is used to determine the target role when the first user needs to apply for the target role.
[0108] The receiving module 52 is used to receive a role application work order corresponding to the target role sent by the first user.
[0109] The application module 53 is used to receive the approval result of the second user on the role application work order, so that when the approval result is passed, the first user successfully applies for the target role.
[0110] It should be noted that the structures and principles of the determination module 51, the receiving module 52 and the application module 53 correspond one-to-one to the steps (steps S1 to S3) in the above-mentioned role application method, and their specific working principles can also be referred to the introduction to the role application method in the above-mentioned embodiment, so they will not be repeated here.
[0111] In the several embodiments provided in the present application, it should be understood that the disclosed system, device or method can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules / units is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules or units, which can be electrical, mechanical or other forms.
[0112] The modules / units described as separate components may or may not be physically separated, and the components displayed as modules / units may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules / units may be selected according to actual needs to achieve the purpose of the embodiments of the present application. For example, the functional modules / units in the various embodiments of the present application may be integrated into one processing module, or each module / unit may exist physically separately, or two or more modules / units may be integrated into one module / unit.
[0113] Those of ordinary skill in the art should further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0114] The descriptions of the processes or structures corresponding to the above-mentioned figures have different emphases. For parts that are not described in detail in a certain process or structure, please refer to the relevant descriptions of other processes or structures.
[0115] The above embodiments are merely illustrative of the principles and effects of the present application and are not intended to limit the present application. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed in the present application shall still be covered by the claims of the present application.
Claims
1. A role application method, applied in a permission system, characterized in that: The method comprises: When the first user needs to apply for a target role, determining the target role; Receiving a role application work order corresponding to the target role sent by the first user; The approval result of the second user on the role application work order is received, so that when the approval result is passed, the first user successfully applies for the target role.
2. The role application method according to claim 1, characterized in that: Determining the target role includes: Calculate a first function point that the first user does not have permission to access; Determining a target function point that the first user needs to access based on the first function point; The target role is recommended to the first user according to the target function point.
3. The role application method according to claim 2, characterized in that: The permission system stores all function points; The calculating the first function point that the first user has no permission to access comprises: Determining whether the first user already has a role; When it is determined that the first user does not have the already owned role, taking all the function points as the first function points; When it is determined that the first user has the already owned role, querying a second function point associated with the already owned role; the second function point is a function point that the first user has permission to access; The first function point is acquired according to all the function points and the second function point.
4. The role application method according to claim 2, characterized in that: The determining, based on the first function point, the target function point that the first user needs to access comprises: presenting the first function point to the first user, so that the first user directly selects the target function point from the first function point; or When the first user accesses a first function point for which he has no authority, the first function point is automatically selected as the target function point.
5. The role application method according to claim 2, characterized in that: The target function point is stored in a function point list; The recommending the target role to the first user according to the target function point comprises: Find all candidate roles associated with the target function point in the function point list; Traverse all the candidate roles, and calculate the number of function points of each candidate role covering the target function point in the function point list, recorded as the first number, and calculate the number of function points of each candidate role covering other function points except the target function point in the function point list, recorded as the second number; select the candidate role with the largest first number and the smallest second number as the candidate role; the first number has a higher priority than the second number; Eliminate the target function point associated with the candidate role from the function point list; Repeat the above steps until the function point list does not contain any of the target function points; The candidate role is recommended to the first user as the target role.
6. The role application method according to claim 1, characterized in that: The determining the target role includes: showing the first user a role selected by the first user that is owned by a third user but not owned by the first user, so that the first user can obtain the target role therefrom.
7. The role application method according to claim 1, characterized in that: The determining the target role includes: receiving a request instruction from the first user, so as to determine the target role based on the request instruction.
8. A role application device, applied to a permission system, characterized in that: The device comprises: A determination module, used for determining the target role when the first user needs to apply for the target role; A receiving module, configured to receive a role application work order corresponding to the target role issued by the first user; The application module is used to receive the approval result of the second user on the role application work order, so that when the approval result is passed, the first user can successfully apply for the target role.
9. A permission system, characterized in that: The permission system includes: a processor and a memory; The memory is used to store computer programs; The processor is used to execute the computer program stored in the memory, so that the permission system executes the role application method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the permission system, the role application method described in any one of claims 1 to 7 is implemented.