A permission management method, device, apparatus and storage medium

By parsing the configuration attributes and user role information of the request packet, matching the target permission matrix and performing authentication, the problem of insufficient flexibility and granularity of the SVN permission management method in the AXPI server is solved, and more flexible and granular permission management is achieved.

CN120124023BActive Publication Date: 2025-12-09GUANGZHOU ZHIYUAN ELECTRONICS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510061286.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-12-09
Estimated Expiration
2045-01-15

AI Technical Summary

Technical Problem

The existing SVN permission management method lacks flexibility and granularity in AXPI servers, making it difficult to meet the multi-level and cross-role permission requirements of complex systems.

Method used

By receiving request packets, parsing configuration attribute information and user role information, matching the target permission matrix, performing authentication processing, generating registration packets and ID information, dynamic permission management is achieved.

Benefits of technology

It improves the flexibility and granularity of permission management, supports multi-level and cross-role permission management, and enhances the accuracy and security of permission matching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124023B_ABST
    Figure CN120124023B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a permission management method, device and equipment and a storage medium. The technical solution provided by the embodiments of the present application receives a request packet, analyzes and processes the request packet to obtain configuration attribute information and user role information, the type of the request packet includes a registration request packet, a viewing request packet, a downloading request packet, a deletion request packet and an updating request packet, matches the configuration attribute information with a preset permission matrix to determine a target permission matrix, performs authentication processing according to the user role information and the target permission matrix to obtain a permission verification result, and executes a packet operation corresponding to the request packet when the permission verification result is verification success. The technical solution can solve the technical problem of poor flexibility and fineness of permission management, and improve the flexibility and fineness of permission management.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of server, and particularly relate to a permission management method, device, equipment and storage medium. BACKGROUND

[0002] AXPI is a resource management platform under the EsDA (Embedded System Design Automation) ecosystem, and it is a key component of the EsDA toolset. AXPI is a software package management and distribution center, responsible for the management and distribution of various aspects of software development, including development, building, testing, publishing and deployment. It supports cross-platform code reuse, especially in the industrial Internet of Things environment with diverse devices and protocols, ensuring product compatibility and development process efficiency. AXPI plays an important role in the EsDA ecosystem, providing strong support for embedded software development.

[0003] The existing permission management of AXPI server usually uses the SVN (Subversion, version control system) permission management method. The SVN permission management method is usually implemented by defining a static permission mapping of users, user groups and resource paths. In the SVN permission configuration file, the administrator can set read-write permissions for specific resource paths, and these read-write permissions are usually directly bound to users or user groups. Therefore, the SVN permission management method can realize basic permission management of resources, including basic operations such as "read only", "writable" and "no access permission". This SVN permission management method has a certain flexibility and is suitable for small-scale systems or scenarios with relatively fixed resource paths.

[0004] However, with the improvement of the system complexity of the AXPI server, the SVN permission management method has certain limitations. The user role definition in the SVN permission management method is relatively single, and it is difficult to meet the multi-level and cross-role permission requirements in complex systems, so the flexibility and fineness of the existing SVN permission management method are insufficient. SUMMARY

[0005] Embodiments of the present application provide a permission management method, device, equipment and storage medium, which can solve the technical problem of poor flexibility and fineness of permission management, and improve the flexibility and fineness of permission management.

[0006] In a first aspect, embodiments of the present application provide a permission management method for a server, comprising:

[0007] The request packet is received, the request packet is parsed and processed to obtain configuration attribute information and user role information, and the type of the request packet includes a registration request packet, a viewing request packet, a downloading request packet, a deletion request packet and an updating request packet;

[0008] The configuration attribute information is matched with a preset permission matrix to determine a target permission matrix;

[0009] The user role information and the target permission matrix are used for authentication processing to obtain a permission verification result;

[0010] When the permission verification result is verification success, a packet operation corresponding to the request packet is executed.

[0011] In an embodiment, the request packet is a registration request packet;

[0012] When the permission verification result is verification success, a packet operation corresponding to the request packet is executed, including:

[0013] When the permission verification result is verification success, the request packet is associated with the target permission matrix, and registration processing is performed;

[0014] After the registration processing is successful, a registration packet and corresponding ID information are generated, the registration packet is saved to a preset storage location, and the ID information is returned to a client corresponding to the sending request packet.

[0015] Before the request packet is received, the following is included:

[0016] A preset configuration attribute list is read to obtain an attribute value combination;

[0017] The preset permission matrix item is generated according to the attribute value combination;

[0018] The permission matrix item is classified to determine a matrix type configuration, and the matrix type configuration includes a public configuration, a first restriction configuration and a second restriction configuration, wherein the permission of the first restriction configuration is greater than the permission of the second restriction configuration;

[0019] The corresponding permission matrix combination item is obtained according to the permission matrix item and the corresponding matrix type configuration.

[0020] The permission matrix set is generated according to all the permission matrix combinations to obtain a preset permission matrix.

[0021] In an embodiment, the permission matrix set is generated according to all the permission matrix combinations to obtain a preset permission matrix, including:

[0022] A global permission matrix set is generated according to all the permission matrix combinations.

[0023] The role permission configuration trigger signal is received, and in response to the role permission configuration trigger signal, a role permission configuration interface is displayed, and the role permission configuration interface is used for configuring permissions of a product group role and a product role;

[0024] The role to be configured and the inheritance mechanism input based on the role permission configuration interface are received, and the role to be configured is a product group role or a product role, and the product group role and the product role are pre-created roles;

[0025] When the inheritance mechanism is non-inheritance, a first configuration interface is displayed according to the global permission matrix set, and a first permission matrix corresponding to the role to be configured is generated according to configuration information input by the first configuration interface.

[0026] In an embodiment, after receiving the role to be configured and the inheritance mechanism input based on the permission configuration interface, the following steps are included:

[0027] When the inheritance mechanism is inheritance, whether there is a parent role permission matrix is determined according to the role to be configured and a preset parent-child role relationship, and the preset parent-child role relationship includes a parent-child relationship of a product group role and a product group role, a parent-child relationship of a product group role and a product role, and a parent-child relationship of a product role and a product role;

[0028] When the role to be configured has a corresponding parent role permission matrix, a second configuration interface is displayed according to the parent role permission matrix, and a second permission matrix corresponding to the role to be configured is generated according to configuration information input by the second configuration interface;

[0029] When the role to be configured does not have a corresponding parent role permission matrix, a first configuration interface is displayed according to the global permission matrix set, and a first permission matrix corresponding to the role to be configured is generated according to configuration information input by the first configuration interface.

[0030] In an embodiment, the authentication processing is performed according to the user role information and the target permission matrix to obtain a permission verification result, including:

[0031] The user role information is compared with the role configured corresponding to the target permission matrix, and when the user role information belongs to the role configured corresponding to the target permission matrix, it is determined that the permission verification result is verification success.

[0032] In an embodiment, the permission management method further includes:

[0033] A product is generated according to a preset number of registration packages, a product permission matrix set is obtained, the product permission matrix set includes a preset permission matrix corresponding to each registration package in the product, and each preset permission matrix includes a corresponding matrix type configuration;

[0034] A product permission change trigger instruction is received, and in response to the product permission change trigger instruction, a product permission configuration interface is displayed;

[0035] receive the matrix type configuration change instruction input based on the article permission configuration interface;

[0036] change the corresponding matrix type configuration in the article permission matrix set according to the matrix type configuration change instruction.

[0037] In an embodiment, changing the corresponding matrix type configuration in the article permission matrix set according to the matrix type configuration change instruction comprises:

[0038] determining the initial matrix type configuration of each registration package in the article permission matrix set;

[0039] when the matrix type configuration change instruction is the first change instruction, changing the matrix type configuration of the registration package with the initial matrix type configuration as the public configuration to the first limited permission configuration; or changing the matrix type configuration of the registration package with the current matrix type configuration as the second limited permission configuration and the corresponding initial matrix type configuration as the first limited permission configuration to the first limited permission configuration;

[0040] when the matrix type configuration change instruction is the second change instruction, changing the matrix type configuration of the registration package with the initial matrix type configuration as the public configuration or the first limited permission configuration to the second limited permission configuration;

[0041] when the matrix type configuration change instruction is the third change instruction, changing the matrix type configuration of the registration package with the current matrix type configuration as the second limited permission configuration or the first limited permission configuration and the corresponding initial matrix type configuration as the public configuration to the public configuration.

[0042] In a second aspect, the embodiments of the present application provide an article permission management device for a server, comprising:

[0043] a request receiving module, configured to receive a request package, analyze and process the request package to obtain configuration attribute information and user role information, and the type of the request package comprises a registration request package, a viewing request package, a downloading request package, a deleting request package and an updating request package;

[0044] a permission matrix matching module, configured to match the configuration attribute information with a preset permission matrix to determine a target permission matrix;

[0045] an authentication module, configured to perform authentication processing according to the user role information and the target permission matrix to obtain a permission verification result;

[0046] an execution module, configured to perform a package operation corresponding to the request package when the permission verification result is verification success.

[0047] In a third aspect, the embodiments of the present application provide an article permission management device, comprising:

[0048] a memory and one or more processors;

[0049] a memory for storing one or more programs;

[0050] When the one or more programs are executed by the one or more processors, the one or more processors implement the permission management method as in the first aspect.

[0051] In a fourth aspect, the embodiments of the present application provide a storage medium storing computer-executable instructions for executing the permission management method as in the first aspect when executed by a computer processor.

[0052] The embodiments of the present application can automatically match the most suitable target permission matrix through the configuration attribute information of the request package, and dynamically authenticate through the user role information and the target permission matrix, thereby solving the technical problem of poor flexibility and fineness of permission management. The embodiments of the present application match the preset permission matrix to obtain the corresponding target permission matrix through the configuration attribute information, which is compared with the existing permission matching method through personnel roles only. The embodiments of the present application match from multiple dimensions of attribute information, thereby improving the fineness and flexibility of permission matching. Furthermore, the embodiments of the present application perform secondary authentication processing through the user role and the target permission matrix to obtain the corresponding permission verification result. When the permission verification result is verified successfully, the corresponding package operation is executed. The secondary authentication through the user role information realizes multi-level user role permission management, thereby further improving the flexibility and fineness of permission management.

[0053] The above-mentioned permission management apparatus, permission management device and storage medium have the beneficial effects of the permission management method. BRIEF DESCRIPTION OF DRAWINGS

[0054] Figure 1 is a flowchart of a permission management method provided by the embodiments of the present application;

[0055] Figure 2 is a permission relationship diagram provided by the embodiments of the present application;

[0056] Figure 3 is a flowchart of another permission management method provided by the embodiments of the present application;

[0057] Figure 4 is a permission matrix configuration method flowchart provided by an embodiment of the present application;

[0058] Figure 5 is a role permission configuration interface schematic diagram provided by an embodiment of the present application;

[0059] Figure 6 is a permission role architecture schematic diagram provided by an embodiment of the present application;

[0060] Figure 7 is a first configuration interface schematic diagram provided by an embodiment of the present application;

[0061] Figure 8 is a second configuration interface schematic diagram provided by an embodiment of the present application;

[0062] Figure 9 is a product permission change method flowchart provided by an embodiment of the present application;

[0063] Figure 10 is a product permission configuration interface schematic diagram provided by an embodiment of the present application;

[0064] Figure 11 is a permission management device structure schematic diagram provided by an embodiment of the present application;

[0065] Figure 12 is a permission management device structure schematic diagram provided by an embodiment of the present application. DETAILED DESCRIPTION

[0066] In order to make the objects, technical solutions and advantages of the present application clearer, the following further describes specific embodiments of the present application with reference to the drawings. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application. In addition, it should be noted that, for the convenience of description, only parts related to the present application are shown in the drawings and not all contents. Before discussing the example embodiments in more detail, it should be mentioned that some example embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe each operation (or step) as a sequential process, many of the operations can be implemented in parallel, concurrently or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operations are completed, but can also have additional steps not included in the drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.

[0067] The permission management of the existing AXPI server usually uses an SVN (Subversion, version control system) permission management manner. The SVN permission management manner is usually implemented by defining a static permission mapping of users, user groups and resource paths. In the configuration file of the SVN permission, an administrator can set read-write permissions for a specific resource path, and the read-write permissions are usually directly bound to a user or a user group. Therefore, the basic permission management of resources can be realized by the SVN permission management manner, including basic operations such as "read only", "writable" and "no access permission". This SVN permission management method has a certain flexibility and is suitable for small-scale systems or scenarios with relatively fixed resource paths.

[0068] However, with the improvement of the system complexity of the AXPI server, the SVN permission management manner has certain limitations. The SVN permission management manner mainly relies on resource paths as the dimension of permission configuration, and an administrator usually needs to manually define permissions for different paths. This path binding manner increases the configuration complexity on the one hand, and lacks support for dynamic permission requirements on the other hand. For example, when the attributes of resources (such as file types and security levels) change, the path-bound permission model cannot flexibly adjust the permissions, which easily leads to permission mismatch. In addition, the definition of user roles in the SVN permission management manner is relatively single, and it is difficult to meet the multi-level and cross-role permission requirements in complex systems, so the flexibility and fineness of the existing SVN permission management manner are insufficient.

[0069] Based on this, the present application provides a permission management method, apparatus, device, and storage medium to solve the technical problem of poor flexibility and granularity in permission management. The permission management method, apparatus, device, and storage medium provided in this application aim to, during server permission management, parse and process received request packets to obtain configuration attribute information and user role information, match the configuration attribute information with a preset permission matrix to determine a target permission matrix, perform authentication processing based on the user role information and the target permission matrix to obtain a permission verification result, and execute the packet operation corresponding to the request packet when the permission verification result is successful. By employing the aforementioned technical means, the most suitable target permission matrix can be automatically matched through the configuration attribute information of the request packet, and dynamic authentication can be performed through user role information and the target permission matrix. This solves the technical problem of poor flexibility and granularity in permission management. In this embodiment, the target permission matrix is ​​obtained by matching the preset permission matrix through configuration attribute information. Compared with the existing method of matching permissions solely based on personnel roles, this embodiment matches from multiple dimensions of attribute information, thereby improving the granularity and flexibility of permission matching. Furthermore, this embodiment combines user roles and the target permission matrix for secondary authentication to obtain the corresponding permission verification result. The corresponding packet operation is only executed when the permission verification result is successful. Secondary authentication through user role information enables multi-level user role permission management, further improving the flexibility and granularity of permission management.

[0070] The permission management method provided in this embodiment can be executed by a permission management device, which can be implemented by software and / or hardware. The permission management device can consist of two or more physical entities, or it can consist of a single physical entity. Generally, the permission management device can be a computer device.

[0071] Figure 1 This is a flowchart of a permission management method provided in an embodiment of this application. The following description uses a computer device as the subject executing the permission management method. (Refer to...) Figure 1 This permission management method, used on a server, is used to generate a preset permission matrix. Specifically, this permission management method includes:

[0072] S101. Read the preset configuration attribute list and obtain the attribute value combination.

[0073] Figure 2 This is a schematic diagram of a permission relationship provided in an embodiment of this application, referred to as follows. Figure 2In the server management system, there are product group 1, product 11, artifact 111 and package 1111. The concept hierarchy in the server management system exists in a tree structure, and the product group 1 is at the upper level of the product 11. The product group 1 can create new product groups 1 or products 11 downward. It should be noted that artifacts 111 cannot be created within the product group. The product 11 is an entity at the next level of the product group 1, and multiple artifacts 111 can be created within it. It should be noted that new product groups 1 cannot be created within the product 11. The artifact 111 is an entity created within the product 11, and the artifact 111 includes (management) package 1111, files and attachments, and other resources. The package is an entity composed of actual data files and manifest attributes (configuration attributes), and may also include some attachments. In the server management system, the package 1111 represents the basic unit of software development and management process, and the package 1111 refers to a collection of elements including software code, resource files and configuration files, which together form a complete and deployable software unit for implementing specific functions or business logic. The package 1111 can be divided into various types, including but not limited to library package, application package and tool package.

[0074] The package in the artifact has a Manifest attribute (configuration attribute), which can be sorted into a preset configuration attribute list according to common Manifest attributes. For example, the preset configuration attribute list is shown in Table 1.

[0075] Table 1:

[0076]

[0077] Read the preset configuration attribute list to get the attribute value combination. For example, by reading the preset configuration attribute list, different combinations of preset values of each Manifest (configuration) attribute are obtained. It should be noted that the value range of the attribute can only be within the preset range, and if it is not within the preset range, an error will be returned.

[0078] For example, different values of edition, distype and report_type in the configuration attribute list are read and combined to form multiple unique permission items, i.e., multiple attribute value combinations. For example, the value of the edition attribute is lite, standard or pro, the value of the distype attribute is dist or sdist, and the value of the report_type attribute is Unit or Integration. Therefore, the values of the three attributes of edition, distype and report_type can be freely combined to obtain corresponding attribute value combinations, such as standard, dist and unit as one attribute value combination, and standard, dist and integration as another attribute value combination. In this way, all attribute value combinations can be obtained for subsequent establishment of a permission matrix set.

[0079] S102, generating a preset permission matrix item according to the attribute value combination.

[0080] According to the attribute value combination obtained in the foregoing, a preset permission matrix item is generated. For example, the following preset permission matrix items can be obtained: standard+dist+unit, standard+dist+integration, standard+sdist+unit, standard+sdist+integration, lite+dist+unit, lite+dist+integration, lite+sdist+unit, and lite+sdist+integration. For example, standard+dist+unit is one of the permission matrix items, and standard+dist+integration is another permission matrix item.

[0081] S103, performing classification processing according to the permission matrix item to determine a matrix type configuration, and the matrix type configuration includes a public configuration, a first restricted configuration and a second restricted configuration, wherein the permission of the first restricted configuration is greater than the permission of the second restricted configuration.

[0082] Each permission matrix item is associated with a matrix type configuration, and the matrix type configuration is used to limit the visibility level. The matrix type configuration includes a public configuration, a first restricted configuration and a second restricted configuration, wherein the permission of the first restricted configuration is greater than the permission of the second restricted configuration. For example, the public configuration is represented by Public, which means that anyone can access. The first restricted configuration is represented by Private+, which means that only member-specific permission users can see. The second restricted configuration is represented by Private, which means that only member-specific permission users can see. The permission of Private+ is greater than the permission of Private.

[0083] According to the classification processing of the permission matrix item, the matrix type configuration is determined. Each permission matrix item is associated with a matrix type configuration, which can be associated according to actual business needs. For example, the sdist type is configured as Private (i.e., the second restriction configuration) to restrict access to the source code package. The standard version and sdist combination item are configured as Private+ (i.e., the first restriction configuration) to restrict access to sensitive content. It should be noted that if higher permissions are required, a new permission matrix can be configured in the product permission matrix set to meet additional security requirements.

[0084] For example, the association relationship between the permission matrix item and the matrix type configuration is shown in Table 2.

[0085] Table 2:

[0086] Edition Distype Report Type Matrix of Rights Configuration standard dist unit Public standard dist integration Public standard sdist unit Private+ standard sdist integration Private+ lite dist unit Public lite dist integration Public lite sdist unit Private lite sdist integration Private

[0087] S104, according to the permission matrix item and the corresponding matrix type configuration, the corresponding permission matrix combination item is obtained.

[0088] According to the permission matrix item and the corresponding matrix type configuration, the corresponding permission matrix combination item is obtained, for example, according to the permission matrix item standard+dist+unit and the corresponding matrix type configuration Public, the permission matrix combination item is standard+dist+unit+Public.

[0089] S105, according to all the permission matrix combinations, a permission matrix set is generated, and a preset permission matrix is obtained.

[0090] According to all the permission matrix combinations, a permission matrix set is generated, and a preset permission matrix is obtained. It should be noted that the permission matrix set can be a set of permission matrices corresponding to the product, or a set of permission matrices corresponding to the product or product group. Based on the attribute value combination combined with the matrix type configuration, a permission matrix set corresponding to all attribute value combinations can be generated, and the corresponding target permission matrix can be determined according to the attribute value combination of the corresponding package for subsequent authentication.

[0091] The above, by reading the attribute value combination through the preset configuration attribute list, generating a preset permission matrix item according to the attribute value combination, and associating the corresponding matrix type configuration according to the permission matrix item to obtain a permission matrix combination item, and generating a permission matrix set according to all the permission matrix combinations. If higher permission control or corresponding new attribute value combination is needed, the permission matrix combination item can be expanded in the product permission matrix set, and new matrix can be flexibly added to meet the customization demand, so as to realize dynamic expansion and improve the scalability of the permission matrix set. In addition, the corresponding permission matrix set is generated through the attribute value combination, which can support multiple permission matrices and meet diversified needs, thereby improving the scalability; different permission levels can be set according to actual conditions, such as Private and Private+, and new permission matrix can be added in the permission matrix set, thereby improving the flexibility of permission matrix setting; chain configuration is realized through attribute value combination, so that the permission configuration has a more clear management architecture, thereby reducing the complexity of management and improving the work efficiency of permission management.

[0092] In an embodiment, the attribute value can not only directly specify a specific value, but also use an expression for more complex matching and configuration. For example, the specification of the expression includes: supporting wildcards such as "*" and "?" to match attribute values more flexibly. For example, the expression: name=test-*, is used to match all packages whose name starts with test-. The expression: system=linux_*, is used to match all packages of Linux operating system. Logical operators such as "AND" and "OR" are supported for multi-condition combination. For example, the expression: status=stable OR status=alpha, is used to represent packages matching stable state or alpha state. The expression: edition=pro AND distype=dist, is used to match only the compiled library package in the professional edition. Common relational operators such as "=", "!=", ">", and "<" are supported. For example, the expression: version>1.0.0, is used to match all packages whose version is higher than 1.0.0. The expression: stage! = production, is used to match all packages in the non-production stage. Parentheses "(" and ")" are supported to group expressions and set priorities. For example, the expression: (edition=standard OR edition=lite) AND status=stable, is used to match the stable state package of the standard edition or the lightweight edition.

[0093] As Figure 2As shown, the product group 1, the product 11 and the product 111 form a hierarchical structure, the product group 1 includes a plurality of products 11, the product 11 includes a plurality of products 111, and each product 111 is composed of a plurality of packages 1111. Each level can be associated with a set of permission matrices, so as to configure and manage permissions at different levels. Among them, the default value of the set of permission matrices in the product group 1 and the product 11 is consistent with the default permission matrix configured by the system administrator. The set of permission matrices includes a plurality of permission matrices. The product group 1 and the product 11 can configure their own set of permission matrices. The set of permission matrices configured in the product group 1 and the product 11 provides a default permission configuration for the next level. The set of permission matrices of the product 111 has the characteristics of dynamic generation, and the attribute value combination (i.e., chain combination) is generated according to the Manifest attribute (configuration attribute) of the package 1111. Each attribute value can form different combinations, so that the number of matrices contained in the set of permission matrices increases exponentially. For example, the edition attribute has two values, and the distype attribute has two values, so the set of permission matrices contains 4 different permission matrices (i.e., 2x2). The product 111 contains a custom configured product permission, which is used for total switch control, so that the permission matrices of all packages in the product are subject to the constraints of the product permission. Each permission matrix in the set of permission matrices is arranged in order to ensure that the permissions are reduced layer by layer and follow the default semantics. The default semantics can be set as: the permission range of the permission matrix in the front position is wider, and the permission range of the permission matrix in the rear position is gradually reduced.

[0094] The product contains a plurality of packages, and each package contains its own Manifest attribute. Based on the foregoing S101-S105, the set of permission matrices in the product is configured through the Manifest attributes.

[0095] Figure 3 is a flowchart of another permission management method provided by the embodiment of the application. The following takes a computer device as an example of the main body for executing the permission management method, and describes the same. Referring to Figure 3 The permission management method is used for a server, and specifically includes the following steps.

[0096] S201, receiving a request package, and performing analysis and processing on the request package to obtain configuration attribute information and user role information. The type of the request package includes a registration request package, a viewing request package, a downloading request package, a deleting request package and an updating request package.

[0097] The user initiates a permission request based on the corresponding client, and the permission request includes registration, viewing, downloading, deleting, or updating, etc. The corresponding request package is generated based on the corresponding permission request, and the type of the request package includes a registration request package, a viewing request package, a downloading request package, a deleting request package, and an updating request package. The corresponding request package is sent to the server through the client. The server receives the request package and performs parsing processing on the request package to obtain configuration attribute information (i.e., Manifest attribute) and user role information. It should be noted that the user role information at this time is the role information of the user currently sending the request package, which is used for subsequent authentication of the corresponding permission request. Through the above, the received request package is parsed to obtain the corresponding configuration attribute information, and the configuration attribute information can be used to match the permission matrix in the subsequent process to determine which permissions the current request package has.

[0098] For example, the role of the user currently sending the request package in the member information of the product can be obtained through the information in the request package, such as determining that the user role is a manager, a developer, or a tester.

[0099] S202, matching the configuration attribute information with the preset permission matrix to determine a target permission matrix.

[0100] The configuration attribute information (i.e., Manifest attribute) is matched with the preset permission matrix to determine a target permission matrix. For example, it is assumed that the edition attribute is lite, the distype attribute is sdist, the stage attribute is staging, and the report_type attribute is unit. According to Table 2, it can be determined that the corresponding target permission matrix is lite+sdist+unit+staging+Private.

[0101] It should be noted that if the configuration attribute information cannot be matched with the preset permission matrix attribute, it means that the authentication fails, and an authentication failure prompt information is returned to the client that sends the request package, for example, “403” is returned.

[0102] S203, performing authentication processing according to the user role information and the target permission matrix to obtain a permission verification result.

[0103] The user role information and the target permission matrix are used for authentication processing to determine whether the user role information has the permission requested by the corresponding request package. The user role information can be compared with the role configured in the target permission matrix, and when the user role information belongs to the role configured in the target permission matrix, it is determined that the permission verification result is successful.

[0104] The preset role corresponding to each permission matrix is configured, and the permission matrix corresponding to the Private is taken as an example for illustration, as shown in Table 3.

[0105] Table 3

[0106]

[0107] For example, the user role information of the sending request package is a developer, based on the stage attribute obtained by analyzing the request package is staging, and according to Table 3, it is assumed that the request package is an update request package, the developer has the permission of updating in the staging stage, and it is determined that the permission verification result is verification success. For another example, the user role information of the sending request package is a tester, based on the stage attribute obtained by analyzing the request package is staging, and according to Table 3, it is assumed that the request package is an update request package, the tester does not have the permission of updating in the staging stage, and it is determined that the permission verification result is verification failure.

[0108] In an embodiment, a role permission matrix associated with each permission matrix can be configured according to the matrix type of each permission matrix, that is, the corresponding role permission matrix is associated with the public configuration (Public), the corresponding role permission matrix is associated with the first restricted configuration (Private+), and the corresponding role permission matrix is associated with the second restricted configuration (Private), for example, Table 3. It should be noted that the specific permissions in the role permission matrix can be set according to actual conditions, and Table 3 in the embodiment is only used for example.

[0109] It should be noted that when the permission verification result is verification failure, the client sending the request package is returned with a verification failure prompt, for example, “403” is returned.

[0110] It should be noted that the role permission matrix can be additionally set, and the corresponding target permission matrix matching role is queried through the associated mapping relationship. The role permission matrix can also be integrated into the preset permission matrix, and the corresponding configured role is determined according to the corresponding matrix item in the target permission matrix after the target permission matrix is determined. For example, it is assumed that the target permission matrix corresponding to the target permission matrix is lite+sdist+unit+staging+Private, and the current request package is an update request package, so the role corresponding to the target permission matrix is a manager and a developer. Therefore, when the user role information is a manager or a developer, the permission verification result is verification success.

[0111] The above, through the user role information and the target permission matrix, the authentication processing is performed, the user without permission is avoided to perform the corresponding package operation, and the security of the permission management is improved.

[0112] S204, when the permission verification result is verification success, the package operation corresponding to the request package is executed.

[0113] When the permission verification result is verification success, the package operation corresponding to the request package is executed. For example, when the request package is a registration request package, after the authentication process of S201-S203 is passed and it is determined that the permission verification result is verification success, the request package is associated with the target permission matrix, and a registration process is performed. After registration is successful, a registration package and corresponding ID information are generated. The registration package is saved to a preset storage location for subsequent retrieval. The ID information is returned to the client that sent the request package, to inform the client that the corresponding registration request package has been successfully registered, and to facilitate the client to subsequently query, download, update, or delete the registration package based on the ID information. The configuration attribute information obtained by parsing the request package is matched with the target permission matrix, and the role configured by the target permission matrix is determined through the role permission mapping in the target permission matrix, so that only users with specific permissions can successfully register the corresponding registration package. After registration is successful, the request package or the registration package is associated with the target permission matrix, and when other package operations (such as download, update, or deletion) are subsequently performed, the permission information corresponding to the target permission matrix can be directly reused based on the association relationship.

[0114] When the permission verification result is verification success, the package operation corresponding to the request package is executed. For example, when the request package is a viewing request package, a download request package, a deletion request package, or an update request package. The server receives the request package, parses the request package, and obtains configuration attribute information and user role information, wherein the configuration attribute information includes a name attribute, and the name attribute value is the ID information of the corresponding registration package. The corresponding associated target permission matrix is found according to the attribute value of the name attribute, i.e., the ID information of the registration package. If the associated target permission matrix is found, the permission verification process is entered; if the associated target permission matrix is not found, it means that there is no corresponding registration package, and a corresponding prompt information is returned to the corresponding client, for example, “403” is returned. When the associated target permission matrix is found, the permission verification process is performed. The specific permission verification process is the same as that of the S203 step described above, and will not be described here. When it is determined that the permission verification result is success, the corresponding package operation is executed, such as a corresponding viewing operation, a download operation, a deletion operation, or an update operation. After the corresponding package operation is executed, a success response is returned to the client that sent the request package.

[0115] The above describes that the attribute chain configuration of each package in the product is performed, the corresponding permission matrix set is generated, and the permission setting of each package is determined to meet the expectation through the matching rule and the verification mechanism, so that the access permission of different users is strictly controlled, and the security and reliability of the permission management are improved.

[0116] According to the above technical means, the configuration attribute information of the request package can be matched with the target permission matrix, and dynamic authentication is performed according to the user role information and the target permission matrix, so as to solve the technical problems of poor flexibility and precision of permission management. The embodiment realizes the matching of the preset permission matrix according to the configuration attribute information to obtain the corresponding target permission matrix. Compared with the existing permission matching method based on personnel roles, the embodiment improves the precision and flexibility of permission matching by matching from multiple dimensions of attribute information. In addition, the embodiment performs secondary authentication processing according to the user role and the target permission matrix to obtain the corresponding permission verification result. When the permission verification result is verified successfully, the corresponding package operation is performed. The secondary authentication is performed according to the user role information, the multi-level user role permission management is realized, and the flexibility and precision of the permission management are further improved.

[0117] On the basis of the above embodiment, Figure 4 is a permission matrix configuration method flowchart provided by the embodiment of the application, referring to Figure 4 The permission matrix configuration method specifically includes:

[0118] S301, generating a global permission matrix set according to all permission matrix combinations.

[0119] According to the above S101-S105, after the corresponding permission matrix set is obtained, when the corresponding product group or product is created, a global permission matrix set can be generated according to all permission matrix combinations of the corresponding product group or product in the above obtained permission matrix set. The global permission matrix serves as the maximum permission matrix set under the level of the product group or product.

[0120] It should be noted that the global permission matrix set is an initialized default permission matrix set, which is used for initial configuration of the permission matrix when the product group or product is created.

[0121] It should be noted that the product group or product copies the corresponding permission matrix from the global permission matrix as an independent set by default, and is not associated with the global permission matrix in the future.

[0122] S302, receiving a role permission configuration trigger signal, and displaying a role permission configuration interface in response to the role permission configuration trigger signal. The role permission configuration interface is used for permission configuration of the product group role and the product role.

[0123] To improve the hierarchy and order of the permission management structure, when configuring the permission matrix, whether to integrate the permission configuration of the superior (also referred to as the parent) can be selected. When the permission configuration of the superior is selected to be inherited, only the same or smaller permission range of the superior's permission matrix can be further selected to form the permission matrix set of the role. When the permission configuration of the superior is selected not to be inherited, the same or smaller permission range can be selected from the global permission matrix set to form the permission matrix set of the role.

[0124] When configuring the permission, a role permission configuration trigger signal can be received, and a role permission configuration interface is displayed in response to the role permission configuration trigger signal. The role permission configuration interface is used for permission configuration of the product group role and the product role.

[0125] Figure 5 is a schematic diagram of a role permission configuration interface provided by an embodiment of the present application. Referring to Figure 5 When the role permission configuration trigger signal is received, the role permission configuration interface is displayed in response to the role permission configuration trigger signal. In the role permission configuration interface, a selection control 51 of a role to be configured is displayed, and a selection control 52 of whether to inherit is displayed. The role to be configured is a product group role or a product role, and the product group role and the product role are pre-created roles. Figure 6 is a schematic diagram of a permission role architecture provided by an embodiment of the present application. Referring to Figure 6 Taking the creation of the product group 1 as an example for description. The product group 1 is a first-level role hierarchy, and the lower-level hierarchy of the product group 1 includes the product group 11, the product group 12, and the product 1. The lower-level hierarchy of the product group 11 includes the product 111 and the product 112; the lower-level hierarchy of the product group 12 includes the product 121. The lower-level hierarchy of the product 1 includes the product 11, the product 12, and the product 13. The lower-level hierarchy of the product 111 includes the product 1111, the lower-level hierarchy of the product 112 includes the product 1121, and the lower-level hierarchy of the product 121 includes the product 1211.

[0126] S303, receiving a role to be configured and an inheritance mechanism input based on the role permission configuration interface. The role to be configured is a product group role or a product role, and the product group role and the product role are pre-created roles.

[0127] The role to be configured and the inheritance mechanism input based on the role permission configuration interface are received, and the permission matrix of the role to be configured is configured according to the selected inheritance mechanism.

[0128] S304, when the inheritance mechanism is non-inheritance, a first configuration interface is displayed according to the global permission matrix set, and a first permission matrix corresponding to the role to be configured is generated according to the configuration information input by the first configuration interface.

[0129] When the inheritance mechanism is non-inheritance, a first configuration interface is displayed according to the global permission matrix set, and a first permission matrix corresponding to the to-be-configured role is generated according to configuration information input by the first configuration interface. Referring to Figure 5 , it is assumed that the currently selected to-be-configured role is product group 11, and the inheritance selection is "no", so it can be determined that the inheritance mechanism of product group 11 is non-inheritance, and therefore the first configuration interface can be displayed according to the global permission matrix set. Figure 7 is a first configuration interface schematic diagram provided by an embodiment of the present application, referring to Figure 7 , the first configuration interface displayed according to the global permission matrix set, all options in the interface are selectable options. For example Figure 7 , for a developer, the registration permission, the deletion permission, the update permission, the read permission, the product visibility permission and the package visibility permission are configured for the develop stage, the review stage, the staging stage and the production stage. A first permission matrix corresponding to the to-be-configured role is generated according to the configuration information input by the first configuration interface. The first permission matrix at this time is the permission matrix of product group 11.

[0130] S305, when the inheritance mechanism is inheritance, it is determined whether there is a parent role permission matrix according to the to-be-configured role and the preset parent-child role relationship. The preset parent-child role relationship includes the parent-child relationship of product group roles, the parent-child relationship of product group roles and product roles, and the parent-child relationship of product roles.

[0131] When the inheritance mechanism is inheritance, it is determined whether there is a parent role permission matrix according to the to-be-configured role and the preset parent-child role relationship. The preset parent-child role relationship includes the parent-child relationship of product group roles, the parent-child relationship of product group roles and product roles, and the parent-child relationship of product roles. Referring to Figure 6 , the parent-child relationship in product group 1 is: product group 1 is the parent of product group 11, product group 12 and product 1, that is, product group 11, product group 12 and product 1 are the children of product group 1. Similarly, it can be known that product group 11 is the parent of product 111 and product 112, that is, product 111 and product 112 are the children of product group 11. Similarly, it can be known that product group 12 is the parent of product 121, that is, product 121 is the child of product group 12. Therefore, according to the pre-created relationship between product groups and products, the preset parent-child role relationship can be obtained. When the inheritance mechanism is inheritance, it is determined whether there is a parent role permission matrix according to the to-be-configured role and the preset parent-child role relationship. Referring to Figure 5-6, assuming that the currently selected role to be configured is product 111, whether the inheritance selection is "yes", so it can be determined that the inheritance mechanism of product 111 is inheritance, and according to the role to be configured product 111 and the preset parent-child role relationship, it can be determined that there is a parent role permission matrix, which is the permission matrix corresponding to product group 11, that is, the first permission matrix mentioned above. For example, assuming that the currently selected role to be configured is product group 11, whether the inheritance selection is "yes", so it can be determined that the inheritance mechanism of product group 11 is inheritance, and according to the role to be configured product group 11 and the preset parent-child role relationship, it can be determined that there is no parent role permission matrix, so the product group 1 at this time is the top level.

[0132] S306, when the role to be configured exists corresponding parent role permission matrix, display the second configuration interface according to the parent role permission matrix, and generate the second permission matrix corresponding to the role to be configured according to the configuration information input by the second configuration interface.

[0133] When the role to be configured exists corresponding parent role permission matrix, display the second configuration interface according to the parent role permission matrix, and the second configuration interface is generated based on the corresponding parent role permission matrix, so it can only be further configured in the permission corresponding to the parent role permission matrix, and cannot exceed the permission range corresponding to the parent role permission matrix. Figure 8 is a second configuration interface schematic diagram provided by an embodiment of the present application, referring to Figure 8 , assuming that the role to be configured is product 111, and its corresponding parent role is product group 11, so the parent role permission matrix of the current role to be configured is Figure 7 generated by the corresponding first configuration interface, so the second configuration interface Figure 8 The selectable options (blank selection controls) in the second configuration interface are Figure 7 corresponding selected options (that is, the selected options marked with "√" in Figure 7 ). That is, Figure 8 The gray selection controls in corresponding selected options (that is, the selected options marked with "√" in

[0134] ). That is,

[0135] When the to-be-configured role does not have a corresponding parent role permission matrix, for example, the product group 1 belongs to a product group that does not have a corresponding parent role permission matrix, a first configuration interface is displayed according to the global permission matrix set, and a first permission matrix corresponding to the to-be-configured role is generated according to the configuration information input by the first configuration interface (for example Figure 7 ).

[0136] When the product group or product enables the "inherit" option, that is, the inheritance mechanism is determined to be inheritance, the permission matrix set will automatically inherit the permission matrix from the parent (i.e., the product group or product at the upper level), rather than being selected from the global permission matrix set. This permission inheritance means that the permission matrix set can be passed down along the hierarchical structure, following the "parent-child" relationship, thereby improving the orderliness of the permission matrix configuration, preventing subsequent mismatching, and thus improving the reliability of the permission management.

[0137] It should be noted that the initial configuration of inheritance can be dynamically synchronized according to the configuration of the parent permission matrix, and subsequent modifications of the corresponding permissions can only reduce permissions based on the original inherited permission matrix, but cannot increase permissions, that is, subsequent modifications cannot exceed the permission range of the initial configuration of the permission matrix.

[0138] By defining the global permission matrix of the system configuration, the inheritance and custom configuration of the permission matrix of the product group and the product are supported, the permission configuration is divided into different levels and the inheritance mechanism is implemented, the flexibility and refinement of the permission configuration are improved, and thus the permission requirements of different user roles are met. In addition, through the permission matrix inheritance mechanism of the system, product group and product hierarchy, it is determined that the parent permission matrix can be automatically integrated after the initial configuration of the permission matrix, thereby ensuring the consistency and rationality of the permissions between different levels. The permission inheritance mode can be flexibly adjusted, for example, whether to inherit in the product group or product, improving the convenience of user permission configuration, and thus improving the user experience. The existing permission management method only supports one-to-one static association, which is difficult to maintain consistency in multiple levels. The present embodiment solves the technical problem that it is difficult to maintain consistency in multiple levels by means of multi-level inheritance and automatic synchronization, thereby improving the stability and reliability of the permission configuration.

[0139] On the basis of the above implementation, Figure 9 is a product permission change method flowchart provided by an embodiment of the present application, referring to Figure 9 , the product matrix type configuration change method specifically includes:

[0140] S401, generating an article according to a preset number of registration packages, obtaining an article permission matrix set, the article permission matrix set including a preset permission matrix corresponding to each registration package in the article, and each preset permission matrix including a corresponding matrix type configuration.

[0141] In the foregoing permission management mode of S201-S204, after the registration processing of the registration request package is performed, the corresponding registration package can be obtained. The corresponding article is generated according to a preset number of registration packages, and an article permission set is obtained. The article permission set takes the permission matrix set of the product as an alternative. The article permission matrix set includes a preset permission matrix corresponding to each registration package in the article, and each preset permission matrix includes a corresponding matrix type configuration.

[0142] S402, receiving an article permission change trigger instruction, and displaying an article permission configuration interface in response to the article permission change trigger instruction.

[0143] In an actual permission management process, the article permission can be changed. When it is necessary to change the article permission, the user can send an article permission change trigger instruction through the corresponding client. The server receives the article permission change trigger instruction, displays an article permission configuration interface in response to the article permission change trigger instruction, and the article permission configuration interface is used to change the article permission.

[0144] Figure 10 is a schematic diagram of an article permission configuration interface provided by an embodiment of the present application, referring to Figure 10 In the article permission configuration interface, the selection control of the corresponding matrix type configuration is limited, for example, the selection control 101 of Public, the selection control 102 of Private+, and the selection control 103 of Private.

[0145] S403, receiving a matrix type configuration change instruction input based on the article permission configuration interface.

[0146] The matrix type configuration change instruction input based on the article permission configuration interface can be generated by triggering the corresponding selection control, for example, triggering the selection control 101 of Public, the selection control 102 of Private+, or the selection control 103 of Private.

[0147] S404, changing the corresponding matrix type configuration in the article permission matrix set according to the matrix type configuration change instruction.

[0148] According to the matrix type configuration change instruction, the corresponding matrix type configuration in the product right matrix set is changed. The initial matrix type configuration of each registration package in the product right matrix set can be determined, for example, the initial matrix type configuration is Public (i.e., public configuration), Private+ (i.e., first restricted right configuration), or Private (i.e., second restricted right configuration). When the matrix type configuration change instruction is a first change instruction, the matrix type configuration of the registration package whose initial matrix type configuration is the public configuration is changed to the first restricted right configuration; or the matrix type configuration of the registration package whose current matrix type configuration is the second restricted right configuration and whose corresponding initial matrix type configuration is the first restricted right configuration is changed to the first restricted right configuration. The first change instruction can be understood as an instruction for changing the current matrix type configuration to the first restricted right configuration. It should be noted that the change of the matrix type configuration cannot exceed the right range of the initial matrix type configuration, that is, the matrix type configuration of the registration package whose initial matrix type configuration is the second restricted right configuration cannot be changed to the first restricted right configuration or the public configuration. For example, the user triggers the selection control 102 of Private+ based on the product right configuration interface to generate a first change instruction. When the current matrix type configuration is changed to the first restricted right configuration (i.e., Private+) according to the first change instruction, the matrix type configuration of the registration package whose initial matrix type configuration is the public configuration (i.e., Public) can be changed to the first restricted right configuration, and the matrix type configuration of the registration package whose current matrix type configuration is the second restricted right configuration (i.e., Private) and whose corresponding initial matrix type configuration is the first restricted right configuration (i.e., Private+) can be changed to the first restricted right configuration (i.e., Private+); the matrix type configuration of the registration package whose current matrix type configuration is the first restricted right configuration (i.e., Private+) remains unchanged.

[0149] When the matrix type configuration change instruction is a second change instruction, the matrix type configuration of the registration package whose initial matrix type configuration is the public configuration or the first restricted right configuration is changed to the second restricted right configuration. The second change instruction can be understood as an instruction for changing the current matrix type configuration to the second restricted right configuration. For example, the user triggers the selection control 103 of Private based on the product right configuration interface to generate a second change instruction. When the current matrix type configuration is changed to the second restricted right configuration (i.e., Private) according to the second change instruction, the matrix type configuration of the registration package whose initial matrix type configuration is the public configuration (i.e., Public) or the first restricted right configuration (i.e., Private+) can be changed to the second restricted right configuration (i.e., Private), and the matrix type configuration of the registration package whose current matrix type configuration is the second restricted right configuration (i.e., Private) remains unchanged.

[0150] When the matrix type configuration change instruction is the third change instruction, the current matrix type configuration is changed to the second limited permission configuration or the first limited permission configuration, and the corresponding initial matrix type configuration of the registration package is changed to the public configuration. The third change instruction can be understood as changing the current matrix type configuration to the public configuration. It should be noted that the change of the matrix type configuration cannot exceed the permission range of the initial matrix type configuration, that is, only the matrix type configuration of the registration package with the initial matrix type configuration as the public configuration can be changed to the public configuration; the matrix type configuration of the registration package with the initial matrix type configuration as the second limited permission configuration and the first limited permission configuration cannot be changed to the public configuration. For example, the user triggers the selection control 101 of Public based on the artifact permission configuration interface, and generates the third change instruction. When the matrix type configuration is changed to the public configuration according to the third change instruction, the matrix type configuration of the registration package with the current matrix type configuration as the second limited permission configuration and the initial matrix type configuration as the public configuration can be changed to the public configuration; the matrix type configuration of the registration package with the current matrix type configuration as the first limited permission configuration and the corresponding initial matrix type configuration as the public configuration can be changed to the public configuration; and the matrix type configuration of the registration package corresponding to the current matrix type configuration as the public configuration remains unchanged.

[0151] The above-mentioned shrinking and expanding of the matrix type configuration of the artifact permission matrix set improves the flexibility of the artifact permission configuration. In addition, on the basis of realizing the shrinking and expanding mechanism of the artifact permission, it is ensured that the permission matrix will not exceed the range of the initial matrix type configuration, effectively preventing the mismatch problem in the permission configuration process, thereby enhancing the security of the permission management.

[0152] The above-mentioned generation mechanism of the permission matrix configured by the attribute value combination can generate a preset permission matrix according to different attribute values of the package, allow flexible configuration of different package attributes (such as release type, version, and state), and realize fine-grained permission control. The user only needs to configure the attribute value, and the system can automatically match the target permission matrix that best meets the conditions, avoiding manual configuration errors, thereby improving the automation of the permission matrix configuration; compared with the existing manual permission configuration method, the present embodiment reduces the configuration difficulty and improves the configuration accuracy by automatically configuring and dynamically generating the permission matrix set.

[0153] The existing permission management mode is often limited by fixed permission templates and is difficult to expand. The embodiment can dynamically adjust the scope of permissions according to actual needs by setting a permission matrix set and a dynamic management mechanism of product permissions, so that new permission matrices can be further added on the basis of preset permission matrices such as "Public, Private and Private+". In addition, the embodiment also supports wildcards and expressions, which can flexibly cope with various combinations of attribute values, so that the permission management system is more expandable, and the customization and expandability of permission configuration are improved.

[0154] Through automatic configuration and intelligent matching, the learning cost of users in the use process is reduced.

[0155] On the basis of the above embodiment, Figure 11 A structural schematic diagram of a permission management device provided by the embodiment of the application is provided. Referring to Figure 11 The permission management device provided by the embodiment is used for a server, and specifically includes a request receiving module 21, a permission matrix matching module 22, an authentication module 23 and an execution module 24.

[0156] The request receiving module 21 is configured to receive a request packet, analyze and process the request packet to obtain configuration attribute information and user role information, and the type of the request packet includes a registration request packet, a viewing request packet, a downloading request packet, a deletion request packet and an updating request packet.

[0157] The permission matrix matching module 22 is configured to match the configuration attribute information with a preset permission matrix to determine a target permission matrix.

[0158] The authentication module 23 is configured to perform authentication processing according to the user role information and the target permission matrix to obtain a permission verification result.

[0159] The execution module 24 is configured to execute a packet operation corresponding to the request packet when the permission verification result is verification success.

[0160] In an embodiment, the request packet is a registration request packet.

[0161] The execution module 24 includes a registration submodule and a registration information returning submodule.

[0162] The registration submodule is configured to associate the request packet with the target permission matrix and perform registration processing when the permission verification result is verification success.

[0163] The registration information returning submodule is configured to generate a registration packet and corresponding ID information after the registration processing is successful, save the registration packet to a preset storage location, and return the ID information to a client corresponding to the sending request packet.

[0164] In an embodiment, the permission management apparatus comprises an attribute combination module, a matrix item generation module, a matrix type configuration determination module, a matrix combination item determination module and a permission matrix generation module;

[0165] The attribute combination module is configured to read a preset configuration attribute list to obtain an attribute value combination.

[0166] The matrix item generation module is configured to generate a preset permission matrix item according to the attribute value combination.

[0167] The matrix type configuration determination module is configured to determine a matrix type configuration according to the permission matrix item, the matrix type configuration comprising a public configuration, a first restriction configuration and a second restriction configuration, wherein the permission of the first restriction configuration is greater than the permission of the second restriction configuration.

[0168] The matrix combination item determination module is configured to obtain a corresponding permission matrix combination item according to the permission matrix item and the corresponding matrix type configuration.

[0169] The permission matrix generation module is configured to generate a permission matrix set according to all the permission matrix combination items to obtain a preset permission matrix.

[0170] In an embodiment, the permission matrix generation module comprises a global set generation submodule, a role configuration interface generation submodule, a configuration information receiving submodule and a non-inheritance configuration submodule.

[0171] The global set generation submodule is configured to generate a global permission matrix set according to all the permission matrix combination items.

[0172] The role configuration interface generation submodule is configured to receive a role permission configuration trigger signal, and display a role permission configuration interface in response to the role permission configuration trigger signal, the role permission configuration interface being used for configuring a product group role and a permission of a product role.

[0173] The configuration information receiving submodule is configured to receive a to-be-configured role and an inheritance mechanism based on an input of the role permission configuration interface, the to-be-configured role being a product group role or a product role, the product group role and the product role being pre-created roles.

[0174] The non-inheritance configuration submodule is configured to display a first configuration interface according to the global permission matrix set when the inheritance mechanism is non-inheritance, and generate a first permission matrix corresponding to the to-be-configured role according to configuration information input by the first configuration interface.

[0175] In an embodiment, the permission matrix generation module further comprises a parent-child role relationship determination submodule, a first inheritance configuration submodule and a second inheritance configuration submodule.

[0176] The parent-child role relationship determination submodule is configured to determine, when the inheritance mechanism is inheritance, whether a parent role permission matrix exists according to the to-be-configured role and a preset parent-child role relationship, the preset parent-child role relationship including a product group role and a parent-child relationship of the product group role, a product group role and a product role, and a product role and a product role.

[0177] The first inheritance configuration submodule is configured to display a second configuration interface according to the parent role permission matrix when the to-be-configured role has a corresponding parent role permission matrix, and generate a second permission matrix corresponding to the to-be-configured role according to configuration information input by the second configuration interface.

[0178] The second inheritance configuration submodule is configured to display a first configuration interface according to the global permission matrix set when the to-be-configured role does not have a corresponding parent role permission matrix, and generate a first permission matrix corresponding to the to-be-configured role according to configuration information input by the first configuration interface.

[0179] On the basis of the above implementation, the authentication module 23 is further configured to compare the user role information with a role corresponding to the target permission matrix, and determine that the permission verification result is a verification success when the user role information belongs to the role corresponding to the target permission matrix.

[0180] In an embodiment, the permission management apparatus further includes a product generation module, a product permission configuration interface generation module, a change instruction receiving module, and a permission change module.

[0181] The product generation module is configured to generate a product according to a preset number of registration packages, and obtain a product permission matrix set, the product permission matrix set including a preset permission matrix corresponding to each registration package in the product, and each preset permission matrix including a corresponding matrix type configuration.

[0182] The product permission configuration interface generation module is configured to receive a product permission change trigger instruction, and display a product permission configuration interface in response to the product permission change trigger instruction.

[0183] The change instruction receiving module is configured to receive a matrix type configuration change instruction input based on the product permission configuration interface.

[0184] The permission change module is configured to change the corresponding matrix type configuration in the product permission matrix set according to the matrix type configuration change instruction.

[0185] In an embodiment, the permission change module includes an initial configuration determination submodule, a first change submodule, a second change submodule, and a third change submodule.

[0186] The initial configuration determination submodule is configured to determine an initial matrix type configuration of each registration package in the product permission matrix set.

[0187] The first changing submodule is configured to change the matrix type configuration of the registration package from the initial matrix type configuration to the first limited permission configuration when the matrix type configuration changing instruction is the first changing instruction; or change the matrix type configuration of the registration package from the current matrix type configuration to the first limited permission configuration and from the corresponding initial matrix type configuration to the first limited permission configuration.

[0188] The second changing submodule is configured to change the matrix type configuration of the registration package from the initial matrix type configuration or the first limited permission configuration to the second limited permission configuration when the matrix type configuration changing instruction is the second changing instruction.

[0189] The third changing submodule is configured to change the matrix type configuration of the registration package from the current matrix type configuration to the second limited permission configuration or the first limited permission configuration and from the corresponding initial matrix type configuration to the public configuration when the matrix type configuration changing instruction is the third changing instruction.

[0190] The permission management apparatus provided by the embodiments of the present application can be used to execute the permission management method provided by the above embodiments, and has the corresponding functions and beneficial effects.

[0191] The embodiments of the present application provide a permission management device, referring to Figure 12 The permission management device includes a processor 31, a memory 32, a communication module 33, an input device 34, and an output device 35. The number of processors in the permission management device can be one or more, and the number of memories in the permission management device can be one or more. The processor, the memory, the communication module, the input device, and the output device of the permission management device can be connected through a bus or other means.

[0192] The memory 32, as a computer readable storage medium, can be used to store software programs, computer executable programs and modules, such as program instructions / modules corresponding to the permission management method of any embodiment of the present application (for example, the request receiving module, the permission matrix matching module, the authentication module and the execution module in the permission management apparatus). The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and application programs required by at least one function; the data storage area can store data created according to the use of the device, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device or other non-volatile solid-state memory device. In some examples, the memory can further include a memory remotely arranged with respect to the processor, which can be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network and a combination thereof.

[0193] The communication module 33 is used for data transmission.

[0194] The processor 31 executes various functional applications and data processing of the device by running the software programs, instructions and modules stored in the memory, that is, implements the above-mentioned permission management method.

[0195] The input device 34 can be used to receive input digital or character information, and generate key signal input related to user settings and function control of the device. The output device 35 can include a display device such as a display screen.

[0196] The above-mentioned permission management device can be used to execute the permission management method provided by the above-mentioned embodiments, and has corresponding functions and beneficial effects.

[0197] The embodiment of the present application also provides a storage medium storing computer executable instructions, which, when executed by a computer processor, are used to execute a permission management method, the permission management method comprising: receiving a request package, performing analysis processing on the request package to obtain configuration attribute information and user role information, the type of the request package including a registration request package, a viewing request package, a downloading request package, a deletion request package and an update request package; matching the configuration attribute information with a preset permission matrix to determine a target permission matrix; performing authentication processing according to the user role information and the target permission matrix to obtain a permission verification result; and when the permission verification result is verification success, performing a package operation corresponding to the request package.

[0198] Storage medium - any type of memory device or storage device. The term "storage medium" is intended to include an installation medium, e.g., a CD-ROM, floppy disks, or tape apparatus; computer system memory or random access memory such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; or a non-volatile memory such as a magnetic medium (e.g., a hard drive or optical storage); registers or other similar types of memory elements, etc. The memory medium can also include other types of storage medium or combinations thereof. In addition, the memory medium can reside in a first computer system's main memory, or in a second different computer system's memory, which second computer system can provide the first computer system with an interface in order to perform a program stored in the memory medium. The term "storage medium" can also be synonymous with a "memory medium" where the two terms are used interchangeably. The memory medium can store program instructions executable by one or more processors (e.g., as a computer program).

[0199] Of course, the storage medium storing computer executable instructions provided by the embodiments of the present application is not limited to the permission management method as described above, and can also execute the related operations in the permission management method provided by any of the embodiments of the present application.

[0200] The permission management apparatus, the storage medium and the permission management device provided in the above embodiments can execute the permission management method provided by any of the embodiments of the present application, and the technical details not described in detail in the above embodiments can refer to the permission management method provided by any of the embodiments of the present application.

[0201] The above are only the preferred embodiments of the present application and the technical principles applied. The present application is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments and replacements made by those skilled in the art will not deviate from the protection scope of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments, and can also include more other equivalent embodiments without deviating from the concept of the present application, and the scope of the present application is determined by the scope of the claims.

Claims

1. A rights management method, characterized by, A server comprises: reading a preset configuration attribute list to obtain an attribute value combination, generating a preset permission matrix item according to the attribute value combination, performing classification processing according to the permission matrix item, determining a matrix type configuration, obtaining a corresponding permission matrix combination item according to the permission matrix item and the corresponding matrix type configuration, generating a global permission matrix set according to all the permission matrix combinations, receiving a role permission configuration trigger signal, displaying a role permission configuration interface in response to the role permission configuration trigger signal, the role permission configuration interface being used for configuring a product group role and a permission of a product role, receiving a to-be-configured role and an inheritance mechanism input based on the role permission configuration interface, the to-be-configured role being a product group role or a product role, the product group role and the product role being pre-created roles, when the inheritance mechanism is non-inheritance, displaying a first configuration interface according to the global permission matrix set and generating a first permission matrix corresponding to the to-be-configured role according to configuration information input by the first configuration interface; receiving a request packet, performing analysis processing on the request packet to obtain configuration attribute information and user role information, the type of the request packet including a registration request packet, a viewing request packet, a downloading request packet, a deletion request packet and an updating request packet; matching the configuration attribute information with a preset permission matrix to determine a target permission matrix; performing authentication processing on the user role information and the target permission matrix to obtain a permission verification result; when the permission verification result is verification success, performing a packet operation corresponding to the request packet.

2. The method of claim 1, wherein the request packet is a registration request packet; when the permission verification result is verification success, performing a packet operation corresponding to the request packet, comprises: when the permission verification result is verification success, associating the request packet with the target permission matrix and performing registration processing; after the registration processing is successful, generating a registration packet and corresponding ID information, saving the registration packet to a preset storage location, and returning the ID information to a client corresponding to the request packet.

3. The method of claim 1, wherein, The matrix type configuration includes an open configuration, a first restriction configuration and a second restriction configuration, wherein the permission of the first restriction configuration is greater than the permission of the second restriction configuration.

4. The method of claim 1, wherein, After receiving the to-be-configured role and the inheritance mechanism input based on the permission configuration interface, comprising: when the inheritance mechanism is inheritance, determining whether there is a parent role permission matrix according to the to-be-configured role and a preset parent-child role relationship, the preset parent-child role relationship including a parent-child relationship of a product group role and a product group role, a parent-child relationship of a product group role and a product role, and a parent-child relationship of a product role and a product role; when the to-be-configured role has a corresponding parent role permission matrix, displaying a second configuration interface according to the parent permission matrix, and generating a second permission matrix corresponding to the to-be-configured role according to configuration information input by the second configuration interface; When the to-be-configured role does not have a corresponding parent role permission matrix, a first configuration interface is displayed according to the global permission matrix set, and a first permission matrix corresponding to the to-be-configured role is generated according to configuration information input by the first configuration interface.

5. The method of claim 1, wherein, The authentication processing according to the user role information and the target permission matrix includes: The user role information is compared with a role configured by the target permission matrix, and when the user role information belongs to the role configured by the target permission matrix, it is determined that the permission verification result is verification success.

6. The method of claim 1, wherein, The method further includes: A product permission matrix set is obtained by generating a product according to a preset number of registration packages, the product permission matrix set including a preset permission matrix corresponding to each registration package in the product, and each preset permission matrix including a corresponding matrix type configuration; A product permission configuration interface is displayed in response to a product permission change trigger instruction; A matrix type configuration change instruction is received based on the product permission configuration interface; The corresponding matrix type configuration in the product permission matrix set is changed according to the matrix type configuration change instruction.

7. The method of claim 6, wherein, The corresponding matrix type configuration in the product permission matrix set is changed according to the matrix type configuration change instruction, including: An initial matrix type configuration of each registration package in the product permission matrix set is determined; When the matrix type configuration change instruction is a first change instruction, the initial matrix type configuration of a registration package with a public configuration is changed to a first limited permission configuration, or the current matrix type configuration is changed to a second limited permission configuration and the initial matrix type configuration of a registration package with a first limited permission configuration is changed to the first limited permission configuration; When the matrix type configuration change instruction is a second change instruction, the initial matrix type configuration of a registration package with a public configuration or a first limited permission configuration is changed to a second limited permission configuration; When the matrix type configuration change instruction is a third change instruction, the initial matrix type configuration of a registration package with a public configuration or a first limited permission configuration is changed to a public configuration.

8. A rights management apparatus characterized by comprising: For a server, including: An attribute combination module configured to read a preset configuration attribute list to obtain an attribute value combination; A matrix item generation module configured to generate a preset permission matrix item according to the attribute value combination; A matrix type configuration determination module configured to classify the permission matrix item to determine a matrix type configuration; A matrix combination item determination module configured to obtain a corresponding permission matrix combination item according to the permission matrix item and the corresponding matrix type configuration; A global set generation submodule configured to generate a global permission matrix set according to all the permission matrix combination items; and A server, including: An attribute combination module configured to read a preset configuration attribute list to obtain an attribute value combination; A matrix item generation module configured to generate a preset permission matrix item according to the attribute value combination; A matrix type configuration determination module configured to classify the permission matrix item to determine a matrix type configuration; A matrix combination item determination module configured to obtain a corresponding permission matrix combination item according to the permission matrix item and the corresponding matrix type configuration; A global set generation submodule configured to generate a global permission matrix set according to all the permission matrix combination items; and A server, including: An attribute combination module configured to read a preset configuration attribute list to obtain an attribute value combination; A matrix item generation module configured to generate a preset permission matrix item according to the attribute value combination; A matrix type configuration determination module configured to classify the permission matrix item to determine a matrix type configuration; A matrix combination item determination module configured to obtain a corresponding permission matrix combination item according to the permission matrix item and the corresponding matrix type configuration; A global set generation submodule configured to generate a global permission matrix set according to all the permission matrix combination items; and The role configuration interface generation submodule is configured to receive a role permission configuration trigger signal, display a role permission configuration interface in response to the role permission configuration trigger signal, and configure the product group role and the product role based on the role permission configuration interface. The configuration information receiving submodule is configured to receive a to-be-configured role and an inheritance mechanism based on the role permission configuration interface, the to-be-configured role being a product group role or a product role, and the product group role and the product role being pre-created roles. The non-inheritance configuration submodule is configured to display a first configuration interface based on the global permission matrix set when the inheritance mechanism is non-inheritance, and generate a first permission matrix corresponding to the to-be-configured role based on configuration information input by the first configuration interface. The request receiving module is configured to receive a request packet, analyze and process the request packet to obtain configuration attribute information and user role information, and the type of the request packet includes a registration request packet, a viewing request packet, a downloading request packet, a deletion request packet, and an update request packet. The permission matrix matching module is configured to match the configuration attribute information with a preset permission matrix to determine a target permission matrix. The authentication module is configured to perform authentication processing based on the user role information and the target permission matrix to obtain a permission verification result. The execution module is configured to execute a packet operation corresponding to the request packet when the permission verification result is verification success.

9. A rights management device, characterized by The method comprises: a memory and one or more processors; the memory is configured to store one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method according to any one of claims 1-7.

10. A storage medium storing computer-executable instructions, wherein: The computer executable instructions, when executed by the processor, are configured to perform the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Role and attribute-based hybrid permission access control method and device

    CN118114272A