Role-based authority control system and method
By defining roles and permissions in the front-end permission control system, the problem of lack of flexibility and scalability in the prior art is solved, and efficient, secure and easy-to-maintain permission management is achieved.
Patent Information
- Application Number
- CN202510223653.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-27
AI Technical Summary
The existing front-end permission control method is based on a fixed permission list, lacks flexibility and scalability, and is difficult to meet complex and changeable business needs.
By defining roles and permissions, assigning permissions to roles, and then assigning roles to users, flexible management and efficient control of permissions are achieved.
Improves the efficiency of permission management, enhances the security and maintainability of the system, improves the user experience, and is easy to expand and maintain.
Smart Images

Figure CN120217335A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer software, and particularly to a role-based permission control system and method. Background Art
[0002] With the popularization of Web and mobile applications, front-end permission control has become crucial for ensuring application security and user experience. Traditional permission control methods often rely on back-end verification, but this approach has problems such as response latency and poor user experience. In recent years, with the rapid development of front-end technologies, the front-back end separation architecture has become mainstream, and the importance of front-end permission control has become even more prominent. However, most existing front-end permission control methods are based on fixed permission lists, lacking flexibility and scalability, and are difficult to meet complex and changing business requirements. Summary of the Invention
[0003] To solve the above technical problems, the present invention provides a role-based permission control system. By defining roles and permissions, assigning permissions to roles, and then assigning roles to users, flexible management and efficient control of permissions are achieved. The method of the present invention not only improves the efficiency of permission management, but also enhances the security and maintainability of the system.
[0004] The technical solution of the present invention is as follows:
[0005] A role-based permission control system, comprising:
[0006] A management module, used for information data management and permission assignment;
[0007] A user front-end module, used for rendering the interface according to the user's permissions;
[0008] A user back-end module, used for providing user permissions to the user front-end.
[0009] Furthermore,
[0010] The management module manages information data, specifically that the management module creates, configures, and maintains user information;
[0011] Maintains role information, determines the basic information, menu permissions, sub-menu permissions, and button permissions within the page of the role;
[0012] Assigns roles to users, and confirms the role type to which the user belongs to determine the user's permissions.
[0013] Furthermore,
[0014] The user front-end realizes permission control, specifically that when the user logs in, the user front-end obtains the user information and automatically stores it;
[0015] Request permission information from the user backend according to the user information, and store it after obtaining the permission information;
[0016] Dynamically render the front-end user interface according to the obtained permission information to implement permission control for the user.
[0017] Among them,
[0018] The user information includes the user's basic information and the user's unique identifier;
[0019] The user can have several roles.
[0020] Furthermore,
[0021] The user backend accepts the request from the user front-end and returns the user permissions. Specifically, the user backend accepts the request information from the user front-end, and queries the user role according to the user information;
[0022] Query the permissions corresponding to the user's role according to the queried user role; the user backend returns the obtained user permissions to the user front-end.
[0023] In addition, the present invention also provides a role-based permission control method, including the following steps:
[0024] 1) Information data management and permission allocation;
[0025] 2) Render the interface according to the user's permissions;
[0026] 3) Provide user permissions to the user front-end.
[0027] Furthermore,
[0028] Step 1) specifically includes: creating a configuration to maintain user information;
[0029] Maintain role information and determine the permissions of the role.
[0030] Assign roles to users, confirm the role type to which the user belongs, and thus determine the user's permissions.
[0031] Among them,
[0032] The user information includes the user's basic information and the user's unique identifier;
[0033] The user can have several roles.
[0034] Furthermore,
[0035] Step 2) specifically includes: obtaining user information and automatically storing it;
[0036] Request permission information from the user backend according to the user information, and store it after obtaining the permission information.
[0037] Dynamically render the front-end user interface according to the obtained permission information to implement user permission control.
[0038] Furthermore,
[0039] Step 3) specifically includes: accepting the request from the user front-end and returning the user permissions, accepting the request information from the user front-end by the user back-end, and querying the user role according to the user information;
[0040] Query the permissions corresponding to the user's role according to the queried user role; return the obtained user permissions to the user front-end.
[0041] The beneficial effects of the present invention are
[0042] Improve the efficiency of permission management: By defining roles and permissions, assigning permissions to roles, and then assigning roles to users, the permission management process is simplified.
[0043] Enhance the system security: The front-end permission control is combined with the back-end verification to effectively prevent unauthorized access and operations.
[0044] Improve the user experience: Dynamically generate the navigation menu and page layout according to the user role to improve the user experience. Easy to expand and maintain: The role and permission definitions are flexible and easy to expand and maintain according to business requirements. Brief Description of the Drawings
[0045] Figure 1 is a schematic diagram of the system structure of the present invention;
[0046] Figure 2 is a schematic diagram of the permission control process. Detailed Embodiments
[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0048] The present invention specifically includes the following steps:
[0049] 1) The management end module manages information data, specifically, the management end module creates, configures, and maintains user information. It should include the basic information of the user and the unique identifier of the user.
[0050] 2) The management end maintains role information, determining the basic information of the role, menu permissions, sub-menu permissions, and button permissions within the page.
[0051] 3) The management end assigns roles to users, confirms the role types to which the users belong so as to determine the users' permissions, and a user can have multiple roles.
[0052] 4) The user front end realizes the control of permissions. Specifically, for user login, the user front end obtains user information and automatically stores it.
[0053] 5) The user end requests permission information from the user back end according to the user information and stores it after obtaining the permission information.
[0054] 6) The user front end dynamically renders the front-end user interface according to the obtained permission information to realize the control of the user's permissions.
[0055] 7) The user back end accepts the request from the user front end and returns the user permissions. Specifically, the user back end accepts the request information from the user front end and queries the user roles according to the user information.
[0056] 8) The user back end queries the permissions corresponding to the user roles according to the queried user roles; the user back end returns the obtained user permissions to the user front end.
[0057] The above are only the preferred embodiments of the present invention, which are only used to illustrate the technical solutions of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.
Claims
1. A role-based permission control system, characterized in that: include: Management module, used for information data management and authority allocation; User front-end module, used to render the interface according to the user's permissions; The user backend module is used to provide user permissions to the user frontend.
2. The system according to claim 1, characterized in that The management module manages information data, specifically the management module creates configuration and maintains user information; Maintain role information, determine the role's basic information, menu permissions, submenu permissions, and button permissions within the page; Assign roles to users and confirm the role type to determine the user's permissions.
3. The system according to claim 1, characterized in that The user front end implements the control of permissions, specifically when the user logs in, the user front end obtains the user information and automatically stores it; Request permission information from the user backend based on the user information, and store the obtained permission information; The front-end user interface is dynamically rendered based on the obtained permission information to implement user permission control.
4. The system according to claim 3, characterized in that User information includes the user's basic information and the user's unique identifier; A user can have several roles.
5. The system according to claim 1, characterized in that The user backend accepts the request from the user frontend and returns the user authority. Specifically, the user backend accepts the request information from the user frontend and queries the user role based on the user information. Query the permissions of the user's corresponding role based on the queried user role; the user backend returns the obtained user permissions to the user frontend.
6. A role-based permission control method, characterized in that: The steps include: 1) Information data management and authority allocation; 2) Render the interface according to the user's permissions; 3) Provide user permissions to the user front end.
7. The method according to claim 6, characterized in that Step 1) specifically includes: creating, configuring and maintaining user information; Maintain role information and determine role permissions. Assign roles to users and confirm the role type to determine the user's permissions.
8. The method according to claim 7, characterized in that User information includes the user's basic information and the user's unique identifier; A user can have several roles.
9. The method according to claim 6, characterized in that Step 2) specifically includes: obtaining user information and automatically storing it; Request permission information from the user backend based on the user information, and store it after obtaining the permission information. The front-end user interface is dynamically rendered based on the obtained permission information to implement user permission control.
10. The method according to claim 6, characterized in that Step 3) specifically includes: accepting the request from the user front end and returning the user authority, accepting the request information from the user front end for the user back end, and querying the user role based on the user information; Query the permissions of the user's corresponding role based on the queried user role; return the obtained user permissions to the user front end.