Integrated authority management method, system and equipment of code-free platform and medium
By creating multiple permission groups on low/no code platforms and merging data scopes, the problem that traditional permission control mechanisms are difficult to achieve fine-grained control is solved, and efficient and secure permission management is achieved.
Patent Information
- Application Number
- CN202510303014.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional permission control mechanisms are difficult to achieve fine-grained control on low/no code platforms, resulting in limited flexibility and efficiency, while increasing the risk of data breaches and abuse.
By creating multiple permission groups, configuring permissions for business objects and operation items, and combining the data scope of different permission groups with business objects and operation items as grouping dimensions, users can realize the permission set of users over business objects and operation items.
It realizes the permission management of fine-grained control, ensuring data security while improving operational flexibility and efficiency, better meeting complex and changeable business needs, and reducing the risk of data leakage.
Smart Images

Figure CN120217433A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of system rapid development, and in particular to an integrated permission management method, system, device and medium for a code-free platform. Background Art
[0002] Traditional permission control mechanisms usually manage the functional permissions of which function modules or operations a user can access separately from the data permissions of which data a user can access or operate on. This separated management mode is sufficient when dealing with static and predefined permission requirements, but it has certain difficulties and thresholds for software development, and there are problems such as insufficient development manpower and rigidity of traditional software.
[0003] However, in modern enterprise information management systems, low / no-code platforms, with their efficient and flexible characteristics, are gradually becoming powerful tools for enterprise digital transformation and quickly responding to market changes. Low / no-code platforms allow users to dynamically create applications through a graphical interface, and complex business logics and data processing can be achieved with little or no coding. Users can create, modify or delete business objects and corresponding operation items at any time according to business requirements. This dynamic nature requires the permission control mechanism to be able to flexibly and finely manage not only who can perform which operations, but also within what data ranges these operations can be performed.
[0004] Currently, when many enterprises use low / no-code platforms, they still adopt traditional and static permission control strategies, which not only limit the flexibility and efficiency of low / no-code platforms, cannot achieve fine-grained control over permissions, but also increase the risks of data leakage and abuse.
[0005] Therefore, there is an urgent need for an integrated permission management method for a code-free platform that can ensure data security while achieving fine-grained control of permissions and improving the flexibility and efficiency of operations. Summary of the Invention
[0006] To overcome the problems existing in the related art, the present disclosure provides an integrated permission management method, system, device and medium for a code-free platform to solve the technical problems in the related art that limit the flexibility and efficiency of the code-free platform, cannot achieve fine-grained control over permissions, and increase the risks of data leakage and abuse.
[0007] One or more embodiments of this specification provide an integrated permission management method for a code-free platform, including the following steps:
[0008] Create multiple permission groups, and assign specific personnel, roles and organizations to each permission group;
[0009] Configure the permissions of business objects and operation items under the business objects for each permission group;
[0010] Taking the business object and the operation item as grouping dimensions, merging the data scopes of different permission groups to obtain the permission set of the user for the business object and the operation item;
[0011] Responding to the user's request, determining the specific personnel, roles and organizations to which the user belongs and the user's permission set, obtaining the query conditions in the user's request, and searching for the permissions that meet the query conditions in the permission set and returning them to the user.
[0012] Preferably, the step of taking the business object and the operation item as grouping dimensions, merging the data scopes of different permission groups to obtain the permission set of the user for the business object and the operation item includes the following steps:
[0013] Searching for the corresponding permission groups according to the specific personnel, roles and organizations to which the user belongs;
[0014] Obtaining the data scopes of the respective permission groups;
[0015] Merging the data scopes of the respective permission groups with the business object and the operation item as grouping dimensions;
[0016] Taking the merged data scope as the permission set of the user for the business object and the operation item.
[0017] Preferably, the step of merging the data scopes of the respective permission groups specifically includes merging the data scopes of the respective permission groups by taking the intersection of the data scopes of the respective permission groups, taking the union of the data scopes of the respective permission groups, and taking the data scopes of the respective permission groups according to the preset permission group priorities.
[0018] Preferably, the permissions of the operation items under the business object include:
[0019] The permission to query the data set that meets the conditions from the database according to specific conditions;
[0020] The permission to operate on known data;
[0021] The permission to operate on the business object.
[0022] Preferably, the step of responding to the user's request, determining the specific personnel, roles and organizations to which the user belongs, and the user's permission set, obtaining the query conditions in the user's request, and searching for the permissions that meet the query conditions in the permission set and returning them to the user further includes the following steps:
[0023] Responding to the user's operation request for the target business, determining the user's permission set, and obtaining the data scope of the operation item corresponding to the operation request;
[0024] Obtain the data range where the data range in the operation request of the user for the target service overlaps with the data range of the corresponding operation item, and return it to the user as the data range of the operation request of the user for the target service.
[0025] Preferably, the following steps are further included:
[0026] In response to the operation request of the user for the target service data, determine the permission set of the user, and obtain the permission of each operation item of the user and the corresponding data range;
[0027] Merge the data ranges corresponding to the permissions of each operation item as the operation data range of the operation request of the user for the target service data.
[0028] One or more embodiments of this specification provide an integrated permission management system for a no-code platform, including a permission group module, a permission configuration module, a permission merging module, and a user access module;
[0029] The permission group module is used to create multiple permission groups, and each permission group is assigned specific personnel, roles, and organizations;
[0030] The permission configuration module is used to configure the business objects of each permission group and the permissions of the operation items under the business objects;
[0031] The permission merging module is used to merge the data ranges of different permission groups with the business object and the operation item as the grouping dimensions to obtain the permission set of the user for the business object and the operation item;
[0032] The user access module is used to respond to the user's request, determine the specific personnel, roles, and organizations to which the user belongs and the user's permission set, obtain the query conditions in the user's request, and find the permissions that meet the query conditions in the permission set and return them to the user.
[0033] Preferably, the permission merging module is further configured to:
[0034] Find the corresponding permission groups according to the specific personnel, roles, and organizations to which the user belongs;
[0035] Obtain the data ranges of the respective permission groups;
[0036] Merge the data ranges of the respective permission groups with the business object and the operation item as the grouping dimensions;
[0037] Use the merged data range as the permission set of the user for the business object and the operation item.
[0038] One or more embodiments of the present specification provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the integrated permission management method of a no-code platform as described above.
[0039] One or more embodiments of the present specification provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the integrated permission management method of a no-code platform as described above.
[0040] The integrated permission management method, system, device, and medium of a no-code platform provided by the present disclosure have the advantage that by creating multiple permission groups, configuring permissions, and assigning specific personnel, roles, and organizations to each permission group, the function permissions and data permissions are assigned in the form of specific personnel, roles, and organizations for unified management. According to the specific personnel, roles, and organizations of each permission group, the business objects, operation items, and permissions of the operation items of each permission group are configured, and the permissions are assigned to the permission groups in a configured form to realize the construction of the no-code platform, avoiding the complex process of coding permission configuration for each user. According to the specific personnel, roles, and organizations to which the user belongs, with business objects and operation items as the grouping dimensions, the data ranges of different permission groups are merged to obtain the permission set of the user for business objects and operation items, and the user permissions are merged to obtain the permission set, which can realize fine-grained control of permission management, improve the flexibility and efficiency of operations while ensuring data security, respond to the user's request, determine the specific personnel, roles, and organizations to which the user belongs, and the user's permission set, obtain the query conditions in the user request, and find the permissions that meet the query conditions in the permission set and return them to the user. By determining the permission group to which the user belongs through the user's role and organization, and configuring different operation data ranges for different operations on business objects within the permission group, fine-grained permission management is achieved. This refined control can better meet complex and changing business requirements while reducing the risk of data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in one or more embodiments of the present specification or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0042] Figure 1 It is a schematic flowchart of an integrated permission management method of a no-code platform provided by one or more embodiments of the present specification;
[0043] Figure 2 Structural diagram of an integrated permission management system for a no-code platform provided for one or more embodiments of this specification;
[0044] Figure 3 Schematic structural diagram of a computer device provided for one or more embodiments of this specification. Detailed implementation manners
[0045] In order to enable those skilled in the art of this technology to better understand the technical solutions in one or more embodiments of this specification, the following will clearly and completely describe the technical solutions in one or more embodiments of this specification with reference to the accompanying drawings in one or more embodiments of this specification. Obviously, the described embodiments are only some of the embodiments of this specification, rather than all the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this invention document.
[0046] The following will make a detailed description of the present invention in combination with the detailed implementation manners and the accompanying drawings of the specification.
[0047] Method embodiments
[0048] No-code / low-code development is a visual application development method that uses a graphical interface with a combination of drag-and-drop components and model-driven logic. No-code / low-code development attempts to lower the barriers to entry for extracting value from software technology platforms, products, and services. Low-code development platforms are referred to as visual integrated development environments (IDEs). Enterprise examples of using no-code / low-code development are testing, learning web applications, websites, the Internet of Things (IoT), artificial intelligence, machine learning, and blockchain, and extracting value from them. No-code / low-code development can help non-technical personnel (such as business analysts, office administrators, and small business owners) build software applications or software application components by dragging and dropping components, forms, reports, etc., without professional developers. Professional developers can also benefit from low-code development by shortening the development time of projects and being able to assign various aspects of the projects to non-technical personnel without programming skills.
[0049] According to an embodiment of the present invention, an integrated permission management method for a no-code platform is provided, as Figure 1 shown, which is a flowchart of the integrated permission management method for the no-code platform provided for this embodiment. The integrated permission management method for the no-code platform according to the embodiment of the present invention includes the following steps:
[0050] S110. Create multiple permission groups G. Each permission group G is assigned specific personnel, roles, and organizations. To address the deficiencies of traditional functional permission and data permission control mechanisms, establish permission groups G for specific personnel, roles, and organizations, bind permissions to users, and improve the granularity of permission management.
[0051] S120. Configure the business objects O of the permission group G, the operation items P under the business object, and the permissions corresponding to the operation items. Among them, the operation items include read operations such as querying the business data list, querying business data details, and exporting data, as well as write operations such as editing data, deleting data, and locking data, and other data read and write operations defined by users.
[0052] The permission classification of the operation items under the business object includes:
[0053] The permission to query a data set that meets the conditions from the database according to specific conditions;
[0054] The permission to operate on known data;
[0055] The permission to operate on business objects.
[0056] Specifically:
[0057] (1) Control the query scope based on permission conditions: Users query a data set that meets the conditions from the database according to specific permission conditions.
[0058] (2) Permission verification for operating on known data: It means that when users know specific data items, the system verifies whether these data items meet the users' operation permissions, so as to determine whether users can perform specific operations on these data items, such as opening data details, editing, deleting, etc.
[0059] (3) Based on the operation permissions of the business object itself, without setting the data scope, only judge "yes" or "no": For example, the "menu" operation item indicates whether the user can operate the business object menu, and the "new" operation item indicates whether the user can create a business document.
[0060] If an operation item P(O) can set the operation scope, that is, P(O) belongs to categories (1) and (2) of the permission control classification of the operation items, then set its corresponding operable data scope. If an operation P(O) cannot set the operation scope, that is, P(O) belongs to category (3) of the permission control classification of the operation items, then check the operation item to indicate that the permission group has the P(O) operation permission, otherwise it means that it does not have the P(O) operation permission. The data scope is defined by the data scope condition C, and the condition C specifies the data screening rules.
[0061] S130. According to the specific personnel, roles, and organizations to which the user belongs, taking business objects and operation items as grouping dimensions, merge the data scopes of different permission groups to obtain the user's permission set for business objects and operation items.
[0062] In a specific embodiment, for a business object O and its operation item P(O), if the operation scope of P(O) can be set, that is, P(O) belongs to categories (1) and (2) of the permission control classification in the operation items, and if the data scopes C1(P(O)), C2(P(O)),..., Cn(P(O)) are respectively configured in the permission groups G1, G2,..., Gn where the personnel are located, then the finally merged data scope C(P(O)) is C1(P(O)) ∪ C2(P(O)) ∪... ∪ Cn(P(O)). Thus, the user's final permission set is obtained as: {C(P j (O i ))}, where O i can be expanded into the set of business objects to which the user has permissions, and P j (O i ) can be expanded into the operation set of the business object O i . If the operation scope of P(O) cannot be set, that is, P(O) belongs to category (3) of the permission control classification in the operation items, as long as there is one permission group among the user's permission groups G1, G2,..., Gn that has the operation permission of P(O), the user has the operation permission of P(O).
[0063] S140. In response to the user's request, determine the specific personnel, roles, and organizations to which the user belongs, and the user's permission set, obtain the query conditions in the user's request, and search for the permissions that meet the query conditions in the permission set and return them to the user.
[0064] The method provided in this embodiment configures permissions by creating multiple permission groups, assigns specific personnel, roles, and organizations to each permission group, and distributes functional permissions and data permissions in the form of specific personnel, roles, and organizations for unified management. According to the specific personnel, roles, and organizations of each permission group, the permissions for business objects, operation items, and the data scope of operation items of the permission group are configured, and the permissions are distributed to the permission group in a configured form to achieve the construction of a code-free platform, avoiding the complex process of coding permission configuration for each user. According to the specific personnel, roles, and organizations to which the user belongs, with business objects and operation items as the grouping dimensions, the data scopes of different permission groups are merged to obtain the user's permission set for business objects and operation items. The user permissions are merged to obtain the permission set, which can achieve fine-grained control of permission management, improve the flexibility and efficiency of operations while ensuring data security, respond to the user's request, determine the specific personnel, roles, and organizations to which the user belongs, as well as the user's permission set, obtain the query conditions in the user request, and find the permissions that meet the query conditions in the permission set and return them to the user. By determining the permission group to which the user belongs through the user's role and organization, and configuring different operation data scopes for different operations on business objects within the permission group, fine-grained permission management is achieved. This refined control can better meet complex and changing business requirements while reducing the risk of data leakage.
[0065] In one embodiment, according to the specific personnel, roles, and organizations to which the user belongs, with business objects and operation items as the grouping dimensions, merging the data scopes of different permission groups to obtain the user's permission set for business objects and operation items includes the following steps:
[0066] Find the corresponding permission groups according to the specific personnel, roles, and organizations to which the user belongs.
[0067] Obtain the data scopes of the respective permission groups.
[0068] Merge the data scopes of the respective permission groups with business objects and operation items as the grouping dimensions.
[0069] Use the merged data scope as the user's permission set for business objects and operation items.
[0070] Among them, merging the data scopes of the respective permission groups specifically includes merging the data scopes of the respective permission groups by taking the intersection of the data scopes of the respective permission groups, taking the union of the data scopes of the respective permission groups, and taking the data scopes of the respective permission groups according to the preset permission group priorities.
[0071] Specifically, when the user belongs to multiple permission groups, a conflict resolution policy library is set, including three modes:
[0072] Strict mode: Take the intersection of the data ranges of each permission group;
[0073] Lenient mode: Take the union of the data ranges of each permission group;
[0074] Priority mode: Override according to the preset priority of permission groups.
[0075] The method provided in this embodiment gradually determines the user's role and organization through the access request initiated by the user, obtains the data range corresponding to the user's operation, and performs fine-grained management of permissions to improve data security.
[0076] In one embodiment, when a user accesses the system, the user's permissions are gradually released by determining the permission group and operation content to which the user's role or organization belongs, responding to the user's request, determining the specific personnel, role, and organization to which the user belongs, and the user's permission set, obtaining the query conditions in the user request, and searching for the permissions that meet the query conditions in the permission set and returning them to the user. The method further includes the following steps:
[0077] Respond to the user's operation request for the target service, determine the user's permission set, and obtain the data range of the operation item corresponding to the operation request.
[0078] Calculate the intersection of the data range in the user's operation request for the target service and the data range of the corresponding operation item, and return it to the user as the data range of the user's operation request for the target service.
[0079] In one embodiment, the user can also access the target service object by operating on the target service data, and determine the user's access permission by judging the query conditions in the access request. Specifically, the method further includes the following steps:
[0080] Respond to the user's operation request for the target service data, determine the user's permission set, and obtain each operation item permission of the user and the corresponding data range.
[0081] Obtain the overlapping data range between the data range in the user's operation request for the target service and the data range of the corresponding operation item, and return it to the user as the data range of the user's operation request for the target service.
[0082] Respond to the user's operation on the returned operation item, match the data of the operation item with the returned data range, return the matched data range to the user, and display the operation items and ranges that can be executed to the user. Specifically, obtain the user's permission set {C(P j (O i ))}, and obtain its operation item set and the data range set on the operation items {C(P1(O)), C(P2(O))...C(P n(O))}, and then match the data with each data range condition to determine which operation item's data range condition the data falls on, and then return these operations to the client. The client shows the executable operations to the user according to the operation list returned by the server.
[0083] The method provided in this embodiment determines the user's operation item permissions and the data range of the operation items by judging the query conditions for the business object, and returns the operation items and data range that meet the user's permissions to the user for the user to perform operations within the data range.
[0084] In one embodiment, the following steps are further included:
[0085] In response to the user's operation request for the target business data, determine the user's permission set, and obtain each operation item permission and the corresponding data range of the user.
[0086] Merge the data ranges corresponding to each operation item permission as the operation data range for the user's operation request for the target business data.
[0087] The method provided in this embodiment obtains the user's data range permission by judging the intersection of the data range in the user's operation request and the data range of the operation items in the user's permission set, merging the data range of the intersection and returning it to the user, which can flexibly and finely manage the operation items and data range, and enhance the flexibility and convenience of the user's operation.
[0088] System embodiment
[0089] According to an embodiment of the present invention, an integrated permission management system for a no-code platform is provided, as Figure 2 shown, which is the structural diagram of the integrated permission management system for the no-code platform provided in this embodiment. The integrated permission management system for the no-code platform according to the embodiment of the present invention includes:
[0090] A permission group module 210 for creating multiple permission groups, and each permission group is assigned specific personnel, roles, and organizations.
[0091] A permission configuration module 220 for configuring the business objects of each permission group and the permissions of the operation items under the business objects. Among them, the permissions of the operation items under the business objects include: the permission to query a data set that meets the conditions from the database according to specific conditions, the permission to operate on known data, and the permission to operate on business objects.
[0092] A permission merging module 230 for merging the data ranges of different permission groups with the business object and operation item as the grouping dimensions to obtain the user's permission set for the business object and operation item.
[0093] The user access module 240 is used to respond to a user's request, determine the specific personnel, roles, and organizations to which the user belongs, as well as the set of permissions of the user, obtain the query conditions in the user request, and find the permissions that meet the query conditions in the set of permissions and return them to the user.
[0094] In the system provided in this embodiment, the permission group module 210 configures permissions by creating multiple permission groups, assigns specific personnel, roles, and organizations to each permission group, and distributes functional permissions and data permissions in the form of specific personnel, roles, and organizations for unified management. The permission configuration module 220 configures the permissions of the business objects, operation items, and data ranges of the operation items of the permission group according to the specific personnel, roles, and organizations of each permission group, and distributes the permissions to the permission group in a configured form, realizing the construction of a code-free platform and avoiding the complex process of coding permission configuration for each user. The permission merging module 230 merges the data ranges of different permission groups according to the specific personnel, roles, and organizations to which the user belongs, with business objects and operation items as the grouping dimensions, to obtain the set of permissions of the user for business objects and operation items, and merges the user permissions to obtain the set of permissions, which can achieve fine-grained control of permission management, ensure data security, and improve the flexibility and efficiency of operations.
[0095] In one embodiment, the permission merging module 230 is further configured to find the corresponding respective permission groups according to the specific personnel, roles, and organizations to which the user belongs, obtain the data ranges of the respective permission groups, merge the data ranges of the respective permission groups with business objects and operation items as the grouping dimensions, and use the merged data range as the set of permissions of the user for business objects and operation items.
[0096] The system provided in this embodiment gradually determines the role and organization of the user through the access request initiated by the user, obtains the data range corresponding to the user's operation, and performs fine-grained management of permissions to improve data security.
[0097] In one embodiment, the user access module 240 is further used to respond to a user's operation request for a target business, determine the set of permissions of the user, and obtain the data range of the operation item corresponding to the operation request.
[0098] Obtain the overlapping data range between the data range in the user's operation request for the target business and the data range of the corresponding operation item, and return it to the user as the data range of the user's operation request for the target business.
[0099] The system provided in this embodiment determines the operation item permissions and the data range of the operation item of the user by judging the query conditions for the business object, and returns the operation items and data ranges that meet the user's permissions to the user for the user to perform operations within the data range.
[0100] In one embodiment, the user access module 240 is further configured to respond to an operation request of a user for target service data, determine a set of permissions of the user, and obtain each operation item permission of the user and the corresponding data range.
[0101] Merge the data ranges corresponding to each operation item permission as the operation data range of the operation request of the user for the target service data.
[0102] The system provided in this embodiment determines the intersection of the data range in the operation request of the user and the data range of the operation item in the user permission set, merges the data range of the intersection and returns it to the user to obtain the data range permission of the user, and can flexibly and finely manage the operation item and the data range, enhancing the flexibility and convenience of user operations.
[0103] The embodiment of the present invention is a system embodiment corresponding to the above method embodiment. The specific operations of each module processing step can be understood with reference to the description of the method embodiment and will not be elaborated here.
[0104] As Figure 3 shown, the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the integrated permission management method of a no-code platform in the above embodiment, or when the computer program is executed by a processor, it implements the integrated permission management method of a no-code platform in the above embodiment.
[0105] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0106] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description of the method embodiments. The device and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present invention, and the content not described in detail in the specification of the present invention belongs to the well-known technology of those skilled in the art.
Claims
1. An integrated rights management method for a codeless platform, characterized in that: The following steps are involved: Create multiple permission groups, assign specific people, roles, and organizations to each permission group; Configure the business objects and operation items of each permission group; Taking business objects and operation items as grouping dimensions, merge the data ranges of different permission groups to obtain the user's permission set for business objects and operation items; In response to the user's request, determine the specific person, role and organization to which the user belongs and the user's permission set, obtain the query conditions in the user's request, search the permission set for the permissions that meet the query conditions and return them to the user.
2. The integrated rights management method for a codeless platform as claimed in claim 1, characterized in that: The method of taking business objects and operation items as grouping dimensions and merging data ranges of different permission groups to obtain a user's permission set for business objects and operation items includes the following steps: Find the corresponding permission groups based on the specific person, role, and organization to which the user belongs; Obtaining the data range of each permission group; Merge the data scope of each permission group based on business object and operation item as grouping dimensions; The merged data range is used as the user's permission set for business objects and operation items.
3. The integrated rights management method for a codeless platform as claimed in claim 2, characterized in that: The merging of the data ranges of the respective permission groups specifically includes merging the data ranges of the respective permission groups by taking the intersection of the data ranges of the respective permission groups, taking the union of the data ranges of the respective permission groups, or taking the data ranges of the respective permission groups according to a preset permission group priority.
4. The integrated rights management method for a codeless platform as claimed in claim 1, characterized in that: The permissions for the operation items under the business object include: The authority to query the qualified data set from the database according to specific conditions; The authority to operate on known data; The authority to operate on business objects.
5. The integrated rights management method for a codeless platform as claimed in claim 1, characterized in that: The responding to the user's request, determining the specific person, role and organization to which the user belongs, and the user's permission set, obtaining the query condition in the user's request, searching the permission set for the permission that meets the query condition and returning it to the user, further includes the following steps: Respond to the user's operation request for the target business, determine the user's permission set, and obtain the data range of the operation item corresponding to the operation request; A data range in which the data range in the user's operation request for the target service overlaps with the data range of the corresponding operation item is obtained, and the data range is returned to the user as the data range in the user's operation request for the target service.
6. The integrated rights management method for a codeless platform as claimed in claim 1, characterized in that: The following steps are also included: Respond to user operation requests for target business data, determine the user's permission set, and obtain the user's various operation item permissions and corresponding data ranges; The data ranges corresponding to the respective operation item permissions are merged to serve as the operation data range of the user's operation request on the target business data.
7. An integrated rights management system for a codeless platform, characterized in that: Including permission group module, permission configuration module, permission merging module and user access module; The permission group module is used to create multiple permission groups, each of which is assigned specific people, roles, and organizations; The permission configuration module is used to configure the permissions of the business objects and operation items under each permission group; The permission merging module is used to merge the data ranges of different permission groups based on business objects and operation items as grouping dimensions to obtain the user's permission set for business objects and operation items; The user access module is used to respond to the user's request, determine the specific person, role and organization to which the user belongs and the user's permission set, obtain the query conditions in the user's request, search the permission set for the permission that meets the query conditions and return it to the user.
8. The integrated rights management system for a codeless platform as claimed in claim 7, characterized in that: The permission merging module also searches for corresponding permission groups according to the specific person, role and organization to which the user belongs; Obtaining the data range of each permission group; Merge the data scope of each permission group based on business object and operation item as grouping dimensions; The merged data range is used as the user's permission set for business objects and operation items.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the integrated permission management method of a codeless platform as described in any one of claims 1 to 6 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of an integrated rights management method for a codeless platform as described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method and device for inquiring authority
CN101916339A
Business system data authority management method, device and equipment for multi-level enterprises
CN116702213A
User dynamic data authority control method and system
CN117332430A
Data authority control method, computer equipment and computer storage medium
CN118228223A
Full-text search system data access authority control method and system and medium
CN118862042A