Method and system for supporting single execution of auditing
By introducing a method that supports single execution review in the enterprise information system, the approval process is generated and connected with the enterprise communication tool platform, and the approval status is synchronized in real time, the cumbersome and opaque problems of user task execution application in read-only roles are solved, and the security and efficiency of permission management are improved.
Patent Information
- Application Number
- CN202510306618.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, the application approval process for task execution of read-only role users in the enterprise information system is cumbersome, the status is opaque, the authority management is inconvenient, and the integration of the approval process with the enterprise communication tools is low, resulting in inefficiency and increased security risks.
A method that supports single execution review is introduced, an approval process is generated and connected with the enterprise communication tool platform, and the approval status is synchronized in real time. User permissions are dynamically controlled based on the approval status, and approval is carried out through the enterprise communication tool platform, and permissions are automatically revoked after the task is completed.
It improves the efficiency and transparency of the approval process, ensures the security and accuracy of permission management, reduces manual intervention, and improves the efficiency and security of system management.
Smart Images

Figure CN120258709A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular, to a method and system for supporting single - execution auditing. Background Art
[0002] In modern enterprise information systems, user privilege management is an important link to ensure data security and operation compliance. Generally, enterprises assign different role permissions to different users. For example, read - only role users only have the permission to view data and cannot perform modification or operation tasks. However, in actual business scenarios, read - only role users may need to temporarily perform certain specific tasks, which requires a complex approval process to ensure the legality and security of the operation.
[0003] The existing approval processes usually rely on manual initiation and processing, which have problems such as low efficiency, opaque approval status, and unclear process nodes. In addition, the integration degree of the approval process with enterprise internal communication tools is low, resulting in untimely information transmission and further affecting the approval efficiency. At the same time, privilege management lacks a dynamic control mechanism and cannot flexibly adjust user privileges according to the real - time approval status, increasing system security risks and management complexity.
[0004] For the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method and system for supporting single - execution auditing to at least solve the technical problems of cumbersome approval processes for read - only user task execution applications, opaque status, and inconvenient privilege management.
[0006] According to one aspect of the embodiments of the present invention, a method for supporting single - execution auditing is provided, including: generating an approval process and initializing an approval status in response to a task execution application initiated by a read - only role user; docking the approval process with an enterprise communication tool platform, performing approval according to preset nodes through the enterprise communication tool platform, and synchronizing the approval status in real time; determining whether to open single - task execution privileges to the user based on the approval status.
[0007] According to another aspect of the embodiments of the present invention, a system for supporting single - execution auditing is further provided, including: a generation module configured to generate an approval process and initialize an approval status in response to a task execution application initiated by a read - only role user; an approval module configured to dock the approval process with an enterprise communication tool platform, perform approval according to preset nodes through the enterprise communication tool platform, and synchronize the approval status in real time; a determination module configured to determine whether to open single - task execution privileges to the user based on the approval status.
[0008] In the embodiments of the present invention, a method for supporting single - execution review is adopted. By responding to a task execution application initiated by a read - only role user, an approval process is generated and the approval status is initialized; the approval process is docked with the enterprise communication tool platform, and the enterprise communication tool platform conducts approvals according to preset nodes and synchronizes the approval status in real - time; based on the approval status, it is determined whether to open the single - task execution permission to the user. Through the above - mentioned solution, the technical problems of cumbersome approval processes, opaque status, and inconvenient permission management for read - only user task execution applications are solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0010] Figure 1 is a step diagram of a method for supporting single - execution review according to an embodiment of the present invention;
[0011] Figure 2 is a task management interface diagram of a user corresponding to a read - only role according to the prior art;
[0012] Figure 3 is a flowchart of a method for supporting single - execution review by xxl - job according to an embodiment of the present invention;
[0013] Figure 4 is a schematic diagram of an application approval process record according to an embodiment of the present invention;
[0014] Figure 5 is a working flowchart of a system for supporting single - execution review according to an embodiment of the present invention;
[0015] Figure 6 is an architecture diagram of a system for supporting single - execution review according to an embodiment of the present invention;
[0016] Figure 7 shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0018] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0019] According to an embodiment of the present invention, a method embodiment for supporting a single execution audit method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0020] Figure 1 is a flowchart of a method for supporting single execution audit according to an embodiment of the present invention, as Figure 1 shown, the method includes the following steps:
[0021] Step S102, in response to a task execution application initiated by a read-only role user, generate an approval process and initialize the approval status;
[0022] In response to a task execution application initiated by a read-only role user, generate an approval process and an approval process record corresponding to the approval process, wherein the approval process record includes at least one of the following: applicant identification, application time, identification information of the applied task, application reason, the approval status, and the execution status, wherein the approval status is initialized to being under approval.
[0023] Step S104, dock the approval process with the enterprise communication tool platform, perform approval according to preset nodes through the enterprise communication tool platform, and synchronize the approval status in real time;
[0024] Perform approval according to preset nodes through the enterprise communication tool platform to generate an approval result; in response to the approval result, update the approval status in the approval process record. If the approval result is passed, further update the execution status in the approval process record to be pending execution.
[0025] Step S106, based on the approval status, determine whether to open the single task execution permission to the user.
[0026] If the approval status is "passed", the single - task execution permission is granted to the user and automatically revoked after the task is completed; wherein, the single - task execution permission only allows the execution of the applied task once, and a new approval process needs to be initiated after execution; if the approval status is "not passed", the single - task execution permission is not granted to the user.
[0027] When the execution status recorded in the approval process is "pending execution", receive the task execution instruction of the read - only role user and trigger the execution of the corresponding task based on the task execution instruction; after the execution of the corresponding task is completed, update the execution status in the approval process record to "completed".
[0028] After triggering the execution of the corresponding task based on the task execution instruction, if the corresponding task is not completed within the preset time limit, automatically trigger a revocation instruction to revoke the execution of the corresponding task and update the execution status to "execution failed".
[0029] In summary, in the embodiments of the present invention, by automatically generating the approval process and initializing the approval status, and at the same time creating an approval record containing detailed information, the approval efficiency, transparency and traceability are improved, laying a foundation for subsequent process management; by docking the approval process with the enterprise communication tool, automated approval and real - time status synchronization are achieved, improving the approval efficiency and transparency, and automatically updating the approval record to ensure data consistency and task execution accuracy; by dynamically controlling the single - task execution permission, ensuring the accuracy and security of the permission, automatically updating the execution status and supporting timeout revocation, the system management efficiency and security are improved.
[0030] When applying a task scheduling platform such as XXL - JOB, after secondary development of XXL - JOB, a read - only role is added. The users corresponding to the read - only role can only view the authorized task information and call logs, but cannot execute tasks. Although the read - only role enhances the security of the system, it also brings new problems. In the test environment, testers need to execute specific tasks to verify requirements, but the read - only role lacks the execution permission. If the execution permission is granted to the read - only role, it violates the original design intention of the read - only role and may cause security risks. XXL - JOB is a lightweight, efficient and easy - to - use distributed task scheduling platform designed to solve the problem of executing timed tasks in a distributed environment.
[0031] In the distributed task scheduling platform XXL - JOB, users with read - only roles usually can only view task information and call logs, but cannot execute tasks, as Figure 2 shown. However, in the test environment, testers sometimes need to execute specific tasks to verify requirements.
[0032] To solve this problem, the embodiments of the present application propose a method for supporting single - execution review. By introducing an approval mechanism, it allows read - only role users to execute tasks under specific circumstances while ensuring the security of the system. When a user corresponding to the read - only role needs to execute a task, they can click the [Apply for One - Time Execution] button to initiate an approval process, which will be docked with an enterprise communication tool platform such as DingTalk approval flow. Specifically, the present application solves the problem in the prior art that in a test environment, testers need to execute specific tasks to verify requirements, but read - only roles lack the execution permission. In the embodiments of the present application, when a user corresponding to the read - only role needs to execute a task, they can click the [Apply for One - Time Execution] button to initiate an approval process, which will be docked with the DingTalk approval flow. The DingTalk approval process first creates an approval process and approves it according to preset nodes, and the current status can be viewed in the approval record; after the approval is passed, the user will be notified in DingTalk, and at the same time, xxl - job will be called back to update the approval status to "passed" and the execution status to "pending execution". At this time, the user can click the execute - once button, and the execution status will be updated to completed. In addition, for each successful application, the applicant of the corresponding task can execute it once, and only one task execution can be applied for each time; when there is an application from the current submitter under approval within 3 days, no new application can be initiated, and a new application can only be made after the previous application is completed and executed; only the initiator and the administrator can manually terminate it. After manual termination, the approval in DingTalk will also be revoked synchronously; the approver can view the task details through the application content and view the corresponding task through the link. Through the above - mentioned solution, the flexibility of the test environment is improved, allowing read - only role users to execute tasks under specific circumstances. The security of the system is enhanced by controlling task execution permissions through the approval mechanism, avoiding the abuse of permissions. The automation level of the approval process is improved, reducing manual intervention and improving efficiency.
[0033] Specifically, as Figure 3 shown, the method for xxl - job to support single - execution review includes the following steps:
[0034] Step S300, role creation and permission configuration.
[0035] The system administrator completes the following operations in the background management interface: add a "read - only role" type, define the role identifier and permission scope; authorize the list of executors that this role can access, restricting its visibility to unauthorized executors; set the permission policy to clearly prohibit this role from directly triggering task execution operations (such as disabling the [Execute Immediately] button); write the role configuration information to the database and synchronously update the RBAC (Role - Based Access Control) policy cache.
[0036] Step S302, user initiates a single - execution application.
[0037] Users with read-only permissions perform operations in the task management interface: click the [Apply to Execute Once] button corresponding to the target task to trigger the front-end interaction logic; the system calls the permission verification interface / auth / check to verify whether the user role has the application qualification; load the preset approver list (synchronized from LDAP / DingTalk organizational structure), the user selects a specified approver and fills in the application remarks; the front-end submits the application data in JSON format to the back-end API / apply / create, including fields: taskId (task ID), approver (approver), remark (remark).
[0038] Insert a new record into the task_apply table in the MySQL database, and mark the initial status as under approval; generate a unique application number applyNo (rule: year-month-day + 6-digit serial number); call the message queue (such as RocketMQ) to send the event ApplyCreatedEvent to trigger the subsequent approval process integration.
[0039] Step S304, conduct the approval.
[0040] The system is deeply integrated with the DingTalk approval system, creates an approval instance through the DingTalk open platform; dynamically constructs the approval form data, including the basic task information, the reason for application, and the H5 link to jump to the task details; configures the callback URL in the DingTalk approval template to receive the approval result; binds the processInstanceId returned by DingTalk to the local applyNo and writes it into the association table dingtalk_apply_mapping.
[0041] Step S306, handle the callback of the approval result.
[0042] The system receives the DingTalk approval result and updates the status. DingTalk pushes the approval result to the callback URL through an HTTP POST request, and the data includes result (approved / rejected), processInstanceId; query the associated local application record applyNo according to the processInstanceId; if the approval is passed: update the status of the task_apply table to passed; write the temporary execution permission key-value (Key: perm:execute_once:{applyNo}, TTL: 24h) into Redis; if the approval is not passed, mark the status as not passed and record the reason for rejection in the reject_reason field; send an in-site message to notify the applicant.
[0043] The system executes the risk control logic when the user initiates an application. Query the task_apply table to check if there are any records with a status of "under approval" or "approved but not executed" for the same user in the past 72 hours; if there is a conflicting application, a Toast prompt "You have an unfinished application. Please wait until the approval is completed before submitting again" will pop up on the front end; the back end returns the HTTP 403 error code and the error message CONCURRENT_APPLY_LIMIT; after passing the verification, the system is allowed to enter step S308.
[0044] Step S308, single-task execution permission verification.
[0045] The back-end verification logic when the user clicks the [Execute Once] button. Check if there is a corresponding temporary permission key perm:execute_once:{applyNo} in Redis; verify that the status of the application record is "approved" and the executed field is false; call the distributed lock service (such as Redisson) to lock the taskId to prevent concurrent execution; if the verification passes: trigger the run method of the task executor (Executor), passing in the task parameters; update the executed flag to true and record the execution timestamp; delete the temporary permission key in Redis to ensure that the permission takes effect once.
[0046] Step S310, status update.
[0047] After the task is executed, the system performs closed-loop processing. The executor calls the Admin service interface / callback / job_finish to report the execution result (success / failure); update the executed_status field of the task_apply table and write it to the task execution log table task_execute_log; if the execution fails, trigger the alarm rule and push a failure notice to the applicant and the administrator through the DingTalk robot; the applicant can re-trigger the execution within 24 hours (permission needs to be re-verified); generate an audit log to record the operator's IP, device fingerprint, and key operation time nodes for the security team to trace. The interface after the status update is as Figure 4 shown.
[0048] Step S312, query the application record.
[0049] Users can view the application history through the personal center. Call the API / apply / list to query all application records of the current user; when rendering the list on the front end, different labels are displayed according to the status value: In approval: orange status icon + countdown progress bar (calculate the remaining approval duration based on the creation time); Approved: green icon + [Execute once] operation button; Rejected: red icon + display the rejection reason; Click on a single record to view the details, including the approver's opinion, task snapshot information, and execution log.
[0050] In other embodiments, other enterprise communication tools (such as WeCom, Slack, etc.) can also be considered to replace DingTalk to achieve the docking of the approval process. For the approval process, different approval nodes and conditions can be designed to adapt to different business scenarios. In terms of data synchronization, an automated data synchronization solution can be explored to reduce manual operations and improve the accuracy and real-time performance of data synchronization.
[0051] The embodiment of the present application also provides a system for implementing single execution permission approval in the XXL-JOB task scheduling platform. This system is mainly applicable to read-only role users. Under the premise of ensuring system security, it allows them to apply to execute a task once under specific conditions, so as to meet the requirements of the test environment for flexible task execution.
[0052] This system mainly includes the following core modules: The task management module is used to define and store various tasks in the XXL-JOB platform, including task ID, execution strategy, task status, etc.; The user permission management module is responsible for user role management. Among them, read-only role users only have the permission to view tasks and cannot directly execute tasks; The approval management module is used to receive, process, and review single execution applications, including approval process configuration, approval record storage, etc.; The task execution module allows users to trigger task execution after approval and records the task execution status at the same time; The notification management module is integrated with an external enterprise communication tool (such as DingTalk) to achieve real-time notification of the approval progress and execution status.
[0053] Next, the working process of the system for implementing single execution permission approval in the XXL-JOB task scheduling platform will be described in detail, as Figure 5 described, this process includes:
[0054] Step S502, in response to a task execution application initiated by a read-only role user, generate an approval process and initialize the approval status.
[0055] The system first responds to the task execution application of read-only role users, generates an approval process and initializes the approval status. The approval process record includes the applicant identification, application time, identification information of the applied task, application reason, approval status, and execution status. The initial value of the approval status is set to "under approval". After the approval process is generated, the system interfaces it with the enterprise communication tool platform (such as DingTalk or WeCom), conducts approval according to the preset approval process through the enterprise communication tool, and synchronizes the approval status in real time. The node configuration of the approval process can be set by the administrator to adapt to different business requirements.
[0056] Step S504: Interface the approval process with the enterprise communication tool platform and synchronize the approval status in real time.
[0057] During the approval process, the enterprise communication tool distributes the approval request to the designated approver according to the preset approval rules and generates an approval record. The approver can directly view the application details in the enterprise communication tool platform and make a decision to approve or reject. The approval decision is transmitted back to the approval management system in real time through the enterprise communication tool, and the approval status is updated accordingly. If the approval result is passed, the approval status is updated to "approved", and at the same time, the execution status is updated to "pending execution". If the approval is rejected, the approval status is updated to "not approved", and the execution status remains "not executable".
[0058] Step S506: Determine whether to grant the user the single-task execution permission based on the approval status.
[0059] After the approval status changes to "approved", the system will determine whether to grant the user the single-task execution permission. If the approval has passed, the user will obtain the single-task execution permission and be allowed to execute the applied task once. This permission is limited to the task involved in the current approval process, and after the task is completed, the permission will automatically expire, and the user needs to submit a new approval process to execute the task again. Through this mechanism, the system can provide flexibility for the test environment while ensuring security, meeting the task execution requirements in specific scenarios.
[0060] Step S508: Trigger task execution.
[0061] During the task execution phase, the system receives the user's task execution instruction and triggers the task execution. The task execution process is strictly controlled. The system records the execution log and synchronizes the task execution status for subsequent auditing and traceability. After the task execution is completed, the system automatically updates the execution status to "completed". If the task execution fails, the system updates the execution status to "execution failed" and allows the user to reapply for task execution permission later. In addition, to avoid wasting system resources due to long-unexecuted tasks, the system introduces a timeout revocation mechanism. When the task is not completed within the preset execution time limit, the system will automatically trigger a revocation instruction, revoke the task execution permission, update the execution status to "execution failed", and record the revocation reason to ensure the effectiveness and security of task management.
[0062] The difference between the embodiments of the present application and the above embodiments lies in that, aiming at the deficiencies of the timeout revocation mechanism in the prior art, an intelligent solution integrating machine learning and dynamic resource scheduling is provided. The core lies in constructing a dynamic risk assessment model and an adaptive execution window control technology, and realizing the intelligent management and security audit of the entire task execution cycle by quantifying the task execution risk and real-time perceiving the system load status.
[0063] 1) Dynamic risk assessment engine.
[0064] This system uses the XGBoost algorithm to train a multi-dimensional risk assessment model and analyzes the task execution characteristics in real time. The model inputs include dynamic parameters such as historical execution data (success rate, failure rate, time-consuming distribution), current system resource load (CPU utilization rate, memory occupancy rate, queue depth), task attributes (sensitive level of involved data tables, complexity of interface calls), and user behavior portraits (application frequency, approval passing rate), and outputs a risk coefficient in the range of 0-1. This coefficient is combined with the preset business period characteristics (such as peak / low period) to dynamically divide the risk levels into low, medium, and high levels, providing a quantitative basis for subsequent decision-making.
[0065] 2) Adaptive execution window control.
[0066] This application uses a three-dimensional execution window matrix model for adaptive execution window control. Time dimension: Dynamically calculate the timeout threshold based on the formula T = T_base × (1 + α × R_risk) × (1 - β × R_load), where T_base is the preset reference value, R_risk is the risk coefficient, R_load is the real-time system load rate, and α, β are adjustable weight parameters. Resource dimension: Dynamically allocate resource quotas such as the number of CPU cores and memory upper limits according to the risk level, and high-risk tasks limit the resource occupancy ratio. Priority dimension: Adopt a dynamic priority queue, and the initial priority is determined by the inverse relationship between the task urgency and the risk coefficient, and is adjusted in real time according to the waiting time and the remaining window ratio.
[0067] 3) Intelligent scheduling.
[0068] To achieve efficient resource utilization, save the task context. When a high-priority task arrives, the system automatically performs a lightweight snapshot save (in-memory incremental storage + disk cold backup) on the low-priority task, releasing the occupied resources. The distributed lock mechanism is adopted to ensure data consistency when the task is interrupted. After the resources are released, seamless resume execution is achieved through context recovery. At the same time, the digital twin technology is introduced to build a virtual execution environment to pre-act the task recovery process, reducing the abnormal risk in the actual recovery process.
[0069] 4) Conduct tracking.
[0070] Build a private chain network to store key operation records, realizing non-tamperable audit tracking: Each block records the approval decision (approver's digital signature, timestamp), the task execution trajectory (resource consumption, intermediate state hash value), and the details of timeout events (model input parameters, decision logic chain). The intelligent contract automatically verifies the compliance of operations, such as checking the integrity of the approval process and the compliance of the execution window. The zero-knowledge proof technology is adopted to achieve the privacy protection of sensitive data, avoiding the leakage of business data while ensuring traceability.
[0071] This solution converts manual experience into dynamic quantitative indicators through a machine learning model, enabling the timeout threshold to be adaptively adjusted according to the system state: In addition, the three-dimensional execution window model combined with preemptive scheduling improves the utilization rate of cluster resources.
[0072] Compared with the prior art, this embodiment has the following improvements: First, in the task scheduling system of the prior art, the user permissions are usually fixed and cannot be temporarily granted execution permissions for specific tasks, resulting in read-only role users being unable to complete necessary operations in the test environment. This method enables read-only role users to temporarily obtain task execution permissions under specific conditions without affecting the overall security of the system by introducing a dynamic approval mechanism. Second, the approval process of the traditional task scheduling system is usually separated from the system itself, and the approval results cannot be synchronized in real time, resulting in low approval efficiency and prone to problems of unauthorized use of permissions. This method realizes the automation of the approval process and ensures the real-time synchronization of the approval status by deeply integrating with enterprise communication tools, effectively improving the approval efficiency and avoiding data inconsistency problems that may be caused by manually synchronizing the approval status.
[0073] In addition, in terms of task execution permission management, this method ensures that a user can only execute a task once by setting single-execution permissions. After the execution is completed, the permissions are automatically revoked, avoiding potential security risks caused by improper permission allocation in traditional systems. At the same time, this method incorporates a timeout revocation mechanism to ensure that tasks are executed within a reasonable time frame. If the execution times out, the system automatically revokes the task execution permission, thereby improving the utilization efficiency of system resources and reducing the need for manual intervention.
[0074] In practical applications, this method can be applied to various distributed task scheduling systems, especially in scenarios with strict control requirements for task execution permissions, such as test environments, data analysis tasks, and scheduled tasks. By introducing an approval process, the system can ensure the reasonable allocation of task execution permissions and provide clear execution records, enhancing the transparency and traceability of the system. Enterprises can adjust approval rules according to their own needs, such as approval levels, approver settings, and approval timeout times, to further optimize the approval process and improve management efficiency.
[0075] In summary, through the introduction of an approval mechanism and the refined management of task execution permissions, this embodiment realizes the task execution review for read-only role users, ensuring the security, flexibility, and traceability of the system. By combining automated approval, real-time status synchronization, single-execution permission control, and a timeout revocation mechanism, this method effectively solves the permission management problem in traditional task scheduling systems and provides a more secure, controllable, and efficient solution for distributed task scheduling.
[0076] This application also provides another system that supports the single-execution review method, as Figure 6 shown, including: a generation module 12 configured to generate an approval process and initialize an approval status in response to a task execution application initiated by a read-only role user; an approval module 14 configured to dock the approval process with an enterprise communication tool platform, perform approvals according to preset nodes through the enterprise communication tool platform, and synchronize the approval status in real time; and a determination module 16 configured to determine whether to open single-task execution permissions for the user based on the approval status.
[0077] It should be noted that for the system that supports the single-execution review method provided in the above embodiment, only the above division of each functional module is used as an example. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the system that supports the single-execution review method provided in the above embodiment and the method embodiment of the single-execution review method belong to the same concept. For the specific implementation process, please refer to the method embodiment and will not be elaborated here.
[0078] Figure 7 The figure shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. It should be noted that Figure 7 the shown electronic device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0079] As Figure 7 shown, the electronic device includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage section 1008 into the random access memory (RAM) 1003. In the RAM 1003, various programs and data required for system operation are also stored. The CPU 1001, ROM 1002, and RAM 1003 are connected to each other via a bus 1004. The input / output (I / O) interface 1005 is also connected to the bus 1004.
[0080] The following components are connected to the I / O interface 1005: an input section 1006 including a keyboard, a mouse, etc.; an output section 1007 including such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, a modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as required. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as required so that the computer program read from it can be installed into the storage section 1008 as required.
[0081] The above is only the preferred embodiment of the present application. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for supporting single - execution review, characterized in that, including: generating an approval process and initializing an approval status in response to a task execution application initiated by a read-only role user; docking the approval process with an enterprise communication tool platform, performing approval according to preset nodes through the enterprise communication tool platform, and synchronizing the approval status in real time; determining whether to grant the user a single-task execution permission based on the approval status.
2. The method according to claim 1, wherein Determining whether to grant the user a single-task execution permission based on the approval status includes: if the approval status is passed, granting the user a single-task execution permission and automatically revoking the permission after the task execution is completed; wherein, the single-task execution permission only allows the execution of the applied task once, and a new approval process needs to be initiated after execution; if the approval status is not passed, not granting the user a single-task execution permission.
3. The method according to claim 2, wherein After generating the approval process, the method further includes: generating an approval process record corresponding to the approval process, wherein the approval process record includes at least one of the following: applicant identification, application time, identification information of the applied task, application reason, the approval status, and execution status, and the approval status is initialized to being under approval.
4. The method according to claim 3, wherein Performing approval according to preset nodes through the enterprise communication tool platform and synchronizing the approval status in real time includes: performing approval according to preset nodes through the enterprise communication tool platform to generate an approval result; responding to the approval result, updating the approval status in the approval process record, and if the approval result is passed, further updating the execution status in the approval process record to pending execution.
5. The method according to claim 4, wherein After granting the user a single-task execution permission, the method further includes: when the execution status of the approval process record is pending execution, receiving a task execution instruction from the read-only role user and triggering the execution of the corresponding task based on the task execution instruction; after completing the execution of the corresponding task, updating the execution status in the approval process record to completed.
6. The method according to claim 4, characterized in that After granting the user a single-task execution permission, the method further includes: after triggering the execution of the corresponding task based on the task execution instruction, if the corresponding task is not completed within a preset time limit, automatically triggering a revocation instruction to revoke the execution of the corresponding task and updating the execution status to execution failed.
7. A system for supporting a single execution audit method, characterized in that, including: a generation module configured to generate an approval process and initialize an approval status in response to a task execution application initiated by a read-only role user; an approval module configured to dock the approval process with an enterprise communication tool platform, perform approval according to preset nodes through the enterprise communication tool platform, and synchronize the approval status in real time; a determination module configured to determine whether to grant the user a single-task execution permission based on the approval status.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein when the program runs, it controls the device where the computer-readable storage medium is located to execute the method according to any one of claims 1 to 6.
9. A computer device, characterized in that, including: a memory and a processor, the memory stores a computer program; The processor is configured to execute the computer program stored in the memory, and when the computer program runs, the processor is caused to execute the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.