User permission configuration method and device, electronic equipment and storage medium
By creating a custom role and permission tree structure, the problem that the RBAC model cannot dynamically adjust the permission inheritance relationship is solved, flexible permission management and immediate effect are achieved, and maintenance costs and security risks for large organizations are reduced.
Patent Information
- Application Number
- CN202510750396.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
The existing RBAC model cannot dynamically adjust the permission inheritance relationship, and its flexibility is poor, resulting in an exponential increase in the number of roles in large organizations, high permission configuration and maintenance costs, and misconfiguration may lead to sensitive data leakage or functional abuse.
By creating multiple custom roles, determining the permission collection based on the attribute information of the custom role, and building a permission tree structure, dynamic adjustment of permission inheritance relationships is achieved, and batch management and immediate effect are supported.
It realizes dynamic adjustment of the permission inheritance relationship, improves the flexibility and security of permission configuration, reduces maintenance costs, prevents misoperation, and supports immediate effectiveness and audit traceability.
Smart Images

Figure CN120277723A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a user permission configuration method, apparatus, electronic device, and storage medium. Background Art
[0002] Early access control models, such as Access Control Lists (ACLs), require configuring permissions for each user individually. This leads to extremely high maintenance costs when the user scale expands or the organizational structure changes. To solve the above problems, the Role-Based Access Control (RBAC) model emerged. This model manages users' access to system resources by assigning users to specific roles and defining permissions for these roles, reducing the complexity of user permission configuration.
[0003] However, the role hierarchy of the RBAC model is fixed and cannot dynamically adjust the permission inheritance relationship, resulting in poor flexibility. Summary of the Invention
[0004] This application provides a user permission configuration method, apparatus, electronic device, and storage medium to at least solve the problem in related technologies that the permission inheritance relationship cannot be dynamically adjusted and the flexibility is poor.
[0005] This application provides a user permission configuration method, including: Create multiple custom roles; Based on the attribute information of the custom roles, determine the permission set of the custom roles, where the permission set includes multiple permission codes, and each permission corresponds to a permission code; Based on the permission set of the custom roles, determine the permission tree structure of the custom roles, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and based on the hierarchical information represented by the permission code, determine the hierarchical information of the tree node corresponding to the permission code; Add users to the custom roles to determine the custom roles to which the users belong; Based on the permission set of the custom roles to which the users belong, determine the permission information of the users; In response to a shielding operation on the target permission of any custom role, based on the target permission and the target permission tree structure of the custom role, determine the permission code to be shielded, and update the permission set of the custom role and the permission information of the user corresponding to the custom role based on the permission code to be shielded.
[0006] This application also provides a user permission configuration apparatus, including: A creation module, configured to create multiple custom roles; A first determination module, configured to determine a permission set of a custom role based on the attribute information of the custom role, where the permission set includes multiple permission codes, and each permission corresponds to one permission code; A second determination module, configured to determine a permission tree structure of the custom role based on the permission set of the custom role, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and determine the hierarchical information of the tree node corresponding to the permission code based on the hierarchical information represented by the permission code; A third determination module, configured to add a user to the custom role to determine the custom role to which the user belongs; A fourth determination module, configured to determine the permission information of the user based on the permission set of the custom role to which the user belongs; A fifth determination module, configured to, in response to a shielding operation on a target permission of any custom role, determine a permission code to be shielded based on the target permission and the target permission tree structure of the custom role, and update the permission set of the custom role and the permission information of the user corresponding to the custom role based on the permission code to be shielded.
[0007] This application also provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any of the above user permission configuration methods when executing the computer program.
[0008] This application also provides a computer-readable storage medium, where a computer program is stored in the computer-readable storage medium, and the computer program, when executed by a processor, implements the steps of any of the above user permission configuration methods.
[0009] This application also provides a computer program product, including a computer program, and the computer program, when executed by a processor, implements the steps of any of the above user permission configuration methods.
[0010] Through this application, since multiple custom roles are created; based on the attribute information of the custom roles, a permission set of the custom roles is determined, where the permission set includes multiple permission codes, and each permission corresponds to one permission code; based on the permission set of the custom roles, a permission tree structure of the custom roles is determined, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and the hierarchical information of the tree node corresponding to the permission code is determined based on the hierarchical information represented by the permission code; a user is added to the custom role to determine the custom role to which the user belongs; based on the permission set of the custom role to which the user belongs, the permission information of the user is determined; in response to a shielding operation on a target permission of any custom role, based on the target permission and the target permission tree structure of the custom role, a permission code to be shielded is determined, and the permission set of the custom role and the permission information of the user corresponding to the custom role are updated based on the permission code to be shielded. Through the permission tree structure, the dynamic adjustment of the permission inheritance relationship is realized. Therefore, the technical problem that the related technology cannot dynamically adjust the permission inheritance relationship and has poor flexibility can be solved, and the technical effect of dynamically adjusting the permission inheritance relationship and improving flexibility is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] To more clearly illustrate the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0012] Figure 1 FIG. is a schematic structural diagram of a user permission configuration system provided by an embodiment of the present application; Figure 2 FIG. is a schematic flowchart of a user permission configuration method provided by an embodiment of the present application; Figure 3 FIG. is a schematic flowchart of another user permission configuration method provided by an embodiment of the present application; Figure 4 FIG. is a schematic flowchart of another user permission configuration method provided by an embodiment of the present application; Figure 5 FIG. is an interaction diagram for performing user permission configuration provided by an embodiment of the present application; Figure 6 FIG. is a schematic structural diagram of a user permission configuration device provided by an embodiment of the present application; Figure 7 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0013] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0014] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variation thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0015] In order to enable those skilled in the art of this technology to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0016] Early access control models such as ACL achieve resource access control by configuring permissions for each user individually. Specifically, permissions are directly bound to users, and the system administrator needs to configure a list of accessible resources (such as pages, operations, data, etc.) for each user individually. This static configuration method results in the need to modify the association relationship between users and permissions one by one when permissions change, thus incurring high maintenance costs. For example, when adding a new user, the permission configuration needs to be repeated, and it is very easy to miss or conflict when adjusting permissions. In addition, early access control models are difficult to adapt to dynamic business requirements. When organizational structure adjustments or user function changes occur in institutions such as schools, the permissions of users need to be adjusted manually frequently, and batch management cannot be achieved through an abstract level. This method of directly configuring permissions for each user easily leads to over-allocation of permissions, violates the principle of least privilege, and is prone to the problem that users obtain sensitive data operation permissions due to incorrect permission configuration, increasing the risk of data leakage. Among them, the principle of least privilege means that each user, process or component in the system should only be granted the minimum level of permissions necessary to complete its tasks and should not have additional permissions for the tasks.
[0017] To solve the above problems, the RBAC model came into being. This model indirectly manages users' access to system resources by assigning users to specific roles and defining permissions for these roles, reducing the complexity of user permission configuration.
[0018] However, the role hierarchy of the RBAC model is fixed, and it is unable to dynamically adjust the permission inheritance relationship, resulting in poor flexibility. Moreover, as the business complexity increases, the number of roles grows exponentially, and the permission configuration and maintenance costs increase significantly. For example, when adjusting the permissions of a role in a large organization, it is necessary to traverse all associated users belonging to that role to complete the adjustment of the role's permissions, which is cumbersome and difficult to ensure consistency. The RBAC model does not support batch permission management and cannot achieve efficient inheritance and coverage through an abstract hierarchy, making it difficult for the system to adapt to dynamic business scenarios.
[0019] Moreover, permission changes rely on manual operations, and misconfigurations may lead to sensitive data leakage or function abuse. For example, accidentally enabling the data deletion permission may cause irreversible data loss, resulting in a high security risk.
[0020] To solve the above problems, the embodiments of the present application provide a user permission configuration method, which includes: creating multiple custom roles; determining a permission set of the custom roles based on the attribute information of the custom roles, where the permission set includes multiple permission codes, and each permission corresponds to a permission code; determining a permission tree structure of the custom roles based on the permission set of the custom roles, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and determining the hierarchical information of the tree node corresponding to the permission code based on the hierarchical information represented by the permission code; adding users to the custom roles to determine the custom roles to which the users belong; determining the permission information of the users based on the permission set of the custom roles to which the users belong; in response to a shielding operation on the target permission of any custom role, determining the permission codes to be shielded based on the target permission and the target permission tree structure of the custom role, and updating the permission set of the custom role and the permission information of the users corresponding to the custom role based on the permission codes to be shielded. The method provided by the above solution can determine the inheritance relationship between the permissions of the custom roles according to the permission tree structure of the custom roles, and then can achieve dynamic adjustment of the permission inheritance relationship through the permission tree structure, achieving the technical effect of dynamically adjusting the permission inheritance relationship and improving the flexibility of permission adjustment.
[0021] Moreover, fine-grained control and batch management of permissions can be achieved through the permission tree structure of the custom roles to adapt to complex business scenarios.
[0022] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the user permission configuration method depends, the specific application environment architecture or specific hardware architecture is described herein.
[0023] The user permission configuration method, device, electronic device, and storage medium provided by the embodiments of the present application are applicable to configuring the permissions of users. As Figure 1As shown in the figure, it is a schematic structural diagram of the user permission configuration system based on the embodiments of the present application, mainly including a client and an Artificial Intelligence (AI) platform. Among them, the AI platform is used to create multiple custom roles; based on the attribute information of the custom roles, determine the permission set of the custom roles, where the permission set includes multiple permission codes, and each permission corresponds to a permission code; based on the permission set of the custom roles, determine the permission tree structure of the custom roles, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and determine the hierarchical information of the tree node corresponding to the permission code based on the hierarchical information represented by the permission code; add users to the custom roles to determine the custom roles to which the users belong; based on the permission set of the custom roles to which the users belong, determine the permission information of the users; in response to the client's shielding operation on the target permission of any custom role, based on the target permission and the target permission tree structure of the custom role, determine the permission codes to be shielded, and update the permission set of the custom role and the permission information of the users corresponding to the custom role based on the permission codes to be shielded.
[0024] An embodiment of the present application provides a user permission configuration method, which is applied to the AI platform. Figure 2 It is a schematic flowchart of the user permission configuration method provided by the embodiments of the present application. As Figure 2 shown, the process includes: Step S201: Create multiple custom roles.
[0025] Among them, multiple basic roles are preset in the AI platform, such as super administrator, system administrator, group administrator, auditor, ordinary user, etc., and each basic role is associated with an initial permission set. The initial permission set of this basic role cannot be changed.
[0026] The AI platform supports the creation of custom roles. The system administrator can define the name, permission description, and permission configuration of the custom roles through a visual interface. The permission configuration by default includes all functional permissions under this role.
[0027] It should be noted that there can be a parent-child relationship between the multiple custom roles created. Among them, the permissions of the sub-roles are default inherited from the parent roles.
[0028] Step S202: Based on the attribute information of the custom roles, determine the permission set of the custom roles, where the permission set includes multiple permission codes, and each permission corresponds to a permission code.
[0029] Among them, the attribute information of the custom role can include super administrator, system administrator, group administrator, auditor, ordinary user, etc. It should be noted that when the attribute information of the custom role is super administrator, the permission set of the custom role is the same as the initial permission set of the super administrator base role; when the attribute information of the custom role is system administrator, the permission set of the custom role is the same as the initial permission set of the system administrator base role; when the attribute information of the custom role is group administrator, the permission set of the custom role is the same as the initial permission set of the group administrator base role; when the attribute information of the custom role is auditor, the permission set of the custom role is the same as the initial permission set of the auditor base role; when the attribute information of the custom role is ordinary user, the permission set of the custom role is the same as the initial permission set of the ordinary user base role. The permission set is the aforementioned permission configuration.
[0030] Furthermore, it should be noted that a certain permission under the custom role can be adjusted by adjusting the permission configuration. The permission can be a menu or a business operation, that is, each menu or business operation corresponds to a permission code. Exemplarily, the permission code can be "User Management: New".
[0031] Step S203: Based on the permission set of the custom role, determine the permission tree structure of the custom role. Among them, each permission code in the permission set corresponds to a tree node in the permission tree structure, and the hierarchical information represented by the permission code is used to determine the hierarchical information of the tree node corresponding to the permission code.
[0032] Among them, each permission code corresponds to a tree node in the permission tree structure, and each tree node corresponds to a unique tree node code. That is to say, each permission code is bound to a unique tree node code, namely tree_id. tree_id can represent the hierarchy and subordinate management of the permission code. The permission tree structure can be used for hierarchical display and hierarchical shielding of the permissions of the custom role. For example, if the second-level menu permission of the user group is shielded, the second-level menu permission of the user group and the labels (tabs) and operation permissions within the second-level menu will also be shielded.
[0033] Step S204: Add a user to the custom role to determine the custom role to which the user belongs.
[0034] It can be understood that if a user is added to a certain custom role, then the user belongs to that custom role.
[0035] There are also pre-added users in multiple base roles. According to the initial permission set of the base role, determine the permission information of the users corresponding to the base role.
[0036] Specifically, member management is performed in the custom role. Adding a member means adding a user to determine the custom role to which the user belongs.
[0037] Step S205: Determine the user's permission information based on the permission set of the custom role to which the user belongs.
[0038] It can be understood that the permissions corresponding to the permission codes included in the permission set of the custom role to which the user belongs are the permissions that the user has. That is to say, the user's permission information is determined according to the permission set of the custom role to which the user belongs.
[0039] Step S206: In response to the shielding operation on the target permission of any custom role, determine the permission codes to be shielded based on the target permission and the target permission tree structure of the custom role, and update the permission set of the custom role and the permission information of the users corresponding to the custom role based on the permission codes to be shielded.
[0040] Through the target permission tree structure, the inheritance relationship between permissions can be determined. When shielding the target permission of any custom role, multiple permissions with an inheritance relationship with the target permission can be determined according to the target permission tree structure of the custom role. The target permission and the multiple permissions with an inheritance relationship with the target permission are used as the permissions to be shielded. The permission codes to be shielded are determined according to the permissions to be shielded, and the permission set of the custom role, the target permission tree structure, and the permission information of the users corresponding to the custom role are updated based on the permission codes to be shielded.
[0041] It can be understood that in the embodiment of the present application, dynamic batch adjustment of user permissions is achieved through the permission tree structure. For example, if it is necessary to modify the user permissions under a certain custom role in the AI platform, directly select the custom role in the role module, and modify the permission configuration of the custom role according to the permission tree structure of the custom role. After the modification is completed, all users belonging to the custom role do not have the user permissions, achieving efficient and fast completion of user permission changes.
[0042] The user privilege configuration method provided by the embodiments of the present application creates multiple custom roles; determines the privilege set of the custom roles based on the attribute information of the custom roles, where the privilege set includes multiple privilege codes, and each privilege corresponds to one privilege code; determines the privilege tree structure of the custom roles based on the privilege set of the custom roles, where each privilege code in the privilege set corresponds to a tree node in the privilege tree structure, and determines the hierarchical information of the tree node corresponding to the privilege code based on the hierarchical information represented by the privilege code; adds a user to the custom role to determine the custom role to which the user belongs; determines the privilege information of the user based on the privilege set of the custom role to which the user belongs; in response to a shielding operation on the target privilege of any custom role, determines the privilege code to be shielded based on the target privilege and the target privilege tree structure of the custom role, and updates the privilege set of the custom role and the privilege information of the user corresponding to the custom role based on the privilege code to be shielded. By implementing the dynamic adjustment of the privilege inheritance relationship through the privilege tree structure, it is possible to solve the technical problem that the related art cannot dynamically adjust the privilege inheritance relationship and has poor flexibility, and achieve the technical effect of dynamically adjusting the privilege inheritance relationship and improving flexibility.
[0043] The embodiments of the present application provide a user privilege configuration method, which is applied to an AI platform. Figure 3 It is a schematic flowchart of the user privilege configuration method provided by the embodiments of the present application. As Figure 3 shown, the process includes: Step S301: Create multiple custom roles. For details, please refer to Figure 2 Step S201 of the embodiment shown, which will not be elaborated here.
[0044] Step S302: Determine the privilege set of the custom role based on the attribute information of the custom role, where the privilege set includes multiple privilege codes, and each privilege corresponds to one privilege code. For details, please refer to Figure 2 Step S202 of the embodiment shown, which will not be elaborated here.
[0045] Step S303: Determine the privilege tree structure of the custom role based on the privilege set of the custom role, where each privilege code in the privilege set corresponds to a tree node in the privilege tree structure, and determine the hierarchical information of the tree node corresponding to the privilege code based on the hierarchical information represented by the privilege code. For details, please refer to Figure 2 Step S203 of the embodiment shown, which will not be elaborated here.
[0046] Step S304: Add a user to the custom role to determine the custom role to which the user belongs. For details, please refer to Figure 2 Step S204 of the embodiment shown, which will not be elaborated here.
[0047] Step S305: Determine the user's permission information based on the permission set of the custom role to which the user belongs. For details, please refer to Figure 2 Step S205 of the illustrated embodiment, which will not be elaborated here.
[0048] Step S306: In response to the shielding operation on the target permission of any custom role, based on the target permission and the target permission tree structure of this custom role, determine the permission code to be shielded, and update the permission set of this custom role and the permission information of the user corresponding to this custom role based on the permission code to be shielded.
[0049] Specifically, the above Step S306 includes: Step S3061: Based on the target permission of this custom role, determine the target permission code corresponding to the target permission.
[0050] Step S3062: Based on the target permission code, obtain the target permission matrix corresponding to the target permission code.
[0051] Among them, each permission code corresponds to a permission matrix, and the permission configuration is configured for the permission matrix of the permission code. For the permission code corresponding to a configurable menu or operation, set the configurable field is_allowd_edit to 1, assign a corresponding tree_id to it, and set the Chinese or English name of the permission code. The permission matrix of the permission code includes information such as tree_id, permission name, is_allowd_edit, whether it is configurable, and permission description.
[0052] The edit authorization function interface supports the setting of fields such as tree_id, is_allowd_edit, and permission name (name), that is, these fields can be set. Among them, the is_allowd_edit field indicates whether it is configurable. Based on the is_allowd_edit field, the configurable permissions on the user permission configuration page can be determined. The name field represents the name of the menu or operation, that is, the permission name, and this field is used for the display of the permission name on the user permission configuration page. Among them, the user permission configuration page includes the user's permission information. The administrator can implement the dynamic adjustment of permissions based on the permission matrix table. Among them, the permission matrix table is shown in Table 1, and each row corresponds to the permission matrix of a permission code.
[0053] Table 1
[0054] Step S3063: Based on the target permission matrix, determine whether the target permission supports configuration.
[0055] It can be understood that, according to the is_allowed_edit field in the target permission matrix, it is determined whether the target permission supports configuration. If the is_allowed_edit field is 1, the target permission supports configuration; if the is_allowed_edit field is 0, the target permission does not support configuration.
[0056] It should be noted that the permissions in the custom role can be preset to support configuration.
[0057] Furthermore, according to this permission matrix, filtering can be performed from multiple dimensions such as roles and permission sets to improve the efficiency of role permission configuration. And combined with configurable fields, it supports flexible overriding and inheritance of permission rules.
[0058] Step S3064, if the target permission supports configuration, then based on the target permission code and the target permission tree structure, determine the permission code to be blocked.
[0059] It can be understood that a sub-role can override the permission configuration of the parent role by setting the is_allowed_edit field to 1. For example, if the parent role has the permission to create a user group and the sub-role inherits this permission, and the is_allowed_edit field of the sub-role's permission to create a user group is 1, then the sub-role can block this permission to create a user group.
[0060] The user permission configuration method provided by the embodiments of this application determines whether the target permission supports configuration by means of the target permission matrix, and only when it supports configuration will it further determine the permission code to be blocked. This avoids performing invalid operations on permissions that are not allowed to be configured, improving the accuracy and efficiency of permission management. For example, some basic permissions that are fixed and not allowed to be changed arbitrarily in some systems will not be misoperated.
[0061] In some optional embodiments, the above step S3064 includes: Step a1, based on the target permission code and the target permission tree structure, determine the target tree node of the target permission code in the target permission tree structure.
[0062] Step a2, if there are descendant tree nodes of the target tree node, then use the permission codes corresponding to the descendant tree nodes of the target tree node and the target permission code as the permission codes to be blocked.
[0063] Among them, the descendant tree nodes refer to all the child nodes of the target tree node and the child nodes of its child nodes, and all the hierarchical nodes recursively down.
[0064] Step a3, if there are no descendant tree nodes of the target tree node, then use the target permission code as the permission code to be blocked.
[0065] In the user permission configuration method provided by the embodiments of this application, when there are descendant tree nodes for a target tree node, the permission codes corresponding to the descendant tree nodes and the target permission code are used together as the permission codes to be blocked. This enables batch operations when it is necessary to block a certain permission and its related sub-permissions derived therefrom, without the need to search and set them one by one, greatly improving the efficiency of permission management.
[0066] In some optional embodiments, the above user permission configuration method further includes: Step b1, caching the permission set of the custom role to the client.
[0067] Step b2, whenever the permission set of the custom role is updated, based on the updated permission set of the custom role, update the permission set of the custom role cached on the client, so that when any user performs a target operation, based on the permission set of the custom role to which the user belongs, determine whether the user has the permission to perform the target operation. If the user has the permission to perform the target operation, allow the user to perform the target operation.
[0068] The client achieves immediate effect by caching the permission set of the custom role, that is: for users belonging to the custom system administrator role whose permissions need to cancel the modified role permissions, the user can uncheck the modified role permissions under the user through the AI platform in the role module. After the setting is completed, the role permissions are synchronously updated to the client in real time, that is, all users belonging to this role will cancel the modified role permissions.
[0069] Furthermore, the AI platform can adopt interceptor technology to determine whether a user has the permission to perform a target operation based on the permission set of the custom role to which the user belongs when the user initiates a target operation. If the user has the permission to perform the target operation, allow the user to perform the target operation. When the permission configuration cancels the modified role permissions for the role to which the user belongs, when the user logs in to the AI platform, the user does not have the permission to modify the role permissions.
[0070] In the user permission configuration method provided by the embodiments of this application, by caching the permission set of the custom role to the client. In this way, when a user performs a target operation, the client does not need to send a request to the server to obtain permission information each time, but directly reads the permission set data from the local cache to judge the user's permissions, greatly reducing the network interaction with the server, reducing network latency, making the operation response more rapid, and solving the problem of the lack of a real-time effect mechanism for user permission configuration in the related art.
[0071] In some optional embodiments, the above user permission configuration method further includes: Step c1, when the permission set of any custom role is updated, record the update information in the audit log, where the update information includes the update operator, the update time, and the update content.
[0072] That is to say, after the permission configuration of each custom role is completed, all permission change operations need to be recorded in the audit log, including the operator, i.e., the update operator, the update time, the priority, the modified content, i.e., the update content, etc.
[0073] The user permission configuration method provided by the embodiments of the present application solves the defect of the lack of audit log tracking function in the related art, and can quickly trace misoperations or malicious behaviors according to the audit log.
[0074] In some alternative embodiments, the above user permission configuration method further includes: Step d1, when the permission set of any custom role is updated, save the historical version of the permission set of the custom role.
[0075] Step d2, after the permission set of any custom role is updated, in response to the permission rollback operation, based on the historical version of the permission set of the custom role, restore the permission set of the custom role.
[0076] The AI platform supports the rollback function of permission set changes to prevent system exceptions caused by misoperations. It can be understood that if the permission set of the custom role is restored, the permission tree structure of the custom role and the permission information of the user corresponding to the custom role are also restored to the historical version.
[0077] The user permission configuration method provided by the embodiments of the present application, by supporting the rollback function of permission set changes, avoids problems such as system function exceptions and data leakage caused by incorrect permission configuration, and ensures the stable and secure operation of the system.
[0078] In some alternative embodiments, the above step S303 includes: Step e1, for any permission code in the permission set, determine the number of delimiters in the permission code. The permission code represents the hierarchical relationship through delimiters. For example, if the permission code is "User Management: New", the delimiter can be ":".
[0079] Step e2, based on the number of delimiters in the permission code, determine the hierarchical information represented by the permission code.
[0080] Among them, if the number of delimiters in the permission code is 0, the hierarchical information represented by the permission code is the first level; if the number of delimiters in the permission code is 1, the hierarchical information represented by the permission code is the second level; if the number of delimiters in the permission code is 2, the hierarchical information represented by the permission code is the third level, and so on. Among them, the first level, the second level, and the third level are the menu or operation levels of the permissions corresponding to the permission code.
[0081] Step e3, based on the hierarchical information represented by the permission code, determine the tree node code of the tree node corresponding to the permission code, so as to obtain the tree node codes of the tree nodes corresponding to all permission codes in the permission set.
[0082] Among them, the tree node code adopts the tree structure format of level 1.level 2.level 3......, supporting hierarchical expansion. Among them, level 1, level 2, and level 3 are the menu or operation levels of the permissions corresponding to the permission code. The shielding logic is that if the role permission of the first-level node is shielded, all its child nodes will be automatically invalidated and the permission will be shielded.
[0083] Exemplarily, the tree node code of the first-level menu "User Management" is "1", the tree node code of the second-level menu "User Group" is "1.1", and the tree node code of the third-level operation "Create User Group" is "1.1.1". The parent-child node relationship is identified by numbers separated by decimal points, and the tree node code of the parent node is the prefix of the child node. It can be understood that the tree node codes corresponding to different first-level menus are different, the tree node codes corresponding to different second-level menus are different, and the tree node codes corresponding to different third-level operations are different. That is to say, the tree node codes corresponding to different permission codes are different, that is, the corresponding tree nodes are different, and each permission corresponds to a unique tree node code.
[0084] Step e4, based on the tree node codes of the tree nodes corresponding to all permission codes in the permission set, determine whether there is a situation where the tree node code of the tree node corresponding to the first permission code is the prefix of the tree node code of the tree node corresponding to the second permission code in the permission set.
[0085] Among them, the first permission code can be any permission code in the permission set, and the second permission code is a permission code different from the first permission code.
[0086] Step e5, if there is a situation where the tree node code of the tree node corresponding to the first permission code is the prefix of the tree node code of the tree node corresponding to the second permission code in the permission set, then determine that the tree node corresponding to the first permission code is the parent node of the tree node corresponding to the second permission code, and the tree node corresponding to the second permission code is the child node of the tree node corresponding to the first permission code.
[0087] It is understandable that if the tree node code of the tree node corresponding to the first permission code in the permission set is a prefix of the tree node code of the tree node corresponding to the second permission code, then it is determined that the association relationship between the tree node corresponding to the first permission code and the tree node corresponding to the second permission code is a parent-child relationship.
[0088] Step e6, based on the tree node codes of the tree nodes corresponding to all permission codes in the permission set and the association relationships between the tree nodes corresponding to all permission codes in the permission set, construct a permission tree structure for the custom role, where the association relationships include parent-child relationships.
[0089] In some alternative embodiments, the above step b2 includes: Step b21, based on the updated permission set of the custom role, determine the incremental permission set update information of the updated permission set of the custom role and the permission set of the custom role before the update.
[0090] Step b22, based on the incremental permission set update information, update the permission set of the custom role cached by the client.
[0091] Compared with pushing the complete updated permission set every time there is an update, the incremental update provided by the user permission configuration method in the embodiments of the present application only transmits the changed part of the permission set, avoiding the complex operation of full data replacement, significantly reducing network latency, ensuring that the user permission configuration takes effect immediately, and improving the user operation response speed.
[0092] An embodiment of the present application provides a user permission configuration method, which is applied to an AI platform. Figure 4 For the process schematic diagram of the user permission configuration method provided by the embodiments of the present application, as Figure 4 shown, this process includes: The first step, role definition and hierarchical modeling. This step includes creating a custom role, configuring permissions in a visual interface, and hierarchical management of the tree structure. For details, please refer to the foregoing steps S201 to S203, and will not be elaborated here.
[0093] The second step, permission dynamic configuration mechanism. This step includes defining a permission matrix table, binding a unique tree node code, permission inheritance and override configuration, and dynamically adjusting the permission matrix. For details, please refer to the corresponding descriptions above, and will not be elaborated here.
[0094] Step 3: Dynamic permission adjustment and effectuation. This step includes caching the permission list at the front end, batch-adjusting the role permissions, synchronizing them to the client in real time, and validating the permission codes by the back-end interceptor. Among them, caching the permission list at the front end means that the client caches the permission set of the custom roles. For the batch adjustment of role permissions, please refer to the relevant description in the foregoing step S206 and will not be elaborated here. For the real-time synchronization to the client, please refer to the relevant description in the foregoing step b2 and will not be elaborated here. The back-end interceptor validating the permission codes means that the AI platform can adopt interceptor technology to intercept the operations initiated by users without permissions.
[0095] Step 4: Security auditing and log tracking. This step includes recording operation logs, storing the modified content, the operator, and the time, and supporting the permission rollback function. For details, please refer to the relevant descriptions in the foregoing steps c1, d1, and d2 and will not be elaborated here.
[0096] The user permission configuration method provided by the embodiments of the present application overcomes the limitations of the traditional RBAC model in complex business scenarios, brings an efficient, secure, and scalable access control solution to the AI platform, realizes precise control of the access resources of different users, and reduces the risks caused by improper permission management or operation errors. Aiming at the defects of the traditional RBAC model, the embodiments of the present application are committed to enhancing the flexibility and dynamics of permission configuration, supporting batch management and realizing immediate effectuation, thereby reducing the maintenance cost, preventing over-allocation of permissions, enhancing the system security, and reducing the risk of misoperations through the audit log and permission rollback functions.
[0097] To make the user permission configuration method of the embodiments of the present application clearer, the following will be described with reference to Figure 5 the interaction diagram showing the user permission configuration. As Figure 5As shown, the AI platform supports basic roles and custom roles. The system administrator among the basic roles has all the permissions under the user management module. The system administrator enters the account and password on the login interface of the AI platform to log in to the AI platform, enters the role management module of the AI platform, and creates custom roles with the permission attributes of system administrator, group administrator, auditor, and ordinary user through the role management module. It can be understood that the custom roles created through the role management module are saved in the database. The custom roles have the permission configuration function. The system administrator can modify the permission configuration of the custom roles and save the permission configuration of the custom roles in the database. After the custom roles are successfully created, the permission configuration can be performed multiple times. Based on the set of permissions that have and can be configured for the permission attributes, some menus or operation permissions are blocked to form the permissions of the new role, etc. The system administrator creates users through the user management module, selects the users who need to be empowered to determine the roles to which the users belong, and determines the permission configuration of the roles to which the users belong as the permission configuration of the users to complete user empowerment. It should be noted that the AI platform also includes other modules.
[0098] Taking the custom role with the permission attributes of system administrator, group administrator, auditor, and ordinary user for the roles to which the AI platform users belong as an example to describe the permission configuration of the roles: The system administrator has all the permissions under the user management module. For the custom role created with the system administrator as the permission attribute, the permissions of the user, user group, and role modules under the user management module can be set in the permission configuration. Then, for the custom role created with the system administrator as the permission attribute, after the user under this custom role logs in to the AI platform, they have the permissions related to users, user groups, and roles; when there is a business requirement to modify a certain permission attribute of the users under this custom role, such as canceling the role module permission, the role module can be blocked in the permission configuration, and then all the users under this custom role who log in to the AI platform do not have the role module permission.
[0099] The group administrator has the permissions of the user module and does not have the permissions of the user group and role modules. For the custom role created with the group administrator as the permission attribute, the permission configuration under the user module can be selected in the permission configuration, and the permissions under the user group and role modules cannot be configured. Then, after the user under the custom role created with the group administrator as the permission attribute logs in to the AI platform, they have the permissions related to users; when there is a business requirement and the group administrator cannot create users, the create user permission can be blocked in the permission configuration. After this permission is blocked, the users under this custom role who log in to the AI platform do not have the permission to create users. If the auditor only has the permission to query the user's basic information and quota permission information, then for the custom role created with the auditor as the permission attribute, only the permission to query the user's basic information and quota permission information can be configured in the permission configuration, and the sub-menus under the user's basic information and permission quota information cannot be configured. The user who sets this custom role can only query the user's basic information and quota permission information page and cannot perform other operations. When the permissions under this custom role are blocked, the user under this custom role will be prompted that they do not have any permissions when logging in to the AI platform.
[0100] Ordinary users do not have the permission to access the user management module. Therefore, users under the custom role created with ordinary users as the permission attribute cannot view the functions related to the user management module after logging in to the AI platform.
[0101] The user permission configuration method provided by the embodiments of the present application adopts a role-based dynamic permission configuration mechanism, effectively solving the deficiencies of the RBAC model in terms of flexibility and scalability. At the same time, while improving work efficiency, it significantly enhances the security of the system.
[0102] The user permission configuration method provided by the embodiments of the present application improves the flexibility of user management. By adopting a tree-like hierarchical permission inheritance model (such as the tree_id coding mechanism), it supports dynamic adjustment of the permission inheritance relationship, realizes fine control and batch management of permissions to adapt to complex business scenarios. And combined with the dynamic permission matrix configuration technology, it supports multi-maintenance screening and real-time synchronization, optimizes the operation efficiency, and thus reduces the cost of large-scale role permission maintenance. By introducing a security audit log and a permission rollback mechanism, it ensures the traceability and recoverability of permission changes. At the same time, the interceptor technology is used to achieve the immediate effect of permission changes, avoiding the risks of misoperation or permission abuse. The user permission configuration method provided by the embodiments of the present application can be widely applied to the entire process of permission definition, configuration, and effectiveness, is applicable to AI platforms in multiple fields, and has broad application prospects.
[0103] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0104] The embodiments of the present application also provide a user permission configuration device, as Figure 6 shown. The user permission configuration device includes: A creation module 601 for creating multiple custom roles.
[0105] The first determination module 602 is configured to determine a permission set of a custom role based on attribute information of the custom role, where the permission set includes multiple permission codes, and each permission corresponds to one permission code.
[0106] The second determination module 603 is configured to determine a permission tree structure of the custom role based on the permission set of the custom role, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and the hierarchical information of the tree node corresponding to the permission code is determined based on the hierarchical information represented by the permission code.
[0107] The third determination module 604 is configured to add a user to the custom role to determine the custom role to which the user belongs.
[0108] The fourth determination module 605 is configured to determine the permission information of the user based on the permission set of the custom role to which the user belongs.
[0109] The fifth determination module 606 is configured to, in response to a shielding operation on a target permission of any custom role, determine a permission code to be shielded based on the target permission and the target permission tree structure of the custom role, and update the permission set of the custom role and the permission information of the user corresponding to the custom role based on the permission code to be shielded.
[0110] In some alternative embodiments, the fifth determination module 606 includes: The first determination unit is configured to determine a target permission code corresponding to the target permission based on the target permission of the custom role.
[0111] The first acquisition unit is configured to acquire a target permission matrix corresponding to the target permission code based on the target permission code.
[0112] The second determination unit is configured to determine whether the target permission supports configuration based on the target permission matrix.
[0113] The third determination unit is configured to, if the target permission supports configuration, determine a permission code to be shielded based on the target permission code and the target permission tree structure.
[0114] In some alternative embodiments, the third determination unit includes: The fourth determination unit is configured to determine a target tree node of the target permission code in the target permission tree structure based on the target permission code and the target permission tree structure.
[0115] The fifth determination unit is configured to, if the target tree node has descendant tree nodes, use the permission codes corresponding to the descendant tree nodes of the target tree node and the target permission code as the permission codes to be shielded.
[0116] The sixth determination unit is configured to, if the target tree node has no descendant tree nodes, use the target permission code as the permission code to be shielded.
[0117] In some alternative embodiments, the user permission configuration device further includes: A cache unit, configured to cache the permission set of a custom role to the client.
[0118] An update unit, configured to, whenever the permission set of a custom role is updated, update the permission set of the custom role cached in the client based on the updated permission set of the custom role, so as to determine whether a user has the permission to perform a target operation based on the permission set of the custom role to which the user belongs when any user performs the target operation. If the user has the permission to perform the target operation, the user is allowed to perform the target operation.
[0119] In some alternative embodiments, the user permission configuration device further includes: A recording unit, configured to record update information to an audit log whenever the permission set of any custom role is updated, where the update information includes an update operator, an update time, and update content.
[0120] In some alternative embodiments, the user permission configuration device further includes: A saving unit, configured to save a historical version of the permission set of a custom role whenever the permission set of any custom role is updated.
[0121] A restoring unit, configured to, after the permission set of any custom role is updated, in response to a permission rollback operation, restore the permission set of the custom role based on the historical version of the permission set of the custom role.
[0122] In some alternative embodiments, the second determination module 603 includes: A seventh determination unit, configured to determine the number of delimiters in any permission code in the permission set.
[0123] An eighth determination unit, configured to determine the hierarchical information represented by the permission code based on the number of delimiters in the permission code.
[0124] A ninth determination unit, configured to determine the tree node code of the tree node corresponding to the permission code based on the hierarchical information represented by the permission code, so as to obtain the tree node codes of the tree nodes corresponding to all the permission codes in the permission set.
[0125] A judgment unit, configured to judge whether there is a prefix relationship between the tree node code of the tree node corresponding to a first permission code and the tree node code of the tree node corresponding to a second permission code in the permission set based on the tree node codes of the tree nodes corresponding to all the permission codes in the permission set.
[0126] A tenth determination unit, configured to determine that the tree node corresponding to the first permission code is the parent node of the tree node corresponding to the second permission code, and the tree node corresponding to the second permission code is the child node of the tree node corresponding to the first permission code if the tree node code of the tree node corresponding to the first permission code in the permission set is a prefix of the tree node code of the tree node corresponding to the second permission code.
[0127] A construction unit, configured to construct a permission tree structure of a custom role based on the tree node codes of the tree nodes corresponding to all permission codes in the permission set and the association relationship between the tree nodes corresponding to all permission codes in the permission set, where the association relationship includes a parent-child relationship.
[0128] For the description of the features in the embodiments corresponding to the user permission configuration device, reference may be made to the relevant descriptions in the embodiments corresponding to the user permission configuration method, which will not be elaborated here one by one.
[0129] An embodiment of the present application further provides an electronic device, as Figure 7 shown, including a processor 701 and a memory 702. A computer program is stored in the memory 702, and the processor 701 is configured to run the computer program to execute the steps in any one of the above embodiments of the user permission configuration method.
[0130] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, where the computer program is configured to execute the steps in any one of the above embodiments of the user permission configuration method when running.
[0131] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM for short), a random access memory (RAM for short), a mobile hard disk, a magnetic disk, or an optical disc that can store a computer program.
[0132] An embodiment of the present application further provides a computer program product, where the computer program product includes a computer program, and the computer program implements the steps in any one of the above embodiments of the user permission configuration method when executed by a processor.
[0133] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium, and the non-volatile computer-readable storage medium stores a computer program, and the computer program implements the steps in any one of the above embodiments of the user permission configuration method when executed by a processor.
[0134] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0135] The above has introduced in detail a user privilege configuration method, apparatus, electronic device, and storage medium provided by this application. Specific examples are used herein to illustrate the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A method for configuring user permissions, characterized in that Including: Create multiple custom roles; Based on the attribute information of the custom roles, determine the permission set of the custom roles, where the permission set includes multiple permission codes, and each permission corresponds to one permission code; Based on the permission set of the custom roles, determine the permission tree structure of the custom roles, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and determine the hierarchical information of the tree node corresponding to the permission code based on the hierarchical information represented by the permission code; Add users to the custom roles to determine the custom roles to which the users belong; Based on the permission set of the custom roles to which the users belong, determine the permission information of the users; In response to the shielding operation of the target permission of any custom role, based on the target permission and the target permission tree structure of the custom role, determine the permission code to be shielded, and update the permission set of the custom role and the permission information of the users corresponding to the custom role based on the permission code to be shielded.
2. The method according to claim 1, wherein The determining the permission code to be shielded based on the target permission and the target permission tree structure of the custom role includes: Based on the target permission of the custom role, determine the target permission code corresponding to the target permission; Based on the target permission code, obtain the target permission matrix corresponding to the target permission code; Based on the target permission matrix, determine whether the target permission supports configuration; If the target permission supports configuration, then based on the target permission code and the target permission tree structure, determine the permission code to be shielded.
3. The method according to claim 2, wherein The determining the permission code to be shielded based on the target permission code and the target permission tree structure includes: Based on the target permission code and the target permission tree structure, determine the target tree node of the target permission code in the target permission tree structure; If the target tree node has descendant tree nodes, then use the permission codes corresponding to the descendant tree nodes of the target tree node and the target permission code as the permission codes to be shielded; If the target tree node does not have descendant tree nodes, then use the target permission code as the permission code to be shielded.
4. The method according to claim 1, characterized in that, The method further includes: Cache the permission set of the custom roles to the client; Whenever the permission set of the custom roles is updated, based on the updated permission set of the custom roles, update the permission set of the custom roles cached on the client, so that when any user performs a target operation, based on the permission set of the custom roles to which the user belongs, determine whether the user has the permission to perform the target operation. If the user has the permission to perform the target operation, then allow the user to perform the target operation.
5. The method according to claim 1, wherein The method further includes: When the permission set of any custom role is updated, record the update information in the audit log, where the update information includes the update operator, the update time, and the update content.
6. The method according to claim 1, characterized in that, The method further includes: When the permission set of any custom role is updated, save the historical version of the permission set of the custom role; After the permission set of any custom role is updated, in response to the permission rollback operation, based on the historical version of the permission set of the custom role, perform the restoration of the permission set of the custom role.
7. The method according to claim 1, characterized in that Determining the permission tree structure of the custom role based on the permission set described above includes: For any permission code in the permission set, determining the number of delimiters in the permission code; Based on the number of delimiters in the permission code, determining the hierarchical information represented by the permission code; Based on the hierarchical information represented by the permission code, determining the tree node code of the tree node corresponding to the permission code, so as to obtain the tree node codes of the tree nodes corresponding to all permission codes in the permission set; Based on the tree node codes of the tree nodes corresponding to all permission codes in the permission set, determining whether there is a prefix relationship where the tree node code corresponding to the first permission code in the permission set is the prefix of the tree node code corresponding to the second permission code; If there is a prefix relationship where the tree node code corresponding to the first permission code in the permission set is the prefix of the tree node code corresponding to the second permission code, determining that the tree node corresponding to the first permission code is the parent node of the tree node corresponding to the second permission code, and the tree node corresponding to the second permission code is the sub-node of the tree node corresponding to the first permission code; Based on the tree node codes of the tree nodes corresponding to all permission codes in the permission set and the association relationship between the tree nodes corresponding to all permission codes in the permission set, constructing the permission tree structure of the custom role, where the association relationship includes the parent-child relationship.
8. A user privilege configuration device, characterized in that, Includes: A creation module for creating multiple custom roles; A first determination module for determining the permission set of the custom role based on the attribute information of the custom role, where the permission set includes multiple permission codes, and each permission corresponds to one permission code; A second determination module for determining the permission tree structure of the custom role based on the permission set of the custom role, where each permission code in the permission set corresponds to a tree node in the permission tree structure, and determining the hierarchical information of the tree node corresponding to the permission code based on the hierarchical information represented by the permission code; A third determination module for adding a user to the custom role to determine the custom role to which the user belongs; A fourth determination module for determining the permission information of the user based on the permission set of the custom role to which the user belongs; A fifth determination module for, in response to a shielding operation on the target permission of any custom role, determining the permission code to be shielded based on the target permission and the target permission tree structure of the custom role, and updating the permission set of the custom role and the permission information of the user corresponding to the custom role based on the permission code to be shielded.
9. An electronic device, characterized in that, Includes: A memory for storing a computer program; A processor for implementing the steps of the user permission configuration method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, where the computer program implements the steps of the user permission configuration method according to any one of claims 1 to 7 when executed by a processor.
Citation Information
Patent Citations
Data permission testing method and device
CN111400170A
Authority control method and device, electronic equipment and storage medium
CN115221481A
Menu configuration and display method and device, electronic equipment and storage medium
CN117667094A
Project operation and maintenance-oriented heterogeneous data security management and control method, system and equipment and medium
CN119066678A
System and method for securing windows discretionary access control
US20230161892A1