Interface authority management method and device, equipment and storage medium
By storing the mapping relationship between user information and interface information in the cache structure, and synchronizing data updates with a multi-level caching mechanism and message queue, the problem of frequent database access in API permission management is solved, and rapid response and user experience is achieved.
Patent Information
- Application Number
- CN202410080921.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, API permission management frequently accesses databases lead to excessive pressure on databases, slow user response and poor user experience.
By storing the mapping relationship between user information and interface information in the cache structure, the number of accesses to the database is reduced, and the multi-level caching mechanism (ehcache and Redis) is used to accelerate permission verification, and data updates are synchronized using message queues.
Reduces database pressure, improves access speed and improves user experience.
Smart Images

Figure CN120354441A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing, and in particular to an interface permission management method, apparatus, device, and storage medium. Background Art
[0002] In the related art, since application programming interfaces (APIs) are open to different customers, not all API permissions are released for security reasons. Different customers have different API permissions, and problems have followed. In the above technology, permission data is stored in a database, and the database permission settings are accessed in real time as needed. Since permission verification is an operation with a very high usage frequency, if the database is accessed in real time at a high frequency, it will not only put pressure on the database, but also cause slow user response, resulting in a very poor user experience. Summary of the Invention
[0003] In view of this, embodiments of this application provide an interface permission management method, apparatus, device, and storage medium, aiming to reduce the number of accesses to the database, greatly relieve the pressure on the database, achieve fast access response, and improve the user experience.
[0004] The technical solution of the embodiments of this application is implemented as follows:
[0005] Embodiments of this application provide an interface permission management method, including:
[0006] Obtain the call request information of the user;
[0007] Determine the user information of the user and the interface to be accessed based on the call request information;
[0008] If the call request information of the user is received for non-first time, search in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information; the first mapping relationship represents the mapping relationship between the user information and the interface information;
[0009] Judge whether the interface to be accessed exists in the first mapping relationship;
[0010] If the interface to be accessed exists in the first mapping relationship, determine the access permission of the user to the interface to be accessed.
[0011] In the above solution, the cache structure at least includes a first cache structure and a second cache structure; before searching in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information, the method further includes:
[0012] If the call request information of the user is obtained for the first time, search for the first mapping relationship in the preset permission information of the preset database based on the user information; the preset permission information includes preset user information, preset interface information, and a first preset relationship between the preset user information and the preset interface information; the first preset relationship includes the first mapping relationship;
[0013] Store the first mapping relationship in the first cache structure and the second cache structure.
[0014] In the above solution, the cache structure at least includes a first cache structure and a second cache structure; the step of searching for the first mapping relationship corresponding to the user information in the cache structure includes:
[0015] Search for the first mapping relationship in the first cache structure based on the user information;
[0016] If the first mapping relationship does not exist in the first cache structure, search for the first mapping relationship in the second cache structure based on the user information.
[0017] In the above solution, the preset permission information further includes: preset role information, a second preset relationship, and a third preset relationship. The second preset relationship represents the corresponding relationship between the preset user information and the preset role information, and the third preset relationship represents the corresponding relationship between the preset role information and the preset interface information; the step of searching for the first mapping relationship in the preset permission information of the preset database based on the user information includes:
[0018] Search for the second mapping relationship corresponding to the user information in the second preset relationship; the second mapping relationship represents the mapping relationship between the user information and the role information;
[0019] Search for the third mapping relationship corresponding to the user information in the third preset relationship; the third mapping relationship represents the mapping relationship between the role information and the interface information;
[0020] Determine the first mapping relationship based on the second mapping relationship and the third mapping relationship.
[0021] In the above solution, the method further includes:
[0022] Monitor the first mapping relationship in the preset database to obtain change data;
[0023] Load the changed first mapping relationship in the preset database into the first cache structure based on the change data.
[0024] In the above solution, the first cache structure includes at least one node; the method further includes:
[0025] Monitoring the message queue corresponding to the preset database according to the at least one node to obtain the change data;
[0026] If a first node among the at least one node monitors the change data, updating the first mapping relationship of the first node based on the change data.
[0027] In the above solution, the method further includes:
[0028] If the first mapping relationship in the first cache structure changes, updating the time stamp of the first cache structure;
[0029] Loading the first mapping relationship in the first cache structure to the second cache structure according to the time stamp.
[0030] An embodiment of the present application provides an interface permission management device, including:
[0031] An obtaining module, configured to obtain call request information of a user;
[0032] A first determining module, configured to determine user information of the user and an interface to be accessed based on the call request information;
[0033] A first searching module, configured to, if the call request information of the user is received not for the first time, search in the cache structure according to the user information to obtain a first mapping relationship corresponding to the user information; the first mapping relationship represents a mapping relationship between the user information and interface information;
[0034] A judging module, configured to judge whether the interface to be accessed exists in the first mapping relationship;
[0035] A second determining module, configured to, if the interface to be accessed exists in the first mapping relationship, determine the access permission of the user to the interface to be accessed.
[0036] An embodiment of the present application provides an interface permission management device, including: a processor and a memory for storing a computer program that can run on the processor, wherein,
[0037] The processor is configured to execute the steps of the above interface permission management method when running the computer program.
[0038] An embodiment of the present application provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above interface permission management method are implemented.
[0039] An embodiment of the present application provides an interface permission management method, apparatus, device, and storage medium. The method includes: obtaining call request information of a user; determining user information of the user and an interface to be accessed based on the call request information; if the call request information of the user is received for the non-first time, searching in a cache structure according to the user information to obtain a first mapping relationship corresponding to the user information; the first mapping relationship represents the mapping relationship between the user information and the interface information; determining whether the interface to be accessed exists in the first mapping relationship; if the interface to be accessed exists in the first mapping relationship, determining the access permission of the user for the interface to be accessed. By adopting the technical solution of the embodiment of the present application, by searching for the first mapping relationship between the user information and the interface information of the user in the cache structure to determine whether the user has the access permission for the interface to be accessed, the number of accesses to the database can be reduced, the pressure on the database can be greatly reduced, fast access response can be achieved, and the user experience can be improved. Description of the Drawings
[0040] Figure 1 It is a schematic flowchart of the implementation process of the interface permission management method in the embodiment of the present application;
[0041] Figure 2 It is a schematic diagram of the interaction between the readable cache storage controller module and the database in the interface permission management method in an application example of the embodiment of the present application;
[0042] Figure 3 It is a schematic flowchart of the implementation process of the interface permission management method in an application example of the embodiment of the present application;
[0043] Figure 4 It is a schematic diagram of the hierarchical composition of the interface permission management method in an application example of the embodiment of the present application;
[0044] Figure 5 It is a schematic diagram of the structure of the interface permission management apparatus in the embodiment of the present application;
[0045] Figure 6 It is a schematic diagram of the structure of the interface permission management device in the embodiment of the present application. Detailed Embodiments
[0046] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used in the specification of this application herein are only for the purpose of describing specific embodiments and are not intended to limit this application.
[0047] In the related art, the generally adopted technical concept is a management mode of centralized control and multi-channel distribution. It mainly centrally configures and manages the users, roles, and corresponding access permissions of all business systems through a database on a central platform, and accesses the pre-set data in the database in the form of interface access, and distributes and configures the user role permissions to each business system.
[0048] Since the application programming interface will be open to different customers, for security reasons, not all API permissions will be released. Different customers have different API permissions, and problems follow. Permission verification is an operation with a very high usage frequency. If the database is requested every time, it will not only put pressure on the database, but also cause slow user response, resulting in a very bad user experience.
[0049] In addition, since the database permission settings are accessed in real time as needed, and the operations and row levels are processed separately, but since each page and many service functions need to perform permission checks, it will also cause relatively frequent database access. Moreover, particularly disadvantageously, for the asynchronous processing mode, it increases the writing complexity of the permission judgment logic.
[0050] To solve the problems existing in the above technical solutions, the embodiments of the present application provide an interface permission management method, device, equipment, and storage medium, aiming to reduce the number of accesses to the database, greatly relieve the pressure on the database, achieve fast access response, and improve the user experience.
[0051] The embodiments of the present application provide an interface permission management method, as Figure 1 shown, the method includes:
[0052] Step 101: Obtain the call request information of the user.
[0053] Exemplarily, the interface permission management method can be applied to the server of the interface permission management system; the call request information can be the information sent by the user terminal to the server to request access to the API, where the user terminal can be a client connected to the interface permission management system.
[0054] Step 102: Determine the user information of the user and the interface to be accessed based on the call request information.
[0055] Exemplarily, the user information can be the user identifier of the user; the interface to be accessed can be the API to be accessed by the user.
[0056] As an example, the server may include a service request receiving module, which can receive call request information; the server may also include a data parsing module, which can parse the authentication information corresponding to the call request information to obtain user information and the interface to be accessed. Among them, the authentication information can be determined according to the actual situation and is not limited here.
[0057] Step 103: If it is not the first time to receive the user's call request information, search in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information; the first mapping relationship represents the mapping relationship between the user information and the interface information.
[0058] Exemplarily, not receiving the user's call request information for the first time can be receiving the call request information of the same user at least for the second time. Among them, the multiple call request information received for the same user multiple times can be the same or different, that is, the interfaces to be accessed requested by the same user multiple times can be the same or different, and this is not limited here.
[0059] Exemplarily, since it is not the first time to receive the user's call request information, the first mapping relationship between the user information and the interface information of this user is stored in the cache structure. The server may also include a readable cache storage controller module, which can match according to the user information and the first preset relationship stored in the cache structure to obtain the first mapping relationship corresponding to the user information, where the first preset relationship at least includes the first mapping relationship.
[0060] In an application example, the cache structure at least includes a first cache structure and a second cache structure; searching in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information includes:
[0061] Search for the first mapping relationship in the first cache structure based on the user information;
[0062] If the first mapping relationship does not exist in the first cache structure, search for the first mapping relationship in the second cache structure based on the user information.
[0063] Exemplarily, the first cache structure can be an open-source cache (ehcache) based on a standard; the second cache structure can be a Remote Dictionary Server (Redis). It should be noted that the steps of searching for the first mapping relationship in the first cache structure based on the user information and searching for the first mapping relationship in the second cache structure based on the user information can refer to the description of searching in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information in the above embodiments, and this is not limited here.
[0064] As an example, a first lookup duration for looking up a first mapping relationship in a first cache structure based on user information can be obtained; if the first lookup duration is greater than a first preset duration, then the first mapping relationship is looked up in a second cache structure based on the user information. In some embodiments, a second lookup duration for looking up the first mapping relationship in the second cache structure based on the user information can be obtained; if the second lookup duration is greater than a second preset duration, then the first mapping relationship is looked up in a preset database; wherein, the first preset duration is less than the second preset duration.
[0065] In some embodiments, if the first cache structure generates a downtime message, then the first mapping relationship is looked up in the second cache structure based on the user information. Wherein, the downtime message indicates that the first cache structure is in a downtime state. Specifically, the downtime situation can be actively discovered through real-time monitoring by a service monitoring tool; it can also be checked whether there is an ehcache downtime situation by accessing the fault through user feedback; or an ehcache downtime reminder message can be generated when a fault occurs in the ehcache middleware, or the server where ehcache is located fails, or the server where ehcache is located loses power, etc.
[0066] The first cache structure in the embodiments of the present application can use the ehcache lightweight caching technology, which is fast, simple, low-consumption, highly scalable, supports object or serialized caching, reduces the number of times the application program accesses the physical data source, thereby improving the running performance of the application program; in the embodiments of the present application, the second cache structure uses Redis, and the data of the first cache structure can also be persistently stored in the second cache structure. In the embodiments of the present application for permission caching, Redis is used as a secondary cache, and the efficient storage of ehcache can still be used in a cluster environment. By using a multi-level caching mechanism in the embodiments of the present application, the pressure on the database can be greatly reduced, fast access response can be achieved, and the user experience can be improved.
[0067] It can be understood that since a cluster uses multiple computers to cooperate, it can provide higher computing performance and faster data processing speed, and has obvious advantages in processing a large amount of data and running complex calculations. Ehcache uses a message queue, and each application node subscribes to a predefined topic. At the same time, when an element in the node is updated, the updated element is also published to the topic. Each application server node obtains the latest data by listening to the message queue, and then updates its own ehcache cache respectively.
[0068] In an application example, the cache structure includes at least a first cache structure and a second cache structure; before looking up the first mapping relationship corresponding to the user information in the cache structure according to the user information, the method further includes:
[0069] If the call request information of the user is obtained for the first time, search for the first mapping relationship in the preset permission information of the preset database based on the user information; the preset permission information includes preset user information, preset interface information, and a first preset relationship between the preset user information and the preset interface information; the first preset relationship includes the first mapping relationship.
[0070] Store the first mapping relationship in the first cache structure and the second cache structure.
[0071] Exemplarily, the preset database can be a database responsible for storing, managing, and processing data in the interface permission management system; the preset permission information can be permission data. The preset user information can include the user who sends the call request information and other users who do not send the call request information; the first preset relationship represents the mapping relationship between each user and the accessible interfaces corresponding to the user, where the accessible interfaces include the interfaces to be accessed and the unaccessed interfaces; the preset interface information can include the interfaces to be accessed and the unaccessed interfaces corresponding to the user who sends the call request information, and the interfaces to be accessed and the unaccessed interfaces corresponding to the users who do not send the call request information.
[0072] As an example, storing the first mapping relationship in the first cache structure and the second cache structure can be that the database asynchronously synchronizes the first mapping relationship of the APIs accessible to the current user in the database to the first mapping relationship tables of ehcache and Redis in the readable cache storage controller module through a Message Queue (MQ) component. When the same user accesses the same API again, first query the data in ehcache. If the third mapping relationship of the corresponding API for the current user is found through the user identifier, the current user can directly access the API to be accessed, thereby reducing the access pressure on the database.
[0073] In some embodiments, there is a first hierarchical structure between the preset user information and the preset interface information; the first hierarchical structure indicates that the level of the preset user information is higher than that of the preset interface information. It should be noted that the level of the preset user information being higher than that of the preset interface information means that one user can correspond to multiple accessible interfaces.
[0074] In some embodiments, the preset database further includes preset tenant information, and the preset tenant information includes at least one tenant, where the first tenant among the at least one tenant can correspond to the user who sends the call request information and the users who do not send the call request. In some embodiments, the tenant can be at the row level.
[0075] In some embodiments, the preset database further includes preset operation information, and the preset operation information includes multiple operations, where each accessible interface can include at least one operation corresponding to the interface.
[0076] In some embodiments, at least one of preset tenant information, preset user information, preset role information, preset interface information, and preset operation information can be stored in both the client and the server simultaneously to reduce the access pressure on the database.
[0077] It can be understood that a hierarchical structure refers to logically dividing a subsystem into many sets, and the formation of the relationships between layers should follow certain rules. The advantages include: (1) It is easy to ensure the correctness of the system. The bottom-up design method makes all decisions in the design orderly, or based on a relatively reliable foundation, making it easier to ensure the correctness of the entire system. (2) It is easy to expand and maintain. Adding, modifying, or replacing a module or an entire layer in the system will not affect other layers as long as the interfaces between the corresponding layers are not changed, which will surely make the system maintenance and expansion easier.
[0078] In the embodiments of the present application, before the call request information of the user is obtained for the first time, the cache structure does not include the first mapping relationship corresponding to the user. Therefore, it is necessary to search for the first mapping relationship in the preset database according to the user information and store it in the cache structure.
[0079] In an application example, the preset permission information further includes: preset role information, a second preset relationship, and a third preset relationship. The second preset relationship represents the corresponding relationship between the preset user information and the preset role information, and the third preset relationship represents the corresponding relationship between the preset role information and the preset interface information; searching for the first mapping relationship in the preset permission information of the preset database based on the user information includes:
[0080] Searching according to the user information in the second preset relationship to obtain a second mapping relationship corresponding to the user information; the second mapping relationship represents the mapping relationship between the user information and the role information;
[0081] Searching according to the user information in the third preset relationship to obtain a third mapping relationship corresponding to the user information; the third mapping relationship represents the mapping relationship between the role information and the interface information;
[0082] Determining the first mapping relationship based on the second mapping relationship and the third mapping relationship.
[0083] Exemplarily, the preset role information may include a first role corresponding to the user who sends the call request information and a second role corresponding to other users who do not send the call request information; the second preset relationship represents the mapping relationship between each user and the role corresponding to the user, and the third preset relationship represents the mapping relationship between each role and the accessible interfaces corresponding to the role; the preset interface information may include the interfaces to be accessed corresponding to the first role and the unaccessed interfaces, as well as the interfaces to be accessed corresponding to the second role and the unaccessed interfaces.
[0084] In some embodiments, there is a second hierarchical structure between the preset user information and the preset role information; the second hierarchical structure represents that the level of the preset user information is higher than that of the preset role information. There is a third hierarchical structure between the preset role information and the preset interface information; the third hierarchical structure represents that the level of the preset role information is higher than that of the preset interface information. It should be noted that the fact that the level of the preset user information is higher than that of the preset role information means that one user can correspond to multiple roles. The fact that the level of the preset role information is higher than that of the preset interface information means that one role can correspond to multiple accessible interfaces.
[0085] Exemplarily, based on the second mapping relationship and the third mapping relationship, the first mapping relationship can be determined, which can be to determine the mapping relationship between user information and interface information based on the mapping relationship between user information and role information, and the mapping relationship between role information and interface information.
[0086] In some embodiments, the second mapping relationship and / or the third mapping relationship can be stored in the first cache structure and the second cache structure, so as to determine the second mapping relationship between user information and role information in the first cache structure or the second cache structure according to the user information; determine the third mapping relationship between role information and interface information in the first cache structure or the second cache structure based on the role information; determine the first mapping relationship in the first cache structure or the second cache structure based on the second mapping relationship and the third mapping relationship.
[0087] Step 104: Determine whether the to-be-accessed interface exists in the first mapping relationship.
[0088] Step 105: If the to-be-accessed interface exists in the first mapping relationship, determine the access permission of the user to the to-be-accessed interface.
[0089] Exemplarily, it can be determined whether the to-be-accessed interface exists in the interface information having a mapping relationship with the user information. If the to-be-accessed interface exists in the interface information, it is determined that the user has the access permission to the to-be-accessed interface; if the to-be-accessed interface does not exist in the interface information, it is determined that the user does not have the access permission to the to-be-accessed interface.
[0090] In an application example, the method further includes:
[0091] Monitor the first mapping relationship in the preset database to obtain change data;
[0092] Load the changed first mapping relationship in the preset database into the first cache structure based on the change data.
[0093] Exemplarily, monitor the first mapping relationship in the preset database to obtain changed data, which may be to monitor the second mapping relationship and / or the third mapping relationship; in the case where the second mapping relationship and / or the third mapping relationship change, determine the changed data for the change of the first mapping relationship.
[0094] Exemplarily, the preset database can pass the changed data to the first cache structure through a message queue to load the changed first mapping relationship in the preset database into the first cache structure based on the changed data. In some embodiments, the preset database can also pass the changed data to the second cache structure and other cache structures through a message queue to load the changed first mapping relationship in the preset database into the second cache structure and other cache structures based on the changed data.
[0095] In an application example, the first cache structure includes at least one node; the method further includes:
[0096] Monitor the message queue corresponding to the preset database according to at least one node to obtain changed data;
[0097] If the first node in at least one node monitors the changed data, update the first mapping relationship of the first node based on the changed data.
[0098] As an example, for the scenario where a cluster uses multiple computers to cooperate, each node in the at least one node included in the first cache structure can correspond to a first sub-structure, and each node in the at least one node can monitor the preset database through a message queue to obtain changed data; in the case where the first node monitors the changed data, update the first mapping relationship of the first sub-structure corresponding to the first node based on the changed data.
[0099] The embodiments of the present application use the MQ message component and the timestamp update synchronization mechanism to perform data synchronization and update to ensure the consistency of data in different storage components (cache structure, database).
[0100] In an application example, the method further includes:
[0101] If the first mapping relationship in the first cache structure changes, update the timestamp of the first cache structure;
[0102] Load the first mapping relationship in the first cache structure into the second cache structure according to the timestamp.
[0103] Exemplarily, the second cache structure depends on the first cache structure; if the first mapping relationship in the first cache structure changes, the timestamp of the first cache structure is updated. It can be to obtain the first timestamp of the first cache structure and the pre-stored second timestamp before obtaining the first mapping relationship in the second cache structure, where the second timestamp can be the timestamp obtained by updating the timestamp of the first cache structure when the first cache structure changes.
[0104] Exemplarily, loading the first mapping relationship in the first cache structure into the second cache structure according to the timestamp can be to determine whether the first timestamp is consistent with the pre-stored second timestamp; if the first timestamp is consistent with the second timestamp, the first mapping relationship in the first cache structure and the second cache structure has not changed, and directly obtain the first mapping relationship in the second cache structure; if the first timestamp is inconsistent with the second timestamp, the first mapping relationship in the first cache structure has changed, and update the first mapping relationship in the second cache structure based on the changed first mapping relationship in the first cache structure, so that the changed first mapping relationship in the first cache structure is loaded into the second cache structure, and then obtain the first mapping relationship in the second cache structure.
[0105] It can be understood that in the case of the first change of the first cache structure, update the first mapping relationship in the second cache structure based on the first mapping relationship in the first cache structure after the first change, and pre-store the second timestamp; if the first timestamp of the first cache structure is obtained before the second change of the first cache structure, the first timestamp is consistent with the second timestamp, and the first mapping relationship in the second cache structure can be directly obtained; if the first timestamp of the first cache structure is obtained after the second change of the first cache structure, the first timestamp corresponding to the second change is inconsistent with the second timestamp corresponding to the first change, and it is necessary to update the first mapping relationship in the second cache structure with the first mapping relationship in the first cache structure after the second change, and then obtain the first mapping relationship in the second cache structure.
[0106] The following uses an application example to illustrate the interface permission management method of the embodiments of the present application. The embodiments of the present application provide an API permission control method and system. As Figure 2As shown, the API permission control system includes: a server, which includes a request receiving module, a data parsing module, a readable cache storage controller module, and a permission verification module. After the request receiving module receives the request, the data parsing module parses out the user identifier of the request, and at the same time, the data parsing module sends the parsed user identifier to the readable cache storage controller module. The readable cache storage controller module pulls the user permissions and then performs a permission query and comparison with the permission verification module, thereby returning whether the user has the operation permission of the API. Among them, the readable cache storage controller module includes ehcache and Redis, and ehcache and Redis communicate with the database through MQ. The API permission control system is connected to the client.
[0107] Before controlling API permissions, the embodiment of the present application first encapsulates access permissions, where permission data includes multiple levels of tenants, users, roles, interfaces, and operations. In the embodiment of the present application, the initial permission data can be obtained at one time, and the target permission data with a hierarchical structure can be obtained by organizing and classifying by tenants, users, roles, interfaces, and operations, and then the target permission data is cached by the client and the server at the same time.
[0108] like Figure 3 As shown, the API permission control method process is as follows:
[0109] Step 301: The service request receiving module receives the call request information of the API to be accessed.
[0110] Exemplarily, the call request information represents a user account requesting to access an API to be accessed.
[0111] Step 302: The data analysis module analyzes the authentication information corresponding to the call request information and sends it to the readable cache storage controller module.
[0112] Exemplarily, when the call request information is monitored, the data analysis module analyzes the authentication information corresponding to the call request information, obtains the user identifier and the API to be accessed by the user, and sends them to the readable cache storage controller module.
[0113] Step 303: The readable cache storage controller module obtains the API corresponding to the user identifier according to the user identifier parsed by the data parsing module.
[0114] Exemplarily, the readable cache storage controller module adopts an ehcache and Redis two-level cache storage structure, mainly caching the first mapping relationship between the user identifier and the API corresponding to the user identifier. Initially, when there is no user accessing the system, the first mapping relationship tables in ehcache and Redis of the readable cache storage controller module are empty; when the user accesses the system, the readable cache storage controller module looks up the first mapping relationship between the user identifier and the API corresponding to the user identifier according to the user identifier parsed by the data parsing module; if the user accesses for the first time, the first mapping relationship is empty and it is necessary to look up the first mapping relationship in the database; in the ehcache cache, the first mapping relationship between the user and the API is stored, and at the same time this relationship is synchronized to the Redis cache. If the user is not accessing for the first time, the first mapping relationship between the user and the corresponding API can be found in ehcache and Redis.
[0115] Exemplarily, the process of looking up in ehcache, Redis or the database can be: looking up the second mapping relationship between the user and the role through the user identifier, and then looking up the third mapping relationship between the role and the API through the role; then obtaining the first mapping relationship between the user identifier and the API corresponding to the user identifier according to the second mapping relationship and the third mapping relationship. The first mapping relationship here refers to the direct relationship between the user and the API, that is, whether the user has the permission to access the API. If there is a first mapping relationship between the user and the API, the user has the permission to access the API; if there is no first mapping relationship between the user and the API, the user does not have the permission to access the API.
[0116] In some embodiments, in the way of sharing ehcache and Redis, ehcache is used as the main cache, and caching and database updates are communicated between clusters through MQ, while Redis is used as the secondary cache. An expiration time T1 can be set in ehcache and an expiration time T2 can be set in Redis. Here, the time T1 is much smaller than T2. When T1 expires, if the access to ehcache misses, continue to access Redis according to the user identifier. When T2 expires, continue to access the database according to the user identifier. In other embodiments, when the ehcache main cache fails, the parsed user identifier can be sent to the Redis secondary cache to look up the first mapping relationship.
[0117] The database adopts a hierarchical structure of row level (tenant), user, role, API, and operation. Such as Figure 4As shown, the second preset relationship between different users and roles is preset in the database, and the second preset relationship is updated and maintained. Among them, one user can correspond to multiple roles at the same time; the second preset relationship can be understood as the mapping relationship between users and ordinary user roles, administrator user roles, and supplier→dealer→consumer (Business to Business to Consumer, B2B2C) user roles. The third preset relationship between different roles and APIs is also preset in the database, and the third preset relationship is updated and maintained. Among them, one role can correspond to multiple APIs at the same time; the third preset relationship can be understood that the mapping relationships between ordinary user roles and APIs, administrator user roles and APIs, and B2B2C user roles and APIs can all be understood as the mapping relationships between roles and APIs.
[0118] When the second mapping relationship and the third mapping relationship in the database change or are deleted, resulting in the change or deletion of the first mapping relationship, the database will asynchronously refresh the ehcache and Redis cache information through MQ. In this way, the information of the first mapping relationship, the second mapping relationship, and the third mapping relationship in the Redis cache is controlled to be the latest, and at the same time, other nodes are notified through MQ to update their own caches. Exemplarily, according to business needs, if the user-role relationship changes, the second mapping relationship will be updated or deleted; according to business needs, if the permissions of different roles and APIs change, adding or deleting the permissions of certain APIs, the third mapping relationship will be updated or deleted.
[0119] The embodiment of this application uses timestamps to ensure the consistency of cascaded caches. Since when designing caches, not all caches are retrieved from the database, some caches are retrieved from other caches, which can reduce the calculation time during use.
[0120] The dependency relationship between the database and the cache structure can be: database --> cache a --> cache b.
[0121] When cache a changes, if cache b is not reloaded from cache a, it will cause cache dirty data. Therefore, when refreshing cache a, cache b needs to be synchronously refreshed. However, from the above dependency relationship, b depends on a, and a does not depend on b, and cache b is invisible to a. So logically, it does not conform to the dependency rule.
[0122] Moreover, the above is only a secondary association. If it is a four - level or five - level association, the changes in the upper - layer cache will drive too many changes in the lower - layer caches, which will consume a lot of time. Therefore, in the embodiments of the present application, a cache delayed - refresh method is adopted. A timestamp can be added to cache a, and each time cache a changes, the timestamp is synchronously updated. When obtaining b, only need to check whether the timestamp of a has changed. If it has changed, reload cache b; otherwise, directly return b.
[0123] Step 304: Determine whether to allow the application account to call the API according to the API corresponding to the user identifier.
[0124] Exemplarily, if the corresponding first mapping relationship is successfully found according to the parsed user identifier, then judge whether the user has the permission to access the corresponding API according to the setting of the first mapping relationship. Specifically, compare all the APIs in the first mapping relationship with the API to be accessed by the current user parsed by the data parsing module. If the API to be accessed by the current user exists in the first mapping relationship, then the current user can access the API to be accessed.
[0125] It can be understood that after the user initiates an API access request and it is successfully parsed by the data parser, it is directly sent to the ehcache main cache to search for the first mapping relationship. If the corresponding first mapping relationship is successfully found according to the parsed user identifier, then judge whether the user has the permission to access the corresponding API according to the setting of the first mapping relationship.
[0126] Among them, the readable cache storage controller module is specifically implemented as follows:
[0127] Receive the user identifier parsed by the data parsing module. When the user request enters the cache, the open - source message middleware (Rabbit MQ) service node is used to provide an information persistence queue service to ensure data addition / deletion consistency; the database cache node is connected to the Rabbit MQ component and acts as the first producer; the Redis node is connected to the Rabbit MQ service node, acts as a consumer, creates its own unique Rabbit MQ message queue, and binds it to the routing rules of the group it belongs to: when there is a request to add / delete data to the database node, the database node finds the message queue group where the data is located and sends it to the routing rules bound by the corresponding group's Rabbit MQ. All Redis cache nodes in the corresponding group receive the Rabbit MQ message and perform related operations.
[0128] When an API access request arrives at the Redis cache node, the Redis cache node finds the queue group where the API access permission data is located and sends it to the corresponding database node within the group. The Redis cache nodes within the group receive the processing result of the API access permission search request.
[0129] Preferably, the Hyper Text Transfer Protocol (HTTP) request for accessing the external request API is inserted into the processing thread pool; the processing thread in the thread pool parses the HTTP request and its parameters; and waits for service requests from the Redis cache node, where the service requests include search, query, and update operations.
[0130] The Rabbit MQ consumption thread is started to wait for service requests from the database node, including operations such as adding API access permissions, updating API access permissions, and deleting API access permissions.
[0131] The persistence thread is started to wait for the persistence of API access permission data that needs to be persisted.
[0132] An embodiment of the present application provides an interface permission management device, as Figure 5 shown, the interface permission management device 500 includes: an acquisition module 501, a first determination module 502, a first search module 503, a judgment module 504, and a second determination module 505; wherein,
[0133] The acquisition module 501 is used to acquire the call request information of the user;
[0134] The first determination module 502 is used to determine the user information of the user and the interface to be accessed based on the call request information;
[0135] The first search module 503 is used to, if the call request information of the user is received for the non-first time, search in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information; the first mapping relationship represents the mapping relationship between the user information and the interface information;
[0136] The judgment module 504 is used to judge whether the interface to be accessed exists in the first mapping relationship;
[0137] The second determination module 505 is used to, if the interface to be accessed exists in the first mapping relationship, determine the access permission of the user to the interface to be accessed.
[0138] In some embodiments, the cache structure at least includes a first cache structure and a second cache structure; the interface permission management device 500 further includes: a second search module and a storage module; wherein,
[0139] The second search module is used to, if the call request information of the user is acquired for the first time, search for the first mapping relationship in the preset permission information of the preset database based on the user information; the preset permission information includes preset user information, preset interface information, and a first preset relationship between the preset user information and the preset interface information; the first preset relationship includes the first mapping relationship;
[0140] A storage module for storing the first mapping relationship into the first cache structure and the second cache structure.
[0141] In some embodiments, the cache structure at least includes a first cache structure and a second cache structure; a first lookup module 503 for looking up the first mapping relationship in the first cache structure based on user information; if the first mapping relationship does not exist in the first cache structure, looking up the first mapping relationship in the second cache structure based on user information.
[0142] In some embodiments, the preset permission information further includes: preset role information, a second preset relationship, and a third preset relationship. The second preset relationship represents the corresponding relationship between the preset user information and the preset role information, and the third preset relationship represents the corresponding relationship between the preset role information and the preset interface information; the first lookup module 503 is configured to look up in the second preset relationship according to the user information to obtain a second mapping relationship corresponding to the user information; the second mapping relationship represents the mapping relationship between the user information and the role information; look up in the third preset relationship according to the user information to obtain a third mapping relationship corresponding to the user information; the third mapping relationship represents the mapping relationship between the role information and the interface information; based on the second mapping relationship and the third mapping relationship, determine the first mapping relationship.
[0143] In some embodiments, the interface permission management device 500 further includes: a first monitoring module and a first loading module; wherein,
[0144] The first monitoring module is configured to monitor the first mapping relationship in the preset database to obtain change data;
[0145] The first loading module is configured to load the changed first mapping relationship in the preset database into the first cache structure based on the change data.
[0146] In some embodiments, the first cache structure includes at least one node; the interface permission management device 500 further includes: a second monitoring module and a second loading module; wherein,
[0147] The second monitoring module is configured to monitor the message queue corresponding to the preset database according to at least one node to obtain change data;
[0148] The second loading module is configured to, if a first node among at least one node monitors change data, update the first mapping relationship of the first node based on the change data.
[0149] In some embodiments, the interface permission management device 500 further includes: an update module and a third loading module; wherein,
[0150] An update module, configured to update the timestamp of the first cache structure if the first mapping relationship in the first cache structure changes;
[0151] A third loading module, configured to load the first mapping relationship in the first cache structure into the second cache structure according to the timestamp.
[0152] It should be noted that when the interface permission management device provided in the above embodiment performs control, only the division of the above program modules is used for illustration. In actual applications, the above processing can be allocated to different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-described processing. In addition, the interface permission management device provided in the above embodiment and the foregoing method embodiment of interface permission management belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be elaborated here.
[0153] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of the present application, the embodiments of the present application further provide an interface permission management device. Figure 6 Only the exemplary structure of the interface permission management device is shown, rather than all structures, and can be implemented according to needs Figure 6 The partial structure or all structures shown.
[0154] Such as Figure 6 As shown, the interface permission management device 600 provided in the embodiments of the present application includes: at least one processor 601, a memory 602, and a user interface 603. Each component in the interface permission management device 600 is coupled together through a bus system 604. It can be understood that the bus system 604 is used to realize the connection and communication between these components. The bus system 604 includes, in addition to the data bus, a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in Figure 6 All kinds of buses are labeled as the bus system 604.
[0155] Among them, the user interface 603 may include a display, a keyboard, a mouse, a trackball, a click wheel, a button, a button, a touchpad, or a touch screen, etc.
[0156] The memory 602 in the embodiments of the present application is used to store various types of data to support the operation of the control device. Examples of these data include: any computer program for operating on the control device.
[0157] The interface permission management method disclosed in the embodiments of the present application can be applied to the processor 601 or implemented by the processor 601. The processor 601 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the interface permission management method can be completed by the integrated logic circuit in the hardware of the processor 601 or the instructions in the form of software. The above-mentioned processor 601 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 601 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. Combining the steps of the method disclosed in the embodiments of the present application, it can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in the storage medium, and this storage medium is located in the memory 602. The processor 601 reads the information in the memory 602 and combines its hardware to complete the steps of the interface permission management method provided in the embodiments of the present application.
[0158] In an exemplary embodiment, the interface permission management device can be implemented by one or more application-specific integrated circuits (ASICs, Application Specific Integrated Circuits), DSPs, programmable logic devices (PLDs, Programmable Logic Devices), complex programmable logic devices (CPLDs, Complex Programmable Logic Devices), field programmable gate arrays (FPGAs, Field Programmable Gate Arrays), general-purpose processors, controllers, microcontroller units (MCUs, Micro Controller Units), microprocessors (Microprocessors), or other electronic components, and is used to execute the foregoing method.
[0159] It can be understood that the memory 602 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory), an electrically erasable programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), a ferromagnetic random access memory (FRAM, ferromagnetic random access memory), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM, Compact Disc Read-Only Memory); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM, Random Access Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as a static random access memory (SRAM, Static Random Access Memory), a synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory), a dynamic random access memory (DRAM, Dynamic Random Access Memory), a synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), a double data rate synchronous dynamic random access memory (DDR SDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), an enhanced synchronous dynamic random access memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), a sync link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and a direct rambus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present application are intended to include, but not limited to, these and any other suitable types of memories.
[0160] In an exemplary embodiment, the embodiments of the present application further provide a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a memory 602 storing a computer program, and the above computer program can be executed by a processor 601 of the interface privilege management device to complete the steps described in the method of the embodiments of the present application. The computer-readable storage medium can be a memory such as ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
[0161] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.
[0162] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.
[0163] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. An interface permission management method, characterized in that, Including: Obtain the call request information of the user; Determine the user information of the user and the interface to be accessed based on the call request information; If the call request information of the user is received for the non-first time, search in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information; The first mapping relationship represents the mapping relationship between the user information and the interface information; Determine whether the interface to be accessed exists in the first mapping relationship; If the interface to be accessed exists in the first mapping relationship, determine the access permission of the user to the interface to be accessed.
2. The method according to claim 1, wherein The cache structure at least includes a first cache structure and a second cache structure; before searching in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information, the method further includes: If the call request information of the user is obtained for the first time, search for the first mapping relationship in the preset permission information of the preset database based on the user information; the preset permission information includes preset user information, preset interface information, and a first preset relationship between the preset user information and the preset interface information; the first preset relationship includes the first mapping relationship; Store the first mapping relationship in the first cache structure and the second cache structure.
3. The method according to claim 1, wherein The cache structure at least includes a first cache structure and a second cache structure; searching in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information includes: Search for the first mapping relationship in the first cache structure based on the user information; If the first mapping relationship does not exist in the first cache structure, search for the first mapping relationship in the second cache structure based on the user information.
4. The method according to claim 2, wherein The preset permission information further includes: preset role information, a second preset relationship, and a third preset relationship. The second preset relationship represents the corresponding relationship between the preset user information and the preset role information, and the third preset relationship represents the corresponding relationship between the preset role information and the preset interface information; searching for the first mapping relationship in the preset permission information of the preset database based on the user information includes: Search in the second preset relationship according to the user information to obtain a second mapping relationship corresponding to the user information; the second mapping relationship represents the mapping relationship between the user information and the role information; Search in the third preset relationship according to the user information to obtain a third mapping relationship corresponding to the user information; the third mapping relationship represents the mapping relationship between the role information and the interface information; Determine the first mapping relationship based on the second mapping relationship and the third mapping relationship.
5. The method according to claim 2, wherein The method further includes: Monitor the first mapping relationship in the preset database to obtain change data; Load the changed first mapping relationship in the preset database into the first cache structure based on the change data.
6. The method according to claim 5, characterized in that, The first cache structure includes at least one node; the method further includes: Monitor the message queue corresponding to the preset database according to the at least one node to obtain the changed data; If the first node among the at least one node monitors the changed data, update the first mapping relationship of the first node based on the changed data.
7. The method according to claim 2, characterized in that The method further includes: If the first mapping relationship in the first cache structure changes, update the timestamp of the first cache structure; Load the first mapping relationship in the first cache structure into the second cache structure according to the timestamp.
8. An interface permission management device, characterized in that, It includes: An acquisition module for acquiring the call request information of the user; A first determination module for determining the user information of the user and the interface to be accessed based on the call request information; A first search module for, if the call request information of the user is received not for the first time, searching in the cache structure according to the user information to obtain the first mapping relationship corresponding to the user information; The first mapping relationship represents the mapping relationship between the user information and the interface information; A judgment module for judging whether the interface to be accessed exists in the first mapping relationship; A second determination module for, if the interface to be accessed exists in the first mapping relationship, determining the access right of the user to the interface to be accessed.
9. An interface permission management device, characterized in that, It includes: A processor and a memory for storing a computer program capable of running on the processor, wherein, The processor, when running the computer program, executes the steps of the method according to any one of claims 1 to 7.
10. A storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.