User authority management method and device and computer program product
By identifying account identity and operating level to set user permissions, and combining business roles and functional permissions, the problem of unsystematic user data permission management in group enterprises is solved, and refined and systematic permission management is achieved.
Patent Information
- Application Number
- CN202510702415.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-10-17
AI Technical Summary
Existing technologies make it difficult to systematically manage user data permissions, especially in group enterprises, where user levels are strongly correlated with data permissions, resulting in insufficient refinement and systematization of permission management.
By identifying the account identity, determining the user-side administrator account based on the platform-side administrator account, setting the account level of the ordinary user account according to the operation level, and accessing the service system through the user-side administrator account, setting data permissions, and combining business roles and functional permissions, systematic management of data permissions is achieved.
It implements systematic management of user data permissions, facilitates association based on user operational levels, improves the accuracy and efficiency of permission management, and meets the differentiated access needs of different business roles within the same data scope.
Smart Images

Figure CN120805152A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a user permission management method, device and computer program product. BACKGROUND
[0002] In modern enterprises, especially group enterprises, customer management, project management and transaction management operations are generally performed on the user side of the service system, and these operations involve access management of business data. It can be understood that different data permissions need to be set for users of different account levels, and currently the data permissions are generally divided directly according to the data to be used by the user, which is strongly related to the specific user demand, and it is difficult to systematically manage the data permissions of the user. SUMMARY
[0003] In view of the problems in the prior art, the present application provides a user permission management method, device and computer program product.
[0004] The present application provides a user permission management method applied to the user side of a service system, wherein the service system can identify an account identity and assign permissions to the account according to the account identity; the method comprises: determining a user side administrator account based on a permission assignment operation of a platform side administrator account in the service system; determining an account level of a corresponding ordinary user account according to an operation level of the user; accessing the service system through the user side administrator account; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine the full amount of business data corresponding to the ordinary user account under different account levels.
[0005] According to the user permission management method provided by the present application, the account level comprises a group level, a regional level, a company level, a department level and a project level; After setting the data permissions of the ordinary user account in the service system according to the account level, the method further comprises: determining a business role of the ordinary user account under the account level; setting function permissions of the ordinary user account in the service system according to the business role; the function permissions allow the ordinary user account to access and manage data within the range of the data permissions.
[0006] According to the user permission management method provided by the present application, determining the business role of the ordinary user account under the account level specifically comprises: determine a business role of the common user account at the account level from a service role option preset by the service system based on a task responsible for processing by the common user account at the account level; set a function permission of the common user account at the service system according to the business role, specifically including: determine a business role function permission preset by the service system according to the business role, and set the function permission of the common user account based on the business role function permission.
[0007] According to the user permission management method provided by the application, the business role of the common user account at the account level is determined, specifically including: Customize the business role of the common user account at the account level based on the task responsible for processing by the common user account at the account level; set a function permission of the common user account at the service system according to the business role, specifically including: determine the business module corresponding to the common user account at the service system according to the business field of the business role; determine the function module corresponding to the common user account from the business module according to the business permission of the business role; determine the permission point corresponding to the common user account from the function module according to the operation permission of the business role; set the function permission of the common user account according to the permission point.
[0008] According to the user permission management method provided by the application, the data permission of the common user account at the service system is set according to the account level, specifically including: In the case that the business role of the common user account includes at least two, obtain the data permission and function permission of each business role; In the case that the function permissions of the at least two business roles of the common user account exist overlap, obtain at least two data permissions corresponding to the overlapping function permissions; determine the data range corresponding to each of the at least two data permissions, and set the data permission of the common user account by obtaining the largest data range.
[0009] According to the user permission management method provided by the application, before setting the function permission of the common user account according to the permission point, the method further includes: obtain the corresponding business module code based on each business module; obtain the corresponding function module of each business module, and obtain the corresponding function module code based on the function module; obtain a permission point corresponding to each function module, and obtain a permission point name corresponding to the permission point based on the permission point; generate a permission point identifier of the permission point based on the business module code, the function module code, and the permission point name; set the function permission of the ordinary user account according to the permission point, and specifically includes: obtain the permission point identifier according to the permission point, and set the function permission of the ordinary user account based on the permission point identifier.
[0010] The application further provides a user permission management method applied to a platform side of a service system, wherein the service system is used for identifying an account identity and allocating a permission to the account according to the account identity; the method comprises: access the service system through a platform side administrator account; determine a user side target account, and determine the user side target account as a user side administrator account in an execution permission allocation operation of the service system; after determining an account level of a corresponding ordinary user account according to an operation level of a user, access the service system through the user side administrator account; set a data permission of the ordinary user account in the service system according to the account level; the data permission is used for determining full amount business data corresponding to the ordinary user account of the account level.
[0011] The application further provides a user permission management device applied to a user side of a service system, wherein the service system is capable of identifying an account identity and allocating a permission to the account according to the account identity; the device comprises: an administrator account determination module, used for determining a user side administrator account based on a permission allocation operation of a platform side administrator account in the service system; an ordinary user account determination module, used for determining an account level of a corresponding ordinary user account according to an operation level of a user; a user side system access module, used for accessing the service system through the user side administrator account; a data permission setting module, used for setting a data permission of the ordinary user account in the service system according to the account level; the data permission is used for determining full amount business data corresponding to the ordinary user account under different account levels.
[0012] The application further provides a user permission management device applied to a platform side of a service system, wherein the service system is used for identifying an account identity and allocating a permission to the account according to the account identity; the method comprises: a platform side system access module, used for accessing the service system through a platform side administrator account; The administrator account determining module is used for determining a user-side target account, and the execution right allocation operation in the service system determines the user-side target account as a user-side administrator account, so as to access the service system through the user-side administrator account after determining an account level of a corresponding common user account according to the operation level of the user; the data right of the common user account is set in the service system according to the account level; and the data right is used for determining the full-amount business data corresponding to the common user account of the account level.
[0013] The application further provides a computer program product comprising a computer program, which, when executed by a processor, implements the user right management method according to any one of the above.
[0014] The user right management method, device and computer program product provided by the application determine a user-side administrator account based on the right allocation operation of a platform-side administrator account in a service system; determine an account level of a corresponding common user account according to the operation level of the user; access the service system through the user-side administrator account; set the data right of the common user account in the service system according to the account level; and the data right can determine the full-amount business data corresponding to the common user account, and the data right of the common user account is associated with the operation level of the user, so that the data right of the user can be systematically managed. BRIEF DESCRIPTION OF DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort.
[0016] Figure 1 Fig. 1 is one of the flow diagrams of the user right management method provided by the application.
[0017] Figure 2 Fig. 2 is one of the framework diagrams of the user right management method provided by the application.
[0018] Figure 3 Fig. 3 is another of the framework diagrams of the user right management method provided by the application.
[0019] Figure 4 Fig. 4 is a third of the framework diagrams of the user right management method provided by the application.
[0020] Figure 5 Fig. 5 is a fourth of the framework diagrams of the user right management method provided by the application.
[0021] Figure 6Figure 5 is a schematic diagram of a fifth framework of the user permission management method provided by the present application.
[0022] Figure 7 Figure 2 is a schematic diagram of a second flow of the user permission management method provided by the present application.
[0023] Figure 8 Figure 1 is a schematic diagram of a first structure of the user permission management device provided by the present application.
[0024] Figure 9 Figure 2 is a schematic diagram of a second structure of the user permission management device provided by the present application.
[0025] Figure 10 Figure 3 is a schematic diagram of the electronic device provided by the present application. DETAILED DESCRIPTION
[0026] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below with reference to the drawings in the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without any creative work fall within the protection scope of the present application.
[0027] The user permission management method, device and computer program product of the present application will be described below. Figures 1-9
[0028] Figure 1 Figure 1 is a schematic diagram of a first flow of the user permission management method provided by the present application, which is applied to a user side of a service system. The service system can identify an account identity and assign a permission to the account according to the account identity. As shown in the figure, the method comprises the following steps. Figure 1 The service system can also be referred to as a service platform, which refers to a platform that centrally provides software services. For example, a user does not need to install a software service locally, but can use the required software service by accessing the service system through a network. Exemplarily, the service system can be a SaaS (Software as a Service) system.
[0029] Step 101: determining a user side administrator account based on a permission assignment operation of a platform side administrator account in the service system.
[0030] The service system provided by the embodiment can include a user side and a platform side. The user side can be multiple, for example, when the user side is an agent enterprise, each agent enterprise is a user side. The platform side can be responsible for managing the user side, such as opening the permission of the user side, data auditing, and operation management, etc. When the user side is an agent enterprise, the user side can be responsible for customer management, project management, transaction management, and other operations.
[0031] When the user logs in the service system through the account, the service system can identify the account identity, for example, the service system can identify the account identity as a platform side administrator account, and assign the permission of the platform side administrator account to the platform side administrator account.
[0032] The administrator account is a special account used to create, edit, and delete other accounts except the administrator account. For example, the platform side administrator account can create, edit, and delete the user side administrator account, and the user side administrator account can create, edit, and delete the user side ordinary user account. In the embodiment, the permission assignment operation refers to the creation, editing, and deletion of the user side administrator account by the platform side administrator account.
[0033] For example, the platform side administrator account can log in the service system, select the user side that needs to create an administrator account through the user management module in the service system, create a new administrator account, or select the user side that has set an administrator account, delete the administrator account, and create a new administrator account.
[0034] Step 102, determining the account level of the corresponding ordinary user account according to the operation level of the user.
[0035] The operation level refers to a specific operation level in the operation level system. The operation level system is a level system corresponding to the organizational structure and / or business process of the user side. According to the different user sides, the operation level of the user can be a real estate operation level, a property operation level, etc. The account level refers to a specific account level in the account level system. The account level system is a level system corresponding to the operation level system.
[0036] In the embodiment, by corresponding and mapping the account level of the ordinary user account and the operation level of the user, the permission setting of the ordinary user account can be matched with the business scope and responsibilities of the user.
[0037] Step 103, accessing the service system through the user side administrator account.
[0038] For example, the login interface of the service system can be accessed through the network, and the user side administrator account related information can be input in the login interface to access the service system.
[0039] In step 104, data permissions of the common user account are set in the service system according to the account level; the data permissions are used to determine the full amount of business data corresponding to the common user account under different account levels.
[0040] Exemplarily, the common user account can obtain data in the service system through the user side of the service system. The service system can pre-divide data in the service system into different data ranges according to an account level system, and the data ranges and the account levels can be one-to-one corresponding. On the user side, the common user account and the corresponding data range in the service system can be associated according to the account level of the common user account, and the data permissions of the common user account are set.
[0041] The user permission management method provided by the embodiment of the application determines the user side administrator account based on the permission allocation operation of the platform side administrator account in the service system, determines the account level of the corresponding common user account according to the operation level of the user, accesses the service system through the user side administrator account, sets the data permissions of the common user account in the service system according to the account level, and the data permissions can determine the full amount of business data corresponding to the common user account. By associating the data permissions of the common user account with the operation level of the user, the data permissions of the user can be systematically managed.
[0042] Based on the above embodiment, the account level includes a group level, a region level, a company level, a department level and a project level, and directly corresponds to the operation level of the user.
[0043] Exemplarily, the account level from high to low can be the group level, the region level, the company level, the department level and the project level in sequence, and the data range corresponding to the data permissions of the account level is positively correlated with the high and low of the account level. For example, the data range corresponding to the data permissions of the group level account level is greater than the data range corresponding to the data permissions of the region level account level.
[0044] In an embodiment, the data range corresponding to the data permissions of the high-level account level includes the data range corresponding to the data permissions of the low-level account level. For example, the data range corresponding to the data permissions of the group level account level includes the data range corresponding to the data permissions of the region level account level. In this way, the common user account of the high-level account level can access the service system and can see the data that the common user account of the low-level account level can see when accessing the service system. The common user account of the low-level account level cannot see the data that the common user account of the high-level account level can see when accessing the service system.
[0045] It can be understood that the account level can also be limited in other ways, such as 1st level, 2nd level, 3rd level, 4th level and 5th level, and the specific naming of the account level is not limited further in the embodiment.
[0046] After setting the data permission of the common user account in the service system according to the account level, the method further comprises: determining the business role of the common user account under the account level; setting the function permission of the common user account in the service system according to the business role; the function permission allows the common user account to access and manage the data within the data permission range.
[0047] The business role can also be referred to as role code, post code, etc., which refers to the role abstracted according to the business responsible by the actual user. For example, the business role under the project-level account level can include real estate consultant, project internal work, and project leader, etc., and the business role under the company-level account level can include operation management, general manager, and marketing director, etc.
[0048] As mentioned above, the service system can pre-divide data into multiple different data ranges, and the data within the data permission range refers to the data range corresponding to the common user account determined according to the account level of the common user account.
[0049] Exemplarily, after determining that the account level of the common user account is the project level, it is determined that the business role of the common user account is the project internal work, and the function permission of the common user account in the service system is set according to the project internal work, including entering transaction sheet, sales change, etc.; after determining that the account level of the common user account is the project level, it is determined that the business role of the common user account is the real estate consultant, and the function permission of the common user account in the service system is set according to the real estate consultant, including recording customers and checking customers, etc. Wherein, entering transaction sheet, sales change, recording customers and checking customers, etc. respectively correspond to different data within the data range corresponding to the project-level common user account.
[0050] In this embodiment, on the basis of setting the data range corresponding to the common user account according to the account level, the function permission of the common user account is further set according to the business role, and there is a differentiated effect between the data accessed and managed by different business roles under the same account level in the same data range through the function permission, which can facilitate the systematic and fine management of the permission of the common user account.
[0051] In an embodiment, the business roles under different account levels are different, exemplarily, the business roles under the project-level account level include real estate consultant, project internal work, and project leader, and the business roles under the company-level account level include operation management, general manager, and marketing director, and the business roles under the project-level account level are different from the business roles under the company-level account level, so that the data access permission and function operation permission of the corresponding common user account can be specifically determined through the business role.
[0052] Based on any of the above embodiments, the business role of the common user account at the account level is determined, specifically including: Based on the task handled by the common user account at the account level, the business role of the common user account at the account level is determined from the service system preset business role options.
[0053] As shown in Figure 2 The group-level account level can include group administrators, business directors, and group sales managers, the regional-level account level can include regional managers, regional directors, and regional sales managers, the company-level account level can include operation managers, market directors, sales managers, and city directors, the department-level account level can include directors, deputy directors, and general managers, and the project-level account level can include project managers, project clerks, project anchors, and real estate consultants.
[0054] Exemplarily, the task handled by the common user account at the account level can be determined based on the input of the user-side administrator user.
[0055] Exemplarily, each business role in the service system preset business role options can be pre-associated with a corresponding task list, and the task handled by the common user account can be matched with the task list to determine the business role of the common user account.
[0056] In this embodiment, the business role of the common user account is determined by the task handled by the common user account at the account level, which can increase the matching degree between the common user account and its specific user, and increase the pertinence and practicality of user permission management.
[0057] In an embodiment, the function permission of the common user account is set in the service system according to the business role, specifically including: The function permission of the common user account is set based on the business role function permission determined according to the business role.
[0058] Exemplarily, the business role and the preset business role function permission can have a mapping relationship, so as to determine the business role function permission according to the business role.
[0059] In this embodiment, the business role of the common user account is determined by the task handled by the common user account at the account level in the service system preset business role options, and the business role function permission is determined after determining the business role of the common user account, so as to determine the function permission of the common user account, which can improve the efficiency of user permission management.
[0060] Based on any of the above embodiments, the business role of the common user account at the account level is determined, specifically comprising: Based on the task handled by the common user account at the account level, the business role of the common user account at the account level is customized.
[0061] Illustratively, the user-side administrator user can input a custom instruction to the user side of the service system based on the task handled by the common user account at the account level, and the user side of the service system can receive the custom instruction input by the user-side administrator user to determine the business role of the common user account at the account level.
[0062] In this embodiment, the way of customizing the business role improves the flexibility and configurability of the function permission setting of the common user account, and improves the accuracy of user permission management.
[0063] Illustratively, the customization of the business role of the common user account can be performed when the matching degree between the task list of the preset business role of the task handled by the common user account is not high, so as to improve the efficiency of user permission management while taking into account the accuracy of user permission management.
[0064] As shown in the figure, Figure 3 The function permission design of the service system includes a business module, a function module under the business module, and a permission point under the function module, wherein the business module can be identified by modelType, the function module can be identified by functionType, and the permission point can also be referred to as a permission point list, which can be identified by permissions.
[0065] In an embodiment, the function permission of the common user account is set in the service system according to the business role, specifically comprising: According to the business field of the business role, the business module corresponding to the common user account is determined in the service system; according to the business permission of the business role, the function module corresponding to the common user account is determined from the business module; according to the operation permission of the business role, the permission point corresponding to the common user account is determined from the function module; and according to the permission point, the function permission of the common user account is set.
[0066] In this embodiment, the business module is selected and determined based on the business domain association between the tasks that the business role is responsible for and the business module, which can ensure the coverage and pertinence of the functional permissions; based on the specific business permissions involved in the tasks that the business role is responsible for, the functional module is further selected and determined in the corresponding business module, which can ensure that the functional permissions meet differentiated business needs; based on the specific operation permissions involved in the tasks that the business role is responsible for, the permission points are further selected and determined in the corresponding functional module, which can ultimately determine the functional permissions of the business role through hierarchical settings, and can better meet differentiated business needs while finely managing user permissions.
[0067] For example, when setting the functional permissions of a common user account, the user side of the service system may choose to set the functional permissions of the common user account according to a system preset method or according to a custom method according to an instruction input by a user side administrator. like Figure 3 As shown, based on any of the above embodiments, before setting the functional permissions of the common user account according to the permission point, the method further includes: Based on each of the business modules, a corresponding business module code is obtained; based on the function module, a corresponding function module code is obtained; based on the function module, a permission point is obtained for each of the function modules, and a corresponding permission point name is obtained based on the permission point; based on the business module code, the function module code, and the permission point name, a permission point identifier is generated for the permission point; and based on the permission point, functional permissions of the ordinary user account are set, specifically including: based on the permission point, obtaining the permission point identifier, and setting functional permissions of the ordinary user account based on the permission point identifier.
[0068] The business module code refers to the business module identifier, which can be an alphabetic or numerical identifier. For example, each business module can be coded sequentially. For example, if the business modules include transactions, customers, projects, and margin, the transaction business module code is 2, the customer business module code is 3, the project business module code is 4, the margin business module code is 5, and so on.
[0069] The function module code refers to the function module identifier, which can be an alphabetic identifier or a numerical identifier. For example, each function module can be coded sequentially. For example, the function modules under the transaction may include property query, transaction ledger, and property payment management. The function module code for property query is 1, the function module code for transaction ledger is 2, and the function module code for property payment management is 3, etc.
[0070] Exemplarily, the permission points under the house source query can include query, report generation and batch import, the query name is list, the report generation name is dataReport, and the batch import name is import.
[0071] Finally, the permission point identification of the query is 2-1-list, the permission point identification of the report generation is 2-1-dataReport, and the permission point identification of the batch import is 2_1_import. Also, the permission point identification of the query is 2_1_list, the permission point identification of the report generation is 2_1_dataReport, and the permission point identification of the batch import is 2_1_import.
[0072] Exemplarily, the permission point identification can be stored centrally, and can be marked by modelType-functionType-permissions, or by modelType_functionType_permissions, etc.
[0073] In the embodiment, on the basis of setting the ordinary user account permissions based on the business role, the permission points are identified by the business module part, the function module part and the permission point part, wherein the business module part, the function module part and the permission point part constituting the permission point identification have respective unique identification marks (codes or names), so as to ensure that the permission point identification has uniqueness and traceability, and the business module part, the function module part and the permission point part constitute the permission point identification, which better expresses the hierarchical relationship of the permission points.
[0074] In the case that the business role of the ordinary user account is unique, according to the data permissions of the ordinary user account, the corresponding data range can be shown to the user when the function is executed by the ordinary user account, for example, in the case that the business role of the ordinary user account is only a real estate consultant, the account level of the ordinary user account is determined as a project level, and the data range of the project level can be shown when the customer function is executed by the ordinary user account according to the data permissions corresponding to the project level.
[0075] However, when an ordinary user account includes multiple business roles, simply determining the data permissions of the ordinary user account based on the account level of a certain business role will cause the business role of the ordinary user account to display data that is too large or too small when executing functional permissions, resulting in unreasonable permission allocation. For example, an ordinary user account includes a property consultant at the project-level account level and an operations manager at the company-level account level. The property consultant includes functional permissions such as customer registration and customer inventory, and the marketing director includes functional permissions such as market analysis and customer inventory. The data permissions of the ordinary user account are determined based on the project-level account level of the property consultant. When the marketing director executes the customer inventory function, the data range corresponding to the project-level data permissions is displayed, resulting in the inability to display the full amount of business data corresponding to the company-level operations level.
[0076] To solve the above technical problem, based on any of the above embodiments, setting the data permissions of the common user account in the service system according to the account level specifically includes: If it is determined that the common user account includes at least two business roles, obtaining data permissions and function permissions of each business role; When determining that functional permissions of at least two business roles of the common user account overlap, obtaining at least two data permissions corresponding to the overlapping functional permissions; Determine the data ranges corresponding to the at least two data permissions respectively, obtain the largest data range, and set the data permission for the common user account.
[0077] For example, based on the aforementioned functional permissions of the marketing director and the property consultant, it can be determined that there is overlap in the functional permissions of the two, and the first data range corresponding to the property consultant's function can be obtained, and the second data range corresponding to the property consultant's function can be obtained. When the first data range is larger than the second data range, the data permissions of the ordinary user account are determined according to the first data range, so that the property consultant's functions both correspond to the first data range.
[0078] like Figure 4 As shown, in this embodiment, the permission point identifier for the "panke" function is 5-1-list, among which 6-1-list is the other permission point identifier for the marketing director, and 7-1-list is the other permission point identifier for the property consultant. It can be ultimately determined that the data permission for the ordinary user account function permission 5-1-list is company-level.
[0079] The functional permissions of the marketing director and the property consultant do not overlap, and their respective data permissions are still determined according to the account level of the business role. For example, the data scope corresponding to the market analysis function of the marketing director is the company-level data scope, and the data scope corresponding to the customer registration function of the property consultant is the project-level data scope.
[0080] As Figure 5 shown, in this embodiment, 5-1-list can be the permission point identification of the recording customer function of the real estate consultant, and the permission point identification of the market director does not include 5-1-list, so the data permission of the function permission 5-1-list of the ordinary user account can be finally determined as project level.
[0081] In this embodiment, by adjusting the business role of the account with lower level in the overlapping function permission between at least two business roles when the business role of the ordinary user account includes at least two, the matching degree between the data range displayed and the actual business range of the user can be increased.
[0082] As Figure 6 shown, in order to specifically illustrate the function of the user permission management method provided by the present embodiment, a specific example is provided below.
[0083] A user permission management method applied to the user side of a service system, wherein the service system can identify an account identity and assign permissions to the account according to the account identity; the method comprises: determining a user side administrator account based on the permission assignment operation of the platform side administrator account in the service system; determining the account level of the corresponding ordinary user account according to the user's operation level; the account level includes group level, regional level, company level, department level and project level; accessing the service system through the user side administrator account; setting the data permission of the ordinary user account in the service system according to the account level; specifically, determining the business role of the ordinary user account includes at least two cases, obtaining the data permission and function permission of each business role; determining the overlapping function permission of at least two business roles of the ordinary user account, obtaining at least two data permissions corresponding to the overlapping function permission; determining the data range corresponding to each of the at least two data permissions, obtaining the largest data range to set the data permission of the ordinary user account; the data permission is used to determine the full amount of business data corresponding to the ordinary user account under different account levels; Customize a business role of the common user account at the account level based on a task that the common user account is responsible for handling at the account level; determine a business module corresponding to the common user account in the service system according to a business field of the business role; determine a function module corresponding to the common user account from the business module according to a business permission of the business role; determine a permission point corresponding to the common user account from the function module according to an operation permission of the business role; set a function permission of the common user account according to the permission point; and the function permission allows the common user account to access and manage data in the data permission range.
[0084] Figure 7 is a flowchart of a user permission management method provided by the application, applied to a platform side of a service system, the service system being configured to identify an account identity and assign a permission to the account according to the account identity; as shown in Figure 7 , the method comprises: Step 701, accessing the service system through a platform side administrator account; Step 702, determining a user side target account, determining the user side target account as a user side administrator account in a permission assignment operation in the service system, accessing the service system through the user side administrator account after determining an account level of a corresponding common user account according to an operation level of a user, setting a data permission of the common user account in the service system according to the account level; the data permission is used to determine full amount business data corresponding to the common user account at the account level.
[0085] The user permission management method provided by the application, the permission assignment operation of the platform side administrator account in the service system determines the user side administrator account; the user side administrator account can be used to access the service system after determining the account level of the corresponding common user account according to the operation level of the user, set the data permission of the common user account in the service system according to the account level; the data permission can determine the full amount business data corresponding to the common user account, and the data permission of the common user account is associated with the operation level of the user, so as to facilitate systematic management of the data permission of the user.
[0086] The user permission management device provided by the application is described below, and the user permission management device described below can be correspondingly referred to the user permission management method described above.
[0087] Figure 8 is a structural schematic diagram of a user permission management device provided by the application, applied to a user side of a service system, the service system being configured to identify an account identity and assign a permission to the account according to the account identity; as shown inFigure 8 The device comprises: The administrator account determination module 801 is configured to determine a user-side administrator account based on a permission allocation operation of a platform-side administrator account in the service system. The ordinary user account determination module 802 is configured to determine an account level of a corresponding ordinary user account according to an operation level of a user. The user-side system access module 803 is configured to access the service system through the user-side administrator account. The data permission setting module 804 is configured to set data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine full-volume business data corresponding to the ordinary user account under different account levels.
[0088] According to any one of the above embodiments, the account level comprises a group level, a region level, a company level, a department level, and a project level. The user permission management device further comprises a function permission setting module, and the function permission setting module comprises: The business role determination unit is configured to determine a business role of the ordinary user account under the account level. The function permission setting unit is configured to set function permissions of the ordinary user account in the service system according to the business role; the function permissions allow the ordinary user account to perform access management on data within the data permission range.
[0089] According to any one of the above embodiments, the business role determination unit is specifically configured to determine the business role of the ordinary user account under the account level from preset business role options of the service system based on a task to be processed by the ordinary user account under the account level. The function permission setting unit is specifically configured to determine the function permissions of the ordinary user account based on function permissions of the business role of the service system.
[0090] According to any one of the above embodiments, the business role determination unit is specifically configured to customize the business role of the ordinary user account under the account level based on a task to be processed by the ordinary user account under the account level. The function permission setting unit is specifically configured to determine a business module corresponding to the ordinary user account in the service system according to a business field of the business role; to determine a function module corresponding to the ordinary user account from the business module according to a business permission of the business role; to determine a permission point corresponding to the ordinary user account from the function module according to an operation permission of the business role; and to set the function permissions of the ordinary user account according to the permission point.
[0091] According to any one of the above embodiments, the data authority setting module 804 is specifically configured to: In a case where the business roles of the ordinary user account include at least two, acquire data authorities and function authorities of each business role; In a case where the function authorities of at least two business roles of the ordinary user account overlap, acquire at least two data authorities corresponding to the overlapping function authorities; Determine data ranges corresponding to the at least two data authorities respectively, and set the data range with the largest size as the data authority of the ordinary user account.
[0092] According to any one of the above embodiments, the user authority management device further includes an authority point identifier generation module configured to: Acquire a corresponding business module code based on each business module; Acquire a corresponding function module based on each business module, and acquire a corresponding function module code based on the function module; Acquire a corresponding authority point based on each function module, and acquire a corresponding authority point name based on the authority point; Generate an authority point identifier of the authority point based on the business module code, the function module code, and the authority point name; The function authority setting module is specifically configured to acquire the authority point identifier based on the authority point, and set the function authority of the ordinary user account based on the authority point identifier.
[0093] Figure 9 is a structural diagram of a user authority management device provided by the application, applied to a platform side of a service system, the service system being configured to identify an account identity and allocate authorities to the account according to the account identity; as shown in the figure, Figure 9 The device includes: The platform side system access module 901 is configured to access the service system through a platform side administrator account; The administrator account determination module 902 is configured to determine a user side target account, and determine the user side target account as a user side administrator account in an execution authority allocation operation in the service system, so as to access the service system through the user side administrator account after determining an account level of a corresponding ordinary user account according to an operation level of a user; set data authorities of the ordinary user account in the service system according to the account level; the data authorities are used to determine full amount business data corresponding to the ordinary user account of the account level.
[0094] Figure 10 An example of a structural diagram of an electronic device is shown in the figure, Figure 10As shown, the electronic device can include a processor 1010, a communications interface 1020, a memory 1030, and a communications bus 1040, wherein the processor 1010, the communications interface 1020, and the memory 1030 complete mutual communication through the communications bus 1040. The processor 1010 can invoke a logical instruction in the memory 1030 to execute a user permission management method, which includes determining a user-side administrator account based on a permission allocation operation of a platform-side administrator account in the service system; determining an account level of a corresponding ordinary user account according to an operation level of a user; accessing the service system through the user-side administrator account; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine full-volume business data corresponding to the ordinary user account under different account levels; or accessing the service system through the platform-side administrator account; determining a user-side target account, and determining the user-side target account as a user-side administrator account in the service system to execute a permission allocation operation; after determining an account level of a corresponding ordinary user account according to an operation level of a user, accessing the service system through the user-side administrator account; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine full-volume business data corresponding to the ordinary user account under the account level.
[0095] In addition, the logical instruction in the memory 1030 described above can be implemented in the form of a software function unit and sold or used as an independent product, and can be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.
[0096] In another aspect, the present application also provides a computer program product comprising a computer program, which can be stored on a non-transitory computer readable storage medium, and the computer program is executable by a processor to cause a computer to perform the user permission management method provided by the above-mentioned methods, which comprises: determining a user-side administrator account based on a permission allocation operation of a platform-side administrator account in the service system; determining an account level of a corresponding ordinary user account according to an operation level of the user; accessing the service system through the user-side administrator account; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine the corresponding full amount of business data of the ordinary user account under different account levels; or accessing the service system through the platform-side administrator account; determining a user-side target account, and determining the user-side target account as a user-side administrator account in the service system by performing a permission allocation operation, so as to access the service system through the user-side administrator account after determining an account level of a corresponding ordinary user account according to an operation level of the user; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine the corresponding full amount of business data of the ordinary user account under the account level.
[0097] In another aspect, the present application also provides a non-transitory computer readable storage medium having a computer program stored thereon, and the computer program is executable by a processor to implement the user permission management method provided by the above-mentioned methods, which comprises: determining a user-side administrator account based on a permission allocation operation of a platform-side administrator account in the service system; determining an account level of a corresponding ordinary user account according to an operation level of the user; accessing the service system through the user-side administrator account; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine the corresponding full amount of business data of the ordinary user account under different account levels; or accessing the service system through the platform-side administrator account; determining a user-side target account, and determining the user-side target account as a user-side administrator account in the service system by performing a permission allocation operation, so as to access the service system through the user-side administrator account after determining an account level of a corresponding ordinary user account according to an operation level of the user; setting data permissions of the ordinary user account in the service system according to the account level; the data permissions are used to determine the corresponding full amount of business data of the ordinary user account under the account level.
[0098] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected to achieve the purposes of the embodiments according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0099] Through the description of the above embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software and the necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0100] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A user rights management method, characterized in that: Applied to the user side of a service system, the service system is capable of identifying an account identity and assigning permissions to the account based on the account identity; the method includes: Determine the user-side administrator account based on the permission allocation operation of the platform-side administrator account in the service system; Determine the account level of the corresponding ordinary user account based on the user's operation level; Accessing the service system through the user-side administrator account; The data permissions of the common user account are set in the service system according to the account level; the data permissions are used to determine the full amount of business data corresponding to the common user account at different account levels.
2. The user rights management method according to claim 1, characterized in that: The account levels include group level, regional level, company level, business unit level and project level; After the service system sets data permissions for the common user account according to the account level, the method further includes: Determine the business role of the common user account at the account level; Functional permissions of the common user account are set in the service system according to the business role; the functional permissions allow the common user account to access and manage data within the data permission range.
3. The user rights management method according to claim 2, characterized in that: Determining the business role of the common user account at the account level specifically includes: Determining a business role of the ordinary user account at the account level from business role options preset by the service system based on the tasks that the ordinary user account is responsible for processing at the account level; Setting the functional permissions of the ordinary user account in the service system according to the business role specifically includes: The business role functional authority preset by the service system is determined according to the business role, and the functional authority of the common user account is set based on the business role functional authority.
4. The user rights management method according to claim 2, characterized in that: Determining the business role of the common user account at the account level specifically includes: Customize the business role of the common user account at the account level based on the tasks that the common user account is responsible for handling at the account level; Setting the functional permissions of the ordinary user account in the service system according to the business role specifically includes: Determining a business module corresponding to the ordinary user account in the service system according to the business domain of the business role; Determine the function module corresponding to the ordinary user account from the business module according to the business authority of the business role; Determine the permission point corresponding to the ordinary user account from the function module according to the operation permission of the business role; The functional permissions of the common user account are set according to the permission points.
5. The user rights management method according to claim 2, characterized in that: Setting the data permissions of the ordinary user account in the service system according to the account level specifically includes: If it is determined that the common user account includes at least two business roles, obtaining data permissions and function permissions of each business role; When determining that functional permissions of at least two business roles of the common user account overlap, obtaining at least two data permissions corresponding to the overlapping functional permissions; Determine the data ranges corresponding to the at least two data permissions respectively, obtain the largest data range, and set the data permission for the common user account.
6. The user rights management method according to claim 4, characterized in that: Before setting the functional permissions of the common user account according to the permission point, the method further includes: Obtaining a corresponding business module code based on each of the business modules; Obtaining a function module corresponding to each of the business modules, and obtaining a corresponding function module code based on the function module; Obtaining the permission point corresponding to each of the functional modules, and obtaining the corresponding permission point name based on the permission point; Generate a permission point identifier for the permission point based on the business module code, the function module code, and the permission point name; The function permissions of the common user account are set according to the permission points, specifically including: The permission point identifier is obtained according to the permission point, and the functional permission of the common user account is set based on the permission point identifier.
7. A user rights management method, characterized in that: Applied to the platform side of a service system, the service system is used to identify an account identity and assign permissions to the account based on the account identity; the method includes: Access the service system through the platform administrator account; Determine a user-side target account, and determine that the user-side target account is a user-side administrator account by executing a permission allocation operation in the service system, so that after determining the account level of the corresponding ordinary user account according to the user's operating level, the service system can be accessed through the user-side administrator account; set data permissions for the ordinary user account in the service system according to the account level; the data permissions are used to determine the full amount of business data corresponding to the ordinary user account of the account level.
8. A user rights management device, characterized in that: Applied to the user side of a service system, the service system is capable of identifying an account identity and assigning permissions to the account based on the account identity; the device includes: An administrator account determination module, configured to determine a user-side administrator account based on a permission allocation operation of the platform-side administrator account in the service system; A common user account determination module is used to determine the account level of the corresponding common user account according to the user's operation level; A user-side system access module, configured to access the service system through the user-side administrator account; A data permission setting module is used to set the data permission of the ordinary user account in the service system according to the account level; the data permission is used to determine the full amount of business data corresponding to the ordinary user account under different account levels.
9. A user rights management device, characterized in that: Applied to the platform side of a service system, the service system is used to identify an account identity and assign permissions to the account based on the account identity; the method includes: A platform-side system access module, used to access the service system through a platform-side administrator account; An administrator account determination module is used to determine a user-side target account, and to determine that the user-side target account is a user-side administrator account by executing a permission allocation operation in the service system, so that after determining the account level of the corresponding ordinary user account according to the user's operating level, the service system can be accessed through the user-side administrator account; data permissions of the ordinary user account are set in the service system according to the account level; the data permissions are used to determine the full amount of business data corresponding to the ordinary user account of the account level.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the user rights management method according to any one of claims 1 to 7 is implemented.