Data authority control method and device and storage medium
By intercepting the initial SQL information and generating the target SQL statement, the problem of redundant SQL statements and lengthy deployment processes in traditional data access control is solved, and fast and flexible access control is achieved.
Patent Information
- Application Number
- CN202510917513.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-10-28
AI Technical Summary
Traditional data access control technologies suffer from redundant SQL statements, lengthy and inefficient deployment processes, and highly intrusive annotation-based access control, failing to meet the needs of rapid business iteration.
By intercepting the initial SQL information, and using preset configuration information and input parameter permission information, the target SQL statement is generated, avoiding manual code modification and achieving fast permission control.
It enables rapid data access control, avoids redundancy in SQL statements and code modifications, and improves the flexibility and scalability of access control.
Smart Images

Figure CN120850313A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer application technology, and more specifically, to a data access control method, device, and storage medium. Background Technology
[0002] As digital business continues to expand, system scale grows exponentially, leading to a surge in the number of SQL (Structured Query Language) statements. Ensuring data security necessitates building a robust data access control system, such as implementing row-level data access control policies to restrict data visibility to the data owner or members of their organization. Due to the complexity and variability of real-world business scenarios, users may hold multiple accounts and be associated with multiple organizations, making access control logic even more complex and diverse. However, current traditional data access control technologies have significant limitations:
[0003] 1. Significant SQL statement redundancy: Each business interface requires manual adjustment of SQL query statements when implementing data permission filtering, resulting in a large amount of repetitive permission control logic in the codebase, which greatly increases maintenance costs and potential error risks.
[0004] 2. Lengthy and inefficient deployment process: Once the access control rules change, developers must modify the code and redeploy the system. From code submission and testing to final deployment, the entire process is lengthy and time-consuming, failing to meet the needs of rapid business iteration.
[0005] 3. Intrusive drawbacks of annotation-based access control: Some systems use annotations to implement access control. Although this simplifies access configuration to some extent, the deep coupling between annotations and business code not only undermines the conciseness and readability of the code, but also requires re-modifying and redeploying the code when modifying the annotation content. This results in a serious lack of flexibility and scalability. Summary of the Invention
[0006] To address the problems, or at least some of the problems, existing technologies described above, embodiments of the present invention provide a data access control method, system, storage medium, device, and computer program product. This method obtains initial SQL information requiring access control through an interceptor, and then directly generates a target SQL statement with access control based on preset configuration information and input parameter access information. This eliminates the need for manual code modification, enabling rapid access control and avoiding complex SQL statements.
[0007] According to a first aspect of the present invention, an embodiment of the present invention provides a data access control method, the method comprising: obtaining initial SQL information through an interceptor, the initial SQL information including the full path name of an SQL method, an original SQL statement, and original input parameter information; when the command type of the original SQL statement is a select query type, determining whether the full path name of the SQL method of the original SQL statement exists in preset configuration information; when the full path name of the SQL method of the original SQL statement exists in the preset configuration information, obtaining input parameter permission information according to the original input parameter information; generating a target SQL statement according to the original SQL statement, the preset configuration information, and the input parameter permission information; and performing a data query operation according to the target SQL statement.
[0008] According to the above embodiments of the present invention, the initial information of the SQL that needs to be subject to access control is obtained by an interceptor, and then the target SQL statement with access control is directly generated according to the preset configuration information and input parameter access control information. There is no need to manually modify the code, which can not only quickly implement access control, but also avoid complicated SQL.
[0009] In some embodiments of the present invention, the configuration fields in the preset configuration information include: whether detection permissions are required, table alias, keyword, field in the data table storing first permission information, and field in the data table storing second permission information.
[0010] In some embodiments of the present invention, obtaining input parameter permission information based on the original input parameter information includes: extracting first permission information, second permission information, third permission information, fourth permission information and permission control type from the original input parameter information as the input parameter permission information.
[0011] In some embodiments of the present invention, the preset configuration information is obtained by the following method: reading the differentiated configuration information in the configuration file; generating the preset configuration information based on the general configuration information and the differentiated configuration information.
[0012] In some embodiments of the present invention, generating a target SQL statement based on the original SQL statement, preset configuration information, and input parameter permission information includes: generating an intermediate processing SQL statement based on the input parameter permission information and preset configuration information; generating a permission processing SQL statement based on the permission control type in the input parameter permission information and the intermediate processing SQL statement; and generating the target SQL statement based on the original SQL statement and the permission processing SQL statement.
[0013] In some embodiments of the present invention, the intermediate processing SQL statement includes: a first processing SQL statement, a second processing SQL statement, a third processing SQL statement, and a fourth processing SQL statement; wherein, the first processing SQL statement is generated based on the first permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the first permission information; the second processing SQL statement is generated based on the second permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the second permission information; the third processing SQL statement is generated based on the third permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the first permission information; and the fourth processing SQL statement is generated based on the fourth permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the second permission information.
[0014] In some embodiments of the present invention, the method further includes: monitoring the configuration file and publishing a change event when the configuration file changes.
[0015] According to the above embodiments of the present invention, by publishing a change event when the configuration file changes, the preset configuration information can be obtained in a timely manner based on the updated configuration file, and new permission control can be implemented on the original SQL statement.
[0016] According to a second aspect of the present invention, an embodiment of the present invention provides a data access control system, the data access control system comprising: an initial information acquisition module, configured to acquire SQL initial information through an interceptor, the SQL initial information including the full path name of an SQL method, the original SQL statement, and the original input parameter information; a target SQL statement generation module, configured to perform the following operations: when the command type of the original SQL statement is a select query type, determining whether the full path name of the SQL method of the original SQL statement exists in preset configuration information; when the full path name of the SQL method of the original SQL statement exists in the preset configuration information, acquiring input parameter permission information based on the original input parameter information; generating a target SQL statement based on the original SQL statement, the preset configuration information, and the input parameter permission information; and a data query module, configured to perform a data query operation based on the target SQL statement.
[0017] According to the above embodiments of the present invention, the initial information of the SQL that needs to be subject to access control is obtained by an interceptor, and then the target SQL statement with access control is directly generated according to the preset configuration information and input parameter access control information. There is no need to manually modify the code, which can not only quickly implement access control, but also avoid complicated SQL.
[0018] In some embodiments of the present invention, the configuration fields in the preset configuration information include: whether detection permissions are required, table alias, keyword, field in the data table storing first permission information, and field in the data table storing second permission information.
[0019] In some embodiments of the present invention, obtaining input parameter permission information based on the original input parameter information includes: extracting first permission information, second permission information, third permission information, fourth permission information and permission control type from the original input parameter information as the input parameter permission information.
[0020] In some embodiments of the present invention, the target SQL statement generation module obtains the preset configuration information by: reading the differentiated configuration information in the configuration file; and generating the preset configuration information based on the general configuration information and the differentiated configuration information.
[0021] In some embodiments of the present invention, generating a target SQL statement based on the original SQL statement, preset configuration information, and input parameter permission information includes: generating an intermediate processing SQL statement based on the input parameter permission information and preset configuration information; generating a permission processing SQL statement based on the permission control type in the input parameter permission information and the intermediate processing SQL statement; and generating the target SQL statement based on the original SQL statement and the permission processing SQL statement.
[0022] In some embodiments of the present invention, the intermediate processing SQL statement includes: a first processing SQL statement, a second processing SQL statement, a third processing SQL statement, and a fourth processing SQL statement; wherein, the first processing SQL statement is generated based on the first permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the first permission information; the second processing SQL statement is generated based on the second permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the second permission information; the third processing SQL statement is generated based on the third permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the first permission information; and the fourth processing SQL statement is generated based on the fourth permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the second permission information.
[0023] In some embodiments of the present invention, the data access control system further includes: a configuration file monitoring module, used to monitor the configuration file and publish a change event when the configuration file changes.
[0024] According to the above embodiments of the present invention, by publishing a change event when the configuration file changes, the preset configuration information can be obtained in a timely manner based on the updated configuration file, and new permission control can be implemented on the original SQL statement.
[0025] According to a third aspect of the present invention, an embodiment of the present invention provides a computer-readable storage medium having stored thereon computer-readable instructions, which, when executed by a processor, cause a computer to perform the following operations: the operations include the steps included in the data access control method described in any of the above embodiments.
[0026] According to a fourth aspect of the present invention, an embodiment of the present invention provides a computer device including a memory and a processor, wherein the memory is used to store one or more computer-readable instructions, wherein the one or more computer-readable instructions, when executed by the processor, can implement the data access control method as described in any of the above embodiments.
[0027] According to a fifth aspect of the present invention, an embodiment of the present invention provides a computer program product including a computer program, which, when executed by a processor, implements the data access control method as described in any of the above embodiments.
[0028] As can be seen from the above, the data access control method, system, storage medium, device and computer program product provided by the embodiments of the present invention obtain the initial information of the SQL that needs to be access controlled through an interceptor, and then directly generate the target SQL statement with access control according to the preset configuration information and input parameter access information. There is no need to manually modify the code, which can not only quickly realize access control, but also avoid complicated SQL. Attached Figure Description
[0029] Figure 1 This is a flowchart illustrating the data access control method according to Embodiment 1 of the present invention;
[0030] Figure 2 This is a flowchart illustrating the data access control method according to Embodiment 2 of the present invention;
[0031] Figure 3 This is a schematic diagram of the architecture of the data access control system according to Embodiment 3 of the present invention. Detailed Implementation
[0032] The various aspects of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. Well-known modules, units, and their connections, links, communications, or operations are not shown or described in detail. Furthermore, the described features, architectures, or functions can be combined in any way in one or more embodiments. Those skilled in the art should understand that the various embodiments described below are for illustrative purposes only and are not intended to limit the scope of protection of the present invention. It will also be readily understood that the modules, units, or processing methods in the embodiments described herein and shown in the accompanying drawings can be combined and designed in various different configurations.
[0033] The following is a brief explanation of the terminology used in this text.
[0034] StatementHandler: In the MyBatis framework, StatementHandler is the core processor for executing SQL statements.
[0035] JSON: JavaScript Object Notation, a lightweight data interchange format.
[0036]
Example 1
[0037] Figure 1 This is a flowchart illustrating the data access control method according to Embodiment 1 of the present invention.
[0038] like Figure 1 As shown, in Embodiment 1 of the present invention, the data access control method may include at least the following steps S11, S12, S13, S14 and S15, which are described in detail below.
[0039] In step S11, the initial SQL information is obtained through the interceptor. The initial SQL information includes the full path name of the SQL method, the original SQL statement, and the original input parameter information.
[0040] In this embodiment, the `@Intercepts` annotation is used to intercept the `StatementHandler`, and the SQL statement is processed within the `Interceptor`, performing operations such as SQL rewriting and parameter manipulation. Utilizing the MyBatis interceptor mechanism, the system dynamically intervenes before the `StatementHandler` executes the SQL, modifying the SQL and its parameters. Specifically, it dynamically enhances the original SQL based on initial information (by appending new query conditions, such as owner or organization), achieving non-intrusive data access control.
[0041] In step S12, when the command type of the original SQL statement is a select query, it is determined whether the full path name of the SQL method of the original SQL statement exists in the preset configuration information. The types of the original SQL statement include, but are not limited to, select (query), update (update), insert (insert), delete (delete), etc.
[0042] In some implementations, the preset configuration information is obtained by: reading differentiated configuration information from a configuration file; and generating the preset configuration information based on general configuration information and the differentiated configuration information. SQL access control is implemented based on this configuration, ensuring that the access control is non-intrusive and does not affect SQL.
[0043] In this framework, both the common configuration information (common block) and the differentiated configuration information (perSqlMap block) adhere to the principle of convention over configuration. The common block provides many default configurations, allowing developers to focus on the business logic (the full path of the SQL statement to be processed) without manually configuring numerous details. Configuring specific full paths of SQL statements for data access control within the differentiated configuration information (perSqlMap block) in the configuration file enables fine-grained access control at the method level.
[0044] In a further implementation, the configuration file is monitored, and whenever the configuration file changes, a change event is published, notifying the Spring environment that the configuration has changed; then, the bean object is refreshed to obtain the latest value. This allows for flexible and dynamic adjustment of configuration information to achieve different levels of access control.
[0045] In this embodiment, the configuration fields in the preset configuration information include, but are not limited to: whether permission detection is required, table alias, keyword, field in the data table storing the first permission information, and field in the data table storing the second permission information. Optionally, the field in the data table storing the first permission information is the field storing the "Organization" (ownerOrg), and the field in the data table storing the second permission information is the field storing the "Owner" (owner). It should be understood that the field storing the permission information in the data table can be changed according to different table structures; that is, the fields storing the first and second permission information in the configured table can be custom fields, thereby achieving different permission controls.
[0046] In one exemplary implementation, the fixed syntax in the MyBatis interceptor is used: MappedStatement mappedStatement = (MappedStatement)metaObject.getValue("delegate.mappedStatement") to obtain the full path of the SQL statement (i.e., the interceptor's mappedStatementId), and the corresponding differential configuration information is found based on the mappedStatementId.
[0047] For example, the full path of the SQL method in MyBatis (i.e., the mappedStatementId in the interceptor) is: com.hcfc.crm.legal.batch.dao.LamLgSysBatchMapper.selectByRecord. If this value corresponds to the key of the differential module (perSqlMap) in the configuration file, then its differential configuration is obtained through the configuration file: {"owner":"create_name"}; then the overall general configuration information is obtained: {"checkAccess":true,"owner":"owner","ownerOrg":"owner_org","replaceKey Word":"9=9","tableAliasName":""}; since the differential configuration has higher priority, the adjusted overall configuration information is: {"checkAccess":true,"owner":"create_name","ownerOrg":"owner_org","replaceKeyWord":"9=9","tableAliasName":""}.
[0048] The specific meanings of the adjusted overall configuration information (i.e., the preset configuration information) are as follows: a. "checkAccess": true - whether permission needs to be checked is yes; b. "owner": "create_name" - the field storing the owner in the table is "create_name"; c. "ownerOrg": "owner_org" - the field storing the organization in the table is "owner_org"; d. "replaceKeyWord": "9=9" - the keyword (replacement character) is "9=9"; e. "tableAliasName": "" - no table alias is used.
[0049] In step S13, when the full path name of the SQL method of the original SQL statement exists in the preset configuration information, the input parameter permission information is obtained according to the original input parameter information.
[0050] The input parameter fields of the original input parameter information include, but are not limited to, one or more of the following: owner (second permission information), owner set (fourth permission information), organization (first permission information), organization set (third permission information), and permission control type. In this embodiment, a pre-encapsulated class, PermissionReqParam, is provided, which can be directly inherited to use its internal fields; it also supports spreading fields across a single input parameter in the current configuration.
[0051] In some implementations, the field for the owner in the original input parameter information is "owner", which is of type String and corresponds to personal permissions. For example, if the creator of a piece of information is "zhangsan", then the owner is "zhangsan". The field for the owner set is "ownerList", which is of type List. <string>For a single user, there may be multiple login accounts. For example, in WeChat, a mobile phone number, email address, and WeChat ID all represent the same person. Therefore, matching any one of these is sufficient to obtain the data permission. The organization field is `ownerOrg`, which is of type String. The organization is the organization to which the user belongs. For example, if a user belongs to the Risk Department, then the organization is `risk`. The collection of organizations has a `ownerOrgList` field, which is of type List. <string>This is used for situations where an individual belongs to multiple organizations. The field for access control is `permissionType`, which is of type `Integer`. The meanings of the numbers in this type are as follows: 0 - No permission check; 1 - Data is retrieved according to the "owner" dimension; 2 - Data is retrieved according to both "owner" and "organization" dimensions; 3 - Data is retrieved according to both "owner" and "organization set" dimensions; 4 - Data is retrieved according to the "owner set" dimension; 5 - Data is retrieved according to both "owner set" and "organization" dimensions; 6 - Data is retrieved according to both "owner set" and "organization set" dimensions; 7 - Data is retrieved according to the "organization" dimension; 8 - Data is retrieved according to the "organization set" dimension.
[0052] In this embodiment, the preset configuration information includes SQL statements with permission configurations. For example, the configuration format of the preset configuration information is as follows:
[0053]
[0054]
[0055] This section of the differential configuration block (perSqlMap) only displays two specific SQL statements: `com.hcfc.crm.legal.batch.dao.LamLgSysBatchMapper.selectByRecord` and `com.hcfc.newlam.collcase.dao.CaseMapper.selectCaseIdByPage`. `com.hcfc.crm.legal.batch.dao.LamLgSysBatchMapper.selectByRecord` is the full path to the SQL method for this statement. Furthermore, when adding new SQL processing, simply append it to the differential configuration block (perSqlMap).
[0056] In the above example of the configuration format for preset configuration information, the configuration fields of the preset configuration information include:
[0057] (1) Whether permission needs to be checked: This is configured in checkAccess. When it is set to false (skip permission verification), the SQL processing step will be skipped and the original SQL will be used directly.
[0058] (2) Table Alias: Configured in tableAliasName. If not assigned a value, it defaults to an empty string; if the SQL uses an alias, then assign the alias used in the actual SQL. Table aliases are supported, especially for complex queries involving joins, where table aliases can be defined.
[0059] (3) Keyword (replacement symbol): Configured at replaceKeyWord. If no value is assigned, the permission processing SQL will be appended directly to the end of the original SQL. If the value 9=9 is assigned, "9=9" in the original SQL will be replaced with the permission processing SQL.
[0060] (4) The field in the table that stores the [organization] is the field in the data table that stores the first permission information: it is configured in ownerOrg, which corresponds to the field in the data table that stores the organization, such as owner_org; in general, the field that stores the organization in multiple tables in a system is the same, so it only needs to be configured in common.
[0061] (5) The field in the table that stores the owner, which is the field in the data table that stores the second permission information: it is configured in the owner field, corresponding to the field in the data table that stores the owner, such as owner or create_name; in general, the field that stores the owner in multiple tables in a system is the same, so it only needs to be configured in common.
[0062] In an exemplary implementation, obtaining input parameter permission information based on the original input parameter information specifically includes the following steps S131 and S132:
[0063] Step S131: Obtain the original input parameter information in JSON format, or convert the original input parameter information into JSON format. For example, the original input parameter information in JSON format is as follows:
[0064] {
[0065] "dataType":"M",
[0066] "dataDateStart":"2023-04-21",
[0067] "dataDateEnd":"2024-03-21",
[0068] "incomingCallReason":"cri_01",
[0069] "numberOfThreads":1,
[0070] "owner":"lugang",
[0071] "ownerList":["wenhai","lugang"],
[0072] "ownerOrg":"system",
[0073] "ownerOrgList":["company","entry"],
[0074] "permissionType":1
[0075] }
[0076] Step S132: Extract information such as owner, owner list, organization (ownerOrg), organization list (ownerOrgList), and permission control type (permissionType) from the original input parameter information, and convert them to obtain the input parameter permission information as follows:
[0077] {"owner":"lugang","ownerList":["wenhai","lugang"],"ownerOrg":"system","ownerOrgList":["company","entry"],"permissionType":1}
[0078] Therefore, the following input parameter permission information is obtained:
[0079] 1. "owner": "lugang" - The owner to be queried is "lugang";
[0080] 2. "ownerList":["wenhai","lugang"] - The set of owners to be queried is: ["wenhai","lugang"];
[0081] 3. "ownerOrg":"system" - The organization to be queried is "system";
[0082] 4. "ownerOrgList":["company","entry"] - The set of organizations to be queried is: "["company","entry"];
[0083] 5. "permissionType": 1 - Permission control type is 1 - Data is retrieved according to the [owner] dimension. That is, the final query will retrieve data in the database whose owner is "lugang".
[0084] In step S14, a target SQL statement is generated based on the original SQL statement, preset configuration information, and input parameter permission information.
[0085] In some implementations, generating a target SQL statement based on the original SQL statement, preset configuration information, and input parameter permission information includes: generating an intermediate processing SQL statement based on the input parameter permission information and preset configuration information; generating a permission processing SQL statement based on the permission control type in the input parameter permission information and the intermediate processing SQL statement; and generating the target SQL statement based on the original SQL statement and the permission processing SQL statement.
[0086] In a further embodiment, the intermediate processing SQL statements include: a first processing SQL statement, a second processing SQL statement, a third processing SQL statement, and a fourth processing SQL statement; wherein, the first processing SQL statement is generated based on the first permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the first permission information; the second processing SQL statement is generated based on the second permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the second permission information; the third processing SQL statement is generated based on the third permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the first permission information; and the fourth processing SQL statement is generated based on the fourth permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the second permission information.
[0087] Optionally, the first permission information is the organization, the second permission information is the owner, the third permission information is the set of organizations, and the fourth permission information is the set of owners; the first processing SQL statement is the processing SQL corresponding to the organization, the second processing SQL statement is the processing SQL corresponding to the owner, the third processing SQL statement is the processing SQL corresponding to the set of organizations, and the fourth processing SQL statement is the processing SQL corresponding to the set of owners. In an exemplary implementation, the intermediate processing SQL statement is obtained in the following way:
[0088] (1) Generate the processing SQL corresponding to the organization based on the organization information in the input parameters, the table alias in the configuration, and the field in the table that stores the organization. For example, if the organization information in the input parameters is "system" and the field in the configuration table that stores the organization is "owner_org", then the processing SQL corresponding to the organization obtained by assembling the parameters is: and owner_org = "system".
[0089] (2) Generate the processing SQL corresponding to the owner based on the owner information in the input parameters, the table alias in the configuration, and the field in the table that stores the owner in the configuration. For example, if the owner information in the input parameters is "lugang", the table alias in the configuration is empty (so no processing is done), and the field in the table that stores the owner in the configuration is "create_name", then the processing SQL corresponding to the owner is: and create_name = "lugang"; for example, if the owner information in the input parameters is "lugang", the table alias in the configuration is "batch", and the field in the table that stores the owner in the configuration is "owner", then the processing SQL corresponding to the owner is: and batch.owner = "lugang".
[0090] (3) Generate the processing SQL corresponding to the organization set based on the organization set information in the input parameters, the table alias in the configuration, and the field in the table that stores the organization in the configuration. For example, if the organization set information in the input parameters is: ["company","entry"], and the field in the configuration table that stores the organization is "owner_org", then the processing SQL corresponding to the assembled organization set is: and owner_org in("company","entry").
[0091] (4) Generate the processing SQL corresponding to the owner set based on the owner set information in the input parameters, the table alias in the configuration, and the field in the table that stores the owner in the configuration. For example, if the owner set information in the input parameters is: ["wenhai","lugang"], and the field in the table that stores the owner is "create_name", then the processing SQL corresponding to the assembled owner set is: and create_name in("wenhai","lugang").
[0092] Furthermore, the specific methods for assembling and generating permission processing SQL statements based on the permission control type include the following:
[0093] (1) When the input parameter permission control type information is 0 (i.e., no permission is checked), the SQL is not processed, but the original SQL is returned directly.
[0094] (2) When the input parameter permission control type information is 1, data is obtained according to the [owner] dimension. That is, the processing SQL corresponding to the owner is used as the permission processing SQL statement, for example: and create_name = "lugang".
[0095] (3) When the input parameter permission control type information is 2, data is obtained according to the dimensions of [owner] and [organization]. That is, the permission processing SQL statement is obtained by concatenating the processing SQL corresponding to the owner and the processing SQL corresponding to the organization. For example, it is: and create_name = "lugang" and owner_org = "system".
[0096] (4) When the input parameter permission control type information is 3, data is obtained according to the dimensions of [owner] and [organization set]. That is, the permission processing SQL statement is obtained by concatenating the processing SQL corresponding to the owner and the processing SQL corresponding to the organization set. For example, it is: and create_name = "lugang" and owner_org in("company","entry").
[0097] (5) When the input parameter permission control type information is 4, data is obtained according to the [owner set] dimension, that is, the processing SQL corresponding to the owner set is used as the permission processing SQL statement, for example: and create_name in("wenhai","lugang").
[0098] (6) When the input parameter permission control type information is 5, data is obtained according to the dimensions of [owner set] and [organization]. That is, the processing SQL corresponding to the owner set is concatenated with the processing SQL corresponding to the organization to obtain the permission processing SQL statement, for example: and create_name in("wenhai","lugang")and owner_org="system".
[0099] (7) When the input parameter permission control type information is 6, data is obtained according to the dimensions of [owner set] and [organization set]. That is, the permission processing SQL statement is obtained by concatenating the processing SQL corresponding to the owner set with the processing SQL corresponding to the organization set. For example, it is: and create_name in("wenhai","lugang")and owner_org in("company","entry").
[0100] (8) When the input parameter permission control type information is 7, data is obtained according to the [organization] dimension. That is, the processing SQL corresponding to the organization is used as the permission processing SQL statement, for example: and owner_org = "system".
[0101] (9) When the input parameter permission control type information is 8, data is obtained according to the [organization set] dimension. That is, the processing SQL corresponding to the organization set is used as the permission processing SQL statement, for example: and owner_org in("company","entry").
[0102] Furthermore, generating the target SQL statement by processing the original SQL statement and permissions can include the following two methods:
[0103] (1) When no keyword (replacement character) is configured, the fields of the assembled permission processing SQL are directly appended to the original SQL. For example, the original SQL is: select id,data_type from lam_lg_sys_batch wheredata_type in(1,2,3,4,5); the processing SQL (i.e. permission processing SQL statement) that obtains data according to the owner dimension is: and create_name="lugang". Then the assembled complete target SQL statement is: select id,data_type from lam_lg_sys_batch where data_type in(1,2,3,4,5)and create_name="lugang".
[0104] (2) When a keyword (replacement character) is configured, the change is performed at the keyword position. For example, when the reference SQL (with an alias) is: select id,serial_no,data_type,task_name,status,source_file_name,source_file_key,count_total,count_success,count_success_actual,count_failed,result_file_key,result_file_name,owner_org,owner,create_name,create_time,update_name,update_time from lam_lg_sys_batch where data_type in('1','2','3','4','5','6','7')and 9=9, and the configured keyword (replacement character) is "9=9", the processing SQL (i.e., the permission processing SQL statement) for obtaining data processing according to the owner dimension is: and create_name="lugang", then the assembled complete target SQL statement is: select id,serial_no,data_type,task_name,status,source_file_name,source_file_key,count_total,count_success,count_success_actual,count_failed,result_file_key,result_file_name,owner_org,owner,create_name,create_time,update_name,update_time from lam_lg_sys_batch where data_type in('1','2','3','4','5','6','7')and create_name="lugang"order by id desc
[0105] The generated target SQL statement supports replacing keywords (replacement characters) or directly appending new SQL statements at the end, thus allowing for flexible specification of the concatenation position of the generated SQL according to the configuration.
[0106] Based on the above examples, data can be obtained according to different dimensions through input parameter control, achieving precise permission control. Specifically, (1) it supports obtaining data according to the dimension of "owner", and accurately matching the owner through input parameter control, for the case where the account is unique; (2) it supports obtaining data according to the dimensions of "owner" and "organization", and accurately matching the owner and organization through input parameter control, and a match is achieved if both of these are matched; (3) it supports obtaining data according to the dimensions of "owner" and "organization set", and accurately matching the owner through input parameter control, where an individual can have multiple organizations, and a match is achieved if one is matched; (4) it supports obtaining data according to the dimension of "owner set", and matching the owner through input parameter control, where the individual's account is matched. (5) Supports data acquisition by the dimensions of [person set] and [organization]. At this time, there can be multiple personal accounts, and as long as one is matched, it is considered a match; (6) Supports data acquisition by the dimensions of [person set] and [organization set]. At this time, there can be multiple personal accounts, and there can also be multiple organizations corresponding to the individual. As long as one is matched, it is considered a match; (7) Supports data acquisition by the dimension of [organization]. Through input parameter control, the organization is accurately matched; (8) Supports data acquisition by the dimension of [organization set]. There can be multiple organizations corresponding to the individual. As long as one is matched, it is considered a match.
[0107] In step S15, a data query operation is performed based on the target SQL statement.
[0108] Using the data access control method described in Embodiment 1 of this invention, the initial information of the SQL that needs to be access controlled is obtained through an interceptor, and then the target SQL statement with access control is directly generated according to the preset configuration information and input parameter access information. There is no need to manually modify the code, which can not only quickly achieve access control, but also avoid complicated SQL.
[0109]
Example 2
[0110] Figure 2 This is a flowchart illustrating the data access control method according to Embodiment 2 of the present invention.
[0111] like Figure 2 As shown, in Embodiment 2 of the present invention, the data access control method may include at least the following steps S21, S22, S23, S24 and S25, which are described in detail below.
[0112] Step S21: Configuration information processing. Specifically, differentiated configuration information and common configuration information are obtained from the configuration file; the differentiated configuration information and common configuration information are merged to obtain the final configuration information (i.e., the preset configuration information).
[0113] Step S22: Determine whether the permission control type in the configuration information is 0. If the permission control type is 0 (i.e., no permission is checked), proceed to step S23; if the permission control type is not 0, proceed to step S24.
[0114] Step S23: Do not check permissions, and directly return the original SQL.
[0115] Step S24: Input parameter permission information processing, extracting input parameter permission information from the original input parameter information.
[0116] Step S25: Obtain the target SQL (i.e., the final SQL) by replacing or concatenating the original SQL and the permission-processed SQL. This step is the same as the specific processing method of step S14 in Example 1, and will not be described again here.
[0117] Using the data access control method described in Embodiment 2 of this invention, developers only need to focus on business logic without needing to pay additional attention to access control verification. Furthermore, the addition and adjustment of permissions are more flexible and do not involve code modification, thus avoiding complex SQL queries.
[0118]
Example 3
[0119] Figure 3 This is a schematic diagram of the architecture of a data access control system according to Embodiment 3 of the present invention. The framework used in this data access control system is Spring, and the persistence layer framework is MyBatis.
[0120] like Figure 3 As shown, the data access control system includes: an initial information acquisition module 310, a target SQL statement generation module 320, a data query module 330, and a configuration file monitoring module 340.
[0121] The initial information acquisition module 310 is used to acquire SQL initial information through an interceptor. The SQL initial information includes the full path name of the SQL method, the original SQL statement, and the original input parameter information.
[0122] The target SQL statement generation module 320 performs the following operations: when the command type of the original SQL statement is a select query type, it determines whether the full path name of the SQL method of the original SQL statement exists in the preset configuration information; when the full path name of the SQL method of the original SQL statement exists in the preset configuration information, it obtains the input parameter permission information according to the original input parameter information; and it generates the target SQL statement based on the original SQL statement, the preset configuration information, and the input parameter permission information. The configuration fields in the preset configuration information include, but are not limited to: whether permission detection is required, table alias, keyword, the field in the data table storing the first permission information, and the field in the data table storing the second permission information.
[0123] In some implementations, the target SQL statement generation module obtains the preset configuration information by: reading the differentiated configuration information in the configuration file; and generating the preset configuration information based on the general configuration information and the differentiated configuration information.
[0124] In some implementations, generating a target SQL statement based on the original SQL statement, preset configuration information, and input parameter permission information includes: generating an intermediate processing SQL statement based on the input parameter permission information and preset configuration information; generating a permission processing SQL statement based on the permission control type in the input parameter permission information and the intermediate processing SQL statement; and generating the target SQL statement based on the original SQL statement and the permission processing SQL statement.
[0125] In a further embodiment, the intermediate processing SQL statements include: a first processing SQL statement, a second processing SQL statement, a third processing SQL statement, and a fourth processing SQL statement; wherein, the first processing SQL statement is generated based on the first permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the first permission information; the second processing SQL statement is generated based on the second permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the second permission information; the third processing SQL statement is generated based on the third permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the first permission information; and the fourth processing SQL statement is generated based on the fourth permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table storing the second permission information.
[0126] The data query module 330 is used to perform data query operations based on the target SQL statement.
[0127] The configuration file monitoring module 340 monitors the configuration file and publishes a change event when the configuration file changes. When a change event is published, the target SQL statement generation module processes the original SQL statement according to the updated configuration file, thereby flexibly and dynamically adjusting the configuration information to achieve different access controls.
[0128] The data access control system described in Embodiment 3 of this invention obtains the initial SQL information that needs to be access controlled through an interceptor, and then directly generates the target SQL statement with access control based on the preset configuration information and input parameter access information. No manual code modification is required, which can not only quickly achieve access control, but also avoid complex SQL.
[0129] In addition, corresponding to the aforementioned data permission control system, the present invention also provides a supporting unified login system, which has built-in management of organizations, users, roles, menus, etc., wherein organizations and users correspond to the first permission information and the second permission information in the aforementioned embodiment 1, respectively.
[0130] Through the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software combined with a hardware platform. Based on this understanding, all or part of the technical solution of the present invention that contributes to the background art can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of the present invention.
[0131] Correspondingly, embodiments of the present invention also provide a computer-readable storage medium storing computer-readable instructions or programs thereon. When executed by a processor, the computer-readable instructions or programs cause a computer to perform the following operations, which include the steps included in the data access control method described in any of the above embodiments, and will not be repeated here. The storage medium may include, for example, an optical disc, a hard disk, a floppy disk, flash memory, magnetic tape, etc.
[0132] Furthermore, embodiments of the present invention also provide a computer device including a memory and a processor. The memory is used to store one or more computer-readable instructions or programs, wherein the one or more computer-readable instructions or programs, when executed by the processor, can implement the data access control method described in any of the above embodiments. The computer device may be, for example, a server, a desktop computer, a laptop computer, a tablet computer, etc.
[0133] This invention also provides a computer program product including a computer program containing program code for executing the data access control method shown in the flowchart. When the computer program product runs on a computer system, the program code enables the computer system to implement the data access control method provided in the embodiments of this disclosure.
[0134] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, Java, C++, Python, "C" language, or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. Therefore, the scope of protection of the present invention should be determined by the claims.< / string> < / string>
Claims
1. A data access control method, characterized in that, The method comprises: The initial SQL information is obtained through an interceptor, which includes the full path name of the SQL method, the original SQL statement, and the original input parameter information. When the command type of the original SQL statement is a select query type, determine whether the full path name of the SQL method of the original SQL statement exists in the preset configuration information; When the full path name of the SQL method in the original SQL statement exists in the preset configuration information, the input parameter permission information is obtained according to the original input parameter information; Generate the target SQL statement based on the original SQL statement, preset configuration information, and input parameter permission information; Perform a data query operation based on the target SQL statement.
2. The data access control method as described in claim 1, characterized in that, The configuration fields in the preset configuration information include: whether permission detection is required, table alias, keyword, field in the data table that stores the first permission information, and field in the data table that stores the second permission information.
3. The data access control method as described in claim 2, characterized in that, Obtaining input parameter permission information based on the original input parameter information includes: The first permission information, the second permission information, the third permission information, the fourth permission information, and the permission control type are extracted from the original input parameter information and used as the input parameter permission information.
4. The data access control method as described in claim 1, characterized in that, The preset configuration information is obtained using the following method: Read the differential configuration information from the configuration file; The preset configuration information is generated based on the general configuration information and the differentiated configuration information.
5. The data access control method as described in claim 3, characterized in that, Generating the target SQL statement based on the original SQL statement, preset configuration information, and input parameter permission information includes: Generate intermediate processing SQL statements based on the input parameter permission information and preset configuration information; Generate permission processing SQL statements based on the permission control type in the input parameter permission information and the intermediate processing SQL statements; The target SQL statement is generated based on the original SQL statement and the permissions processed SQL statement.
6. The data access control method as described in claim 5, characterized in that, The intermediate processing SQL statements include: a first processing SQL statement, a second processing SQL statement, a third processing SQL statement, and a fourth processing SQL statement; wherein, The first processing SQL statement is generated based on the first permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the first permission information. The second processing SQL statement is generated based on the second permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the second permission information. The third processing SQL statement is generated based on the third permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the first permission information. The fourth processing SQL statement is generated based on the fourth permission information in the input parameter permission information, the table alias in the preset configuration information, and the field in the data table that stores the second permission information.
7. The data access control method as described in claim 4, characterized in that, The method further includes: monitoring the configuration file and publishing a change event when the configuration file changes.
8. A computer-readable storage medium storing computer-readable instructions, characterized in that, The computer-readable instructions are executed by a processor to implement the data access control method as described in any one of claims 1-7.
9. A computer device comprising a memory and a processor, The memory stores computer-readable instructions, characterized in that, The processor executes the computer-readable instructions to implement the data access control method as described in any one of claims 1-7.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data access control method as described in any one of claims 1-7.