Authority management method and device, equipment, medium and product

By generating and sending permission management information in the software system, the complex permission management problem of user roles is solved, low-code development is achieved, development and maintenance costs are reduced, and efficiency is improved.

CN120909568APending Publication Date: 2025-11-07AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511070880.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In software systems, user roles are complex and permission management is complicated. Existing technologies make it difficult to achieve low-code development, resulting in high development and maintenance costs, and requiring operations and maintenance personnel to spend a lot of time analyzing the code.

Method used

By generating target permission management information, including form configuration operations and program configuration operations, the permission configuration information is generated and sent to the server. The system responds to user role requests to trigger operations, determines permissions, and provides feedback on the results, thus achieving low-code development and permission management.

Benefits of technology

It reduced development and maintenance costs, improved development efficiency, reduced the workload of operations and maintenance personnel, and simplified the access control process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120909568A_ABST
    Figure CN120909568A_ABST
Patent Text Reader

Abstract

The invention discloses an authority management method and device, equipment, a medium and a product, and the method comprises the steps: for target data, responding to authority configuration operation of a management role on a visual interface, and generating target authority management information, the authority configuration operation comprising form configuration operation and program configuration operation; sending the target permission configuration information to a server; and for target data, in response to a request triggering operation of a user role, calling the target permission configuration information from a server, determining whether the user role has a triggering permission, and feeding back a corresponding triggering result to the user role. According to the technical scheme, low-code development is realized, and the operation complexity of operation and maintenance personnel during authority management can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer technology, and in particular to a permission management method, device, equipment, medium and product. BACKGROUND

[0002] In a software system, different user roles exist for different users, and the functions and operation permissions of different user roles are different. Software developers need to customize the development of these permission functions according to various business scenarios and user roles.

[0003] Taking a software system of a task flow type as an example, when two user roles view the same task, the task details that can be viewed and the operations on the task are different. If the number of user roles of a system is large and the business scenarios are complex, the workload of the developers will be greatly increased. If the developers do not leave documents during development, the operation and maintenance personnel may need to spend a lot of effort to read the code for analysis. SUMMARY

[0004] The present application provides a permission management method, device, equipment, medium and product, which realizes low-code development and can reduce the operation complexity of operation and maintenance personnel in permission management.

[0005] In a first aspect, the present application provides a permission management method, comprising:

[0006] For target data, in response to a permission configuration operation of a management role on a visual interface, generating target permission management information, the permission configuration operation including a form configuration operation and a program configuration operation;

[0007] Sending the target permission configuration information to a server;

[0008] For target data, in response to a request trigger operation of a user role, calling the target permission configuration information from the server, determining whether the user role has a trigger permission, and feeding back a corresponding trigger result to the user role.

[0009] In a second aspect, the present application provides a permission management device, comprising:

[0010] A permission configuration module for generating target permission management information in response to a permission configuration operation of a management role on a visual interface for target data, the permission configuration operation including a form configuration operation and a program configuration operation;

[0011] An information storage module for sending the target permission configuration information to a server;

[0012] The permission triggering module is configured to, for target data, in response to a request triggering operation of a user role, call the target permission configuration information from the server, determine whether the user role has the triggering permission, and feed back the corresponding triggering result to the user role.

[0013] In a third aspect, the embodiments of the present disclosure provide an electronic device, comprising:

[0014] at least one processor; and

[0015] a memory in communication with the at least one processor; wherein

[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the permission management method provided in the first aspect.

[0017] In a fourth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which stores computer instructions, and the computer instructions are used to enable a processor to implement the permission management method provided in the first aspect when executed.

[0018] In a fifth aspect, the embodiments of the present disclosure provide a computer program product, which comprises a computer program, and the computer program implements the permission management method provided in the first aspect when executed by a processor.

[0019] The permission management method, device, equipment, medium and product provided by the embodiments of the present disclosure comprise: for target data, in response to a permission configuration operation of a management role on a visual interface, generating target permission management information, the permission configuration operation comprising a form configuration operation and a program configuration operation; sending the target permission configuration information to a server; for target data, in response to a request triggering operation of a user role, calling the target permission configuration information from the server, determining whether the user role has the triggering permission, and feeding back the corresponding triggering result to the user role. The above technical solution realizes low-code development and can reduce the operation complexity of an operation and maintenance personnel in permission management.

[0020] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to make the technical solution in the embodiments of the present application clearer, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some of the embodiments of the present application, and all other drawings obtained by those skilled in the art without any creative effort should be within the protection scope of the present application.

[0022] Figure 1 is a flow chart of a permission management method provided by the first embodiment of the present application;

[0023] Figure 2 is a flow chart of a form-based permission configuration and invocation provided by the first embodiment of the present application;

[0024] Figure 3 is a flow chart of a permission management method provided by the second embodiment of the present application;

[0025] Figure 4 is an example display diagram of a permission management form provided by the second embodiment of the present application;

[0026] Figure 5 is an example display diagram of a meta form provided by the second embodiment of the present application;

[0027] Figure 6 is a flow chart of a meta form configuration provided by the second embodiment of the present application;

[0028] Figure 7 is an example display diagram of a form row provided by the second embodiment of the present application;

[0029] Figure 8 is a flow chart of a form row configuration provided by the second embodiment of the present application;

[0030] Figure 9 is a structural schematic diagram of a permission management device provided by the third embodiment of the present application;

[0031] Figure 10 is a structural schematic diagram of an electronic device provided by the fourth embodiment of the present application. DETAILED DESCRIPTION

[0032] In order to make the technical solution in the embodiments of the present application clearer, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some of the embodiments of the present application, and all other drawings obtained by those skilled in the art without any creative effort should be within the protection scope of the present application.

[0033] It should be noted that the terms "first", "second", and "target" and the like in the description, claims, and drawings of the present application and the above-mentioned are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0034] In a software system, there are information and multiple buttons on a certain software page that need to be read and filled in by users, different users use the information of the page, but the permissions of the buttons are different, and the state of the page information also affects the availability of the buttons. For example,

[0035] Button 1: requires the current logged-in user to be role 1 and the task state to be state 1;

[0036] Button 2: requires the current logged-in user to be role 1 or 2 or 3, and the task state to be state 2 or state 3 or state 4;

[0037] Button 3: requires the current logged-in user to be role 2, and when all process states are state 5 or state 6.

[0038] The permission configuration method in the prior art can only visually configure the permissions of users entering the page, so the visual configuration of different permissions in the complex page in the above scenario is not perfect. In addition, the prior art is often implemented through hard coding technology, and if the permission requirements change, the code needs to be redeveloped, which is low in maintenance efficiency.

[0039] Embodiment one

[0040] Figure 1 is a flowchart of a permission management method provided by the present application embodiment one, the present application embodiment one can be applicable to the case that the management role configures permissions for the target data and the user role accesses the target data, and the method can be executed by a permission management device, which can be realized in the form of hardware and / or software.

[0041] As shown in Figure 1 , the method comprises:

[0042] S101, for the target data, in response to the permission configuration operation of the management role on the visual interface, generating target permission management information, the permission configuration operation comprising form configuration operation and program configuration operation.

[0043] In the embodiment, the target data can be understood as data information with permissions, which can be data itself or a trigger button control for accessing or modifying data. The management role can be understood as an administrator role, including a first management role and a second management role, the first management role being a developer role and the second management role being an operation and maintenance personnel role. The visual interface can be understood as an interface for configuring permissions, such as a form interface or a program interface. The form interface includes a permission management form, and the corresponding permission configuration can be completed by configuring the permission management form in the form interface, and the first management role and the second management role can access the configuration. The program interface is used for inputting a program language, and the permission configuration is directly completed based on the input program language, and only the first management role can access the configuration. The target permission management information can be understood as information configured for managing permissions. If the permission configuration operation is a form configuration operation, the target permission management information is formatted information of the permission management form. If the permission configuration operation is a program configuration operation, the target permission management information is the program itself input in the program interface.

[0044] Specifically, for the target data or the button control for accessing and processing the target data, Figure 2 is a flowchart of permission configuration and calling based on a form provided by an embodiment of the present application, as Figure 2 shown, in response to a form configuration operation of the management role on the visual interface, a complete permission management form is determined, information in the permission management form is generated into a legal syntax string, such as a JavaScript syntax string, and formatted information (such as JSON format or XML format) is generated according to the agreement between the client and the server to form target permission management information that can be received and stored by the server. In response to the program configuration operation of the management role on the visual interface, the program language input by the management role is directly taken as the target permission management information.

[0045] S102, the target permission configuration information is sent to the server.

[0046] In the embodiment, the target permission configuration information is sent to the associated server for storage and calling by the client.

[0047] S103, for the target data, in response to the request trigger operation of the user role, the target permission configuration information is called from the server, it is determined whether the user role has the trigger permission, and the corresponding trigger result is fed back to the user role.

[0048] In this embodiment, the request trigger operation can be understood as an operation in which the user role requests to access or manage the target data. The trigger result can be understood as information related to whether the user role has the trigger permission. When the user role has the trigger permission, the trigger result is the target data. When the user role does not have the trigger permission, the trigger result is a request failure notification.

[0049] Specifically, for the target data, in response to the request trigger operation of the user role, the target permission configuration information is requested from the server and the target permission configuration information fed back by the server based on the request is accepted. As shown in Figure 2 If the target permission configuration information is formed based on the form configuration operation, after the target permission configuration information is received, the formatted target permission configuration information is converted into a string with a specific syntax, for example, a JavaScript string. Through a constructor in the specific syntax, the string is converted into a method that can be run by the browser. For example, in JavaScript, through the Function constructor in JavaScript, the string is converted into a JavaScript method that can be run by the browser. During the system development stage, the developer needs to pre-embed the part that needs to control the permission. When the permission needs to be judged, the method generated above is called. The parameter of the method is the unique identifier of the current function and all data related to the business logic in the current use scenario. The return result of the method is of a Boolean type (true / false). The client determines whether the user role has the permission for the target role through the value of the Boolean type. True indicates that the permission is possessed, and false indicates that the permission is not possessed. If the permission is possessed, the target data corresponding to the request trigger operation and the trigger result thereof are fed back to the user role. If the permission is not possessed, a request failure notification is fed back to the user role. Taking the front-end framework Vue as an example, the v-if="true" or v-if="false" instruction is used in the label that needs to control the permission, so that the function can be realized.

[0050] If the target permission configuration information is formed based on the form configuration operation, the formatted information does not need to be processed. The data edited online is generated into a method by a constructor with a specific syntax, and other operations are the same as the visual editing.

[0051] The method comprises the following steps: in response to a permission configuration operation of a management role on a visual interface, generating target permission management information for target data, the permission configuration operation comprising a form configuration operation and a program configuration operation; sending the target permission configuration information to a server; in response to a request trigger operation of a user role for the target data, calling the target permission configuration information from the server, determining whether the user role has the trigger permission, and feeding back the corresponding trigger result to the user role. The above technical solution uses a visual and general logic to process complex business scenarios when a software developer writes a function about permission in a system, so as to reduce workload, reduce maintenance cost, and improve development efficiency. The form configuration method used in the embodiment only needs to be programmed once, that is, to be embedded in a function that needs to be controlled by permission; the user is maintained in a visual page; the communication link with the developer, the new program code deployment link, and the network server restart link are removed, so that the efficiency is greatly improved; in addition, the maintenance personnel only need to learn the use method of the software system, and do not need to have professional software development knowledge to achieve the purpose of modifying the role permission, so that the maintenance threshold is significantly reduced.

[0052] As a first optional embodiment of the present embodiment, when the permission configuration operation is a program configuration operation, in response to the permission configuration operation of the management role on the visual interface, the target permission management information is generated, comprising:

[0053] In response to program input of the first management role on the program interface, the target permission management information is generated.

[0054] In the present embodiment, in the actual use of the system, there may be some complex business judgments that cannot be met by pure form filling. At this time, advanced usage can be used for online programming. Online programming only needs to write a method that can return a Boolean value in the form according to the agreement, but for the online written method, a regular expression check needs to be performed to exclude unsafe code or the situation that the system performance is affected due to misoperation. For the sake of system security, the permission of the program configuration operation can only be opened to senior management users with professional knowledge, that is, the first management role, and the second management role of the non-developer can only use the visual form to control the permission. Therefore, in response to the program input of the first management role on the program interface, the input program language is directly taken as the target permission management information.

[0055] Embodiment two

[0056] Figure 3is a flowchart of a permission management method provided by Embodiment Two of the present application, the present embodiment is a further optimization of any of the above embodiments, and can be applicable to a case where a management role performs permission configuration on target data based on form configuration operations and a user role performs permission access on target data, the method can be executed by a permission management apparatus, which can be realized in the form of hardware and / or software.

[0057] As shown in Figure 3 , the method comprises:

[0058] S201, for target data, in response to the meta-form configuration of the permission management form on the form interface by the target management role, generating meta-form information, the target management role comprising a first management role and a second management role.

[0059] In the present embodiment, the target management role is a management role that can perform form configuration operations, including a first management role (developer) and a second management role (ordinary management role / operation and maintenance personnel). The permission management form can be understood as a form for the target management role to select or input conditions on the visual interface. The meta-form information can be understood as a permission judgment condition, which is composed of comparison options, comparison symbols, comparison values and their corresponding fields.

[0060] Specifically, in response to the meta-form configuration of the permission management form on the form interface by the target management role, the comparison options, comparison symbols and comparison values in the meta-form are determined, and the corresponding meta-form information is generated. Among them, the comparison options and comparison symbols are selected through the radio box, and the comparison values are selected through the radio box or input by the input box.

[0061] Optionally, in response to the meta-form configuration of the permission management form on the form interface by the target management role, generating meta-form information, comprising:

[0062] S2011, in response to the meta-form new operation of the permission management form on the form interface by the target management role, establishing a current meta-form.

[0063] In the present embodiment, the current meta-form can be understood as a meta-form established based on the meta-form new operation, and each meta-form new operation corresponds to a current meta-form.

[0064] Specifically, Figure 4 is an example display diagram of a permission management form provided by Embodiment Two of the present application, Figure 5 is an example display diagram of a meta-form provided by Embodiment Two of the present application, as shown in Figure 4 and Figure 5 As shown in Figure 4 , the visual interface presents a permission management form as shown in Figure 5The "add or" control and the "delete or" control for the meta form are shown. In response to a trigger operation of the "add or" control, a current meta form is established, and the current meta form includes a comparison option control, a comparison symbol control and a comparison value control, at this time, the comparison option, the comparison symbol and the comparison value are all null values. In response to a trigger operation of the "delete or" control, the corresponding current meta form is deleted.

[0065] S2012, in response to a configuration item configuration operation of the target management role for the current meta form, the comparison option, the comparison symbol and the comparison value of the meta form are determined, and meta form information related to the meta form is generated.

[0066] Specifically, in response to a selection operation of an option in the comparison option list single selection box on the current meta form, a selection operation of an option in the comparison symbol single selection box, a selection operation of an option in the comparison value single selection box or an input operation of information in the comparison value input box, the specific fields of the comparison option, the comparison symbol and the comparison value of the meta form are determined, and the meta form information related to the meta form is generated.

[0067] Among them, the meta form is divided into three parts, the comparison option, the comparison symbol and the comparison value.

[0068] The form filling form of the comparison symbol control is a single selection box, and the options of the single selection box are greater than (>), greater than or equal to (>=), equal to (==), less than (<), less than or equal to (<=), not equal to (!=) and the like.

[0069] The left side of the comparison symbol control is the comparison option control, and the form filling form of the comparison option control is a single selection box, and the options of the single selection box are all the business information used for the judgment of the permission, which is the specific data obtained by the client through the interface request. Taking a task flow type system as an example, in a certain task approval link, the approval detail page will have a button control related to the approval function. The judgment conditions required by this button control are "user" and "task state", so the options of the single selection box should include "user" and "task state".

[0070] The right side of the comparison symbol control is the comparison value control, and the comparison value control has two filling forms, one is a single selection box, and the options correspond to the options of the comparison option control; the other is an input box, which allows the user to freely input the value to be compared.

[0071] Figure 6 is a flowchart of a meta form configuration provided by an embodiment of the present application, as Figure 6 shown, the configuration item configuration operation for the current meta form includes:

[0072] 1. selecting a comparison option in the single selection box;

[0073] 2. selecting a comparison symbol in the single selection box;

[0074] 3. confirming whether the comparison value is manually inputted;

[0075] 4. if the comparison value is manually inputted, inputting the comparison value in the input box;

[0076] 5. if the comparison value is not manually inputted, selecting the comparison value in the single selection box.

[0077] S202, in response to the target management role configuring a form row of the permission management form on the form interface, generating form row information.

[0078] In the embodiment, the form row information can be understood as a permission judgment condition, which is composed of the meta-form and the corresponding fields.

[0079] Specifically, in response to the target management role configuring the form row of the permission management form on the form interface, the meta-form in the form row is determined, and the form row information containing all meta-forms in the form row is generated.

[0080] Optionally, in response to the target management role configuring the form row of the permission management form on the form interface, the form row information is generated, including:

[0081] S2021, in response to the target management role performing a form row new operation on the permission management form on the form interface, establishing a current form row.

[0082] In the embodiment, the current form row can be understood as a form row established based on the form row new operation, and each form row new operation corresponds to a current form row.

[0083] Specifically, Figure 7 is an example display diagram of a form row provided by the second embodiment of the application, as Figure 4 and Figure 7 shown, the visual interface presents a permission management form as Figure 4 shown, the permission management form is provided with an "add with" control and a "delete with" control for the form row as Figure 7 shown. In response to the triggering operation of the "add with" control, a current form row is established, and the current form row includes at least one meta-form. In response to the triggering operation of the "delete with" control, the corresponding current form row is deleted.

[0084] S2022, in response to the target management role performing a meta-form configuration operation on the current form row, determining the meta-form of the form row, and generating form row information related to the form row, the form row including at least one meta-form, and the meta-forms in the form row using or logic.

[0085] Specifically, in response to a configuration operation of a target management role on a meta form in a current form row, step S201 is performed to determine each meta form and its specific field in the form row, and generate meta form information related to the form row. Wherein, the form row includes at least one meta form, and the meta forms in the form row are connected by or logic, that is, the addition and deletion of the meta forms in the form row are realized through "add or" or "delete or" controls.

[0086] Figure 8 is a flowchart of form row configuration provided by the second embodiment of the present application, as shown in Figure 8 After the meta form is newly created and filled in the form row, it is judged whether there is "or" logic at present. If there is, the meta form can be newly created and filled in the form row, and it is judged again whether there is "or" logic at present. The cycle is repeated until there is no "or" logic at present, and the establishment and filling of a single form row are completed. If there is no "or" logic, it is judged whether there is "and" logic at present. If there is "and" logic, a new form row is established, and the meta form is newly created and filled in the new form row. The cycle is repeated until there is no "or" logic and no "and" logic at present.

[0087] S203, in response to the form block configuration of the target management role on the permission management form on the form interface, form block information is generated.

[0088] In the present embodiment, the form block information can be understood as a permission judgment condition, which is composed of the form row and its corresponding field.

[0089] Specifically, in response to the form block configuration of the target management role on the permission management form on the form interface, the form row in the form block is determined, and the form block information containing all form rows in the form block is generated.

[0090] Optionally, in response to the form block configuration of the target management role on the permission management form on the form interface, the form block information is generated, including:

[0091] S2031, in response to the form block creation operation of the target management role on the permission management form on the form interface, a current form block is established.

[0092] In the present embodiment, the current form block can be understood as a form block established based on the form block creation operation. Each form block creation operation corresponds to a current form block.

[0093] Specifically, as shown in Figure 4 The visual interface presents, as shown in Figure 4The shown permission management form is provided with an "add or" control and a "delete or" control for the form block. In response to the triggering operation of the "add or" control, a current form block is established, and the current form block includes at least one form row. In response to the triggering operation of the "delete or" control, the corresponding current form block is deleted.

[0094] S2032, in response to the form row configuration operation of the target management role for the current form block, the form rows of the form block are determined, the three-level permission management information related to the form block is generated, the form block includes at least one form row, and the form rows in the form block adopt an and logic, the permission management form includes at least one form block, and the form blocks in the permission management form adopt an or logic.

[0095] Specifically, in response to the configuration operation of the target management role for the form row on the current form block, step S202 is performed, each form row and its specific field of the form block are determined, and form block information related to the form block is generated. Wherein, the form block includes at least one form row, and the form rows in the form block adopt an and logic, that is, the addition and deletion of the form rows in the form block are realized through the "add and" or "delete and" control. The permission management form includes at least one form block, and the form blocks in the permission management form adopt an or logic, that is, the addition and deletion of the form blocks in the permission management form are realized through the "add or" or "delete or" control.

[0096] In the embodiment, the permissions can be configured in the order of the meta-form, the form row, and the form block, or vice versa, which is not limited in the embodiment.

[0097] The visual form interface provided by the embodiment of the application is designed according to the "and" and "or" conditions. In the logical judgment, "and" and "or" are the most important judgment conditions. The design of the visual form should serve the data structure of the formatted information finally processed. The core of the formatted information data structure of the client and the server interaction in the scheme is that the "and" logic is the array type of the same level, and the "or" logic is the same level item in the same array. A form with a complete comparison formula is defined as a "meta-form". The "or" logic between the judgment conditions is represented by adding or deleting the same level meta-form in the same row. A module composed of one or more meta-forms in the same row is defined as a "form row". The "and" logic of the judgment conditions is represented by adding or deleting the form row. A module composed of one or more form rows is defined as a "form block". The form blocks are "or" logic, and the form blocks can be extended indefinitely.

[0098] In summary, the meta-forms are "or" logic; the form rows are "and" logic; and the form blocks are "or" logic.

[0099] S204, encapsulate at least one of the metaform information, the form row information and the form block information into a target format to form target permission management information.

[0100] In this embodiment, the target format can be understood as a pre-set format, for example, a JSON format or an XML format.

[0101] Specifically, based on the received configuration type, the corresponding information is encapsulated into a target format to form target permission management information. If only metaform configuration is received, the metaform information is encapsulated into a target format to form target permission management information; the other two are the same. If metaform configuration and form row configuration are received, the metaform information and the form row information are encapsulated into a target format to form target permission management information; the other two combinations are the same. If metaform configuration, form row configuration and form block configuration are received, the metaform information, form row information and form block information are encapsulated into a target format to form target permission management information.

[0102] S205, send the target permission configuration information to the server.

[0103] S206, for the target data, in response to the request of the user role triggering operation, call the target permission configuration information from the server, determine whether the user role has triggering permission, and feed back the corresponding triggering result to the user role.

[0104] The permission management method provided by the embodiment of the application comprises: in response to a meta-form configuration of a permission management form on a form interface by a target management role, generating meta-form information for target data, the target management role comprising a first management role and a second management role; in response to a form row configuration of the permission management form on the form interface by the target management role, generating form row information; in response to a form block configuration of the permission management form on the form interface by the target management role, generating form block information; at least one of the meta-form information, the form row information and the form block information is encapsulated into a target format to form target permission management information. The target permission configuration information is sent to a server; in response to a request trigger operation by a user role, the target permission configuration information is called from the server for the target data, it is determined whether the user role has a trigger permission, and a corresponding trigger result is fed back to the user role. The above technical solution decouples the business logic from the software code, so that the developer does not need to consider the specific business logic and business scenario when writing the permission-related code, and only needs to pre-embed the position where the logic needs to be judged, thereby greatly reducing the development difficulty and workload; the business logic code is abstracted into a visual page, so that even in the absence of a system design document, the business logic can still be clearly and intuitively read, facilitating subsequent conditional modification; since the judgment conditions of the business logic are stored in the database, if the judgment conditions need to be modified, the visual page operation is only needed, and the system can be re-entered, without the need to modify the code, re-deploy and restart the server, so that the modification efficiency is significantly improved.

[0105] Embodiment three

[0106] Figure 9 is a structural schematic diagram of a permission management device provided by the embodiment three of the application. As shown in the figure, Figure 9 the device comprises:

[0107] The permission configuration module 31 is configured to generate target permission management information in response to a permission configuration operation of a management role on a visual interface for target data, the permission configuration operation comprising a form configuration operation and a program configuration operation.

[0108] The information storage module 32 is configured to send the target permission configuration information to a server.

[0109] The permission trigger module 33 is configured to call the target permission configuration information from the server in response to a request trigger operation by a user role for target data, determine whether the user role has a trigger permission, and feed back a corresponding trigger result to the user role.

[0110] The permission management device adopted in the technical solution can realize low-code development and reduce the operation complexity of an operation and maintenance personnel during permission management.

[0111] Optionally, the permission configuration module 31 comprises:

[0112] The meta-form configuration unit is configured to, when the permission configuration operation is a form configuration operation, generate meta-form information in response to a meta-form configuration of a target management role on a permission management form on a form interface, the target management role comprising a first management role and a second management role.

[0113] The form row configuration unit is configured to, when the permission configuration operation is a form configuration operation, generate form row information in response to a form row configuration of a target management role on a permission management form on a form interface.

[0114] The form block configuration unit is configured to, when the permission configuration operation is a form configuration operation, generate form block information in response to a form block configuration of a target management role on a permission management form on a form interface.

[0115] The management information generation unit is configured to, when the permission configuration operation is a form configuration operation, encapsulate at least one of the meta-form information, the form row information and the form block information into a target format to form target permission management information.

[0116] Optionally, the meta-form configuration unit is specifically configured to:

[0117] establish a current meta-form in response to a meta-form new operation of a target management role on a permission management form on a form interface.

[0118] determine a comparison option, a comparison symbol and a comparison value of the meta-form, and generate meta-form information related to the meta-form in response to a configuration item configuration operation of the target management role on the current meta-form.

[0119] Optionally, the form row configuration unit is specifically configured to:

[0120] establish a current form row in response to a form row new operation of a target management role on a permission management form on a form interface.

[0121] determine a meta-form of the form row, and generate form row information related to the form row in response to a meta-form configuration operation of a target management role on the current form row, the form row comprising at least one meta-form, and the meta-forms in the form row using or logic.

[0122] Optionally, the form block configuration unit is specifically configured to:

[0123] establish a current form block in response to a form block new operation of a target management role on a permission management form on a form interface.

[0124] In response to a target management role configuring a form row of the current form block, a form row of the form block is determined, third-level permission management information related to the form block is generated, at least one form row is included in the form block, and and logic is used between the form rows in the form block, at least one form block is included in the permission management form, and or logic is used between the form blocks in the permission management form.

[0125] Optionally, the permission configuration module 31 is further configured to:

[0126] When the permission configuration operation is a program configuration operation, in response to a program input of the first management role on the program interface, target permission management information is generated.

[0127] The permission management apparatus provided by the embodiments of the present application can execute the permission management method provided by any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of the execution method.

[0128] Embodiment four

[0129] Figure 10 Fig. 1 is a structural schematic diagram of an electronic device provided by Embodiment Four of the present application. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (such as headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.

[0130] As shown in Fig. 10, the electronic device 40 includes at least one processor 41, and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41, wherein the memory stores a computer program that can be executed by the at least one processor. The processor 41 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. In the RAM 43, various programs and data required for the operation of the electronic device 40 can also be stored. The processor 41, the ROM 42, and the RAM 43 are connected to each other through a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0131] A plurality of components in the electronic device 40 are connected to the I / O interface 45, including: an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.

[0132] The processor 41 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 performs various methods and processes described above, such as the permission management method.

[0133] In some embodiments, the permission management method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded onto the RAM 43 and executed by the processor 41, one or more steps of the permission management method described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to perform the permission management method by any other appropriate means, such as by means of firmware.

[0134] The various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0135] Computer programs for implementing the methods of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, enables the functions / acts specified in the flowcharts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine or entirely on a remote machine or server.

[0136] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0137] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0138] The systems and techniques described herein can be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described herein, or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0139] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.

[0140] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be performed in parallel, in series, or in a different order, and the present disclosure is not limited in this regard.

[0141] The specific embodiments described above are not intended to limit the scope of the present disclosure. Those skilled in the art will understand that various modifications, combinations, sub-combinations, and alternatives can be made to the specific embodiments without departing from the spirit and principles of the present disclosure. Any further modifications, equivalents, and / or alternatives come within the scope of the present disclosure as recited by the claims.

Claims

1. A rights management method, characterized by, The application comprises the following steps: For target data, in response to the permission configuration operation of the management role on the visualization interface, target permission management information is generated, and the permission configuration operation comprises form configuration operation and program configuration operation; The target permission configuration information is sent to the server; For target data, in response to the request trigger operation of the user role, the target permission configuration information is called from the server, it is determined whether the user role has the trigger permission, and the corresponding trigger result is fed back to the user role.

2. The method of claim 1, wherein, When the permission configuration operation is the form configuration operation, the target permission management information is generated in response to the permission configuration operation of the management role on the visualization interface, comprising: In response to the meta-form configuration of the target management role to the permission management form on the form interface, meta-form information is generated, and the target management role comprises a first management role and a second management role; In response to the form row configuration of the target management role to the permission management form on the form interface, form row information is generated; In response to the form block configuration of the target management role to the permission management form on the form interface, form block information is generated; At least one of the meta-form information, the form row information and the form block information is encapsulated into a target format to form target permission management information.

3. The method of claim 2, wherein, The meta-form information is generated in response to the meta-form configuration of the target management role to the permission management form on the form interface, comprising: In response to the meta-form new operation of the target management role to the permission management form on the form interface, a current meta-form is established; In response to the configuration item configuration operation of the target management role to the current meta-form, the comparison option, the comparison symbol and the comparison value of the meta-form are determined, and the meta-form information related to the meta-form is generated.

4. The method of claim 2, wherein, The form row information is generated in response to the form row configuration of the target management role to the permission management form on the form interface, comprising: In response to the form row new operation of the target management role to the permission management form on the form interface, a current form row is established; In response to the meta-form configuration operation of the target management role to the current form row, the meta-form of the form row is determined, and the form row information related to the form row is generated, the form row comprises at least one meta-form, and the meta-forms in the form row adopt or logic.

5. The method of claim 2, wherein, The form block information is generated in response to the form block configuration of the target management role to the permission management form on the form interface, comprising: In response to the form block new operation of the target management role to the permission management form on the form interface, a current form block is established; In response to the form row configuration operation of the target management role to the current form block, the form row of the form block is determined, and the three-level permission management information related to the form block is generated, the form block comprises at least one form row, the form rows in the form block adopt and logic, the permission management form comprises at least one form block, and the form blocks in the permission management form adopt or logic.

6. The method of claim 1, wherein, When the permission configuration operation is the program configuration operation, the target permission management information is generated in response to the permission configuration operation of the management role on the visualization interface, comprising: In response to a program input of the first management role on the program interface, target permission management information is generated.

7. A rights management apparatus characterized by comprising: The method comprises the steps of: The permission configuration module is configured to generate target permission management information in response to a permission configuration operation of a management role on a visual interface for target data, wherein the permission configuration operation comprises a form configuration operation and a program configuration operation; The information storage module is configured to send the target permission configuration information to a server; The permission triggering module is configured to determine whether a user role has triggering permission by calling the target permission configuration information from the server in response to a request triggering operation of the user role for target data, and feed back the corresponding triggering result to the user role.

8. An electronic device, comprising: The method comprises the steps of: at least one processor; and a memory connected to the at least one processor in communication; wherein The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute any one of the claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for enabling the processor to execute any one of the claims 1-6 when executed.

10. A computer program product, characterised in that, The computer program product comprises a computer program which, when executed by a processor, implements a permission management method according to any one of claims 1-6.