Product retrieval method and device based on permission configuration, equipment and medium

By parsing the user's identity and permission fields and generating data filtering conditions, the problem of insufficient permission control in enterprise-level product retrieval is solved, achieving accurate data filtering and efficient data retrieval.

CN122086933APending Publication Date: 2026-05-26特赞(上海)信息科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
特赞(上海)信息科技有限公司
Filing Date
2026-01-13
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies lack flexibility in access control for enterprise-level product retrieval, resulting in low data retrieval efficiency and difficulty in meeting the needs for refined and dynamic access control.

Method used

By receiving data query requests from users, parsing their identity and permission fields, generating data filtering conditions using preset permission-filter mapping relationships, and filtering out target content that meets the permissions from the product database, including preset content or other content.

Benefits of technology

It enables precise filtering of product content, ensuring that users only access data within their authorized scope, improving data retrieval efficiency and enhancing the security and controllability of data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122086933A_ABST
    Figure CN122086933A_ABST
Patent Text Reader

Abstract

This disclosure provides a product retrieval method, apparatus, device, and medium based on permission configuration, comprising: receiving a data query request from a user for preset product content; responding to the user's data query request for preset product content by obtaining the user's identity permission field; parsing the specific permission parameters included in the user's identity permission field to obtain user permission parameters; mapping the user permission parameters through a preset permission-filter mapping relationship to obtain data filtering conditions for the product content in the product database corresponding to the user; and determining the target product content to be displayed to the user from the product database according to the data filtering conditions corresponding to the user; the target product content includes: preset product content, or preset product content and other product content, or other product content. This effectively improves data retrieval efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this disclosure relate to the field of data retrieval technology, and more specifically, to a product retrieval method, apparatus, device, and medium suitable for permission-based configuration. Background Technology

[0002] Enterprise-level content management often involves complex permission requirements. For example, different departments and roles may have different access permissions to content; content needs to differentiate between the visibility of internal employees and external contacts; and permission granularity needs to be fine-grained down to the content level, rather than simple menu permissions.

[0003] In related technologies, role-based access control is mainly used to constrain user search content. Although it can achieve a preliminary division of the scope of user operations, it often has certain limitations when facing the increasingly refined and dynamic permission requirements in enterprise-level product search scenarios.

[0004] However, the existing methods lack flexibility in access control, resulting in low data retrieval efficiency. Summary of the Invention

[0005] The embodiments described herein provide a product retrieval method, apparatus, device, and medium based on permission configuration, overcoming the aforementioned problems.

[0006] Firstly, based on the content of this disclosure, a product retrieval method based on permission configuration is provided, including: Receive data query requests from users for preset product content; In response to the query user's data query request for the preset product content, obtain the identity and permission fields corresponding to the query user; Parse the specific permission parameters included in the identity permission field corresponding to the queried user to obtain the user permission parameters; By performing a relational mapping on the user permission parameters through a preset permission-filter mapping relationship, the data filtering conditions corresponding to the product content in the product database for the querying user are obtained. Based on the data filtering conditions corresponding to the querying user, the target product content to be displayed to the querying user is determined from the product database; the target product content includes: the preset product content, or the preset product content and other product content, or the other product content.

[0007] Secondly, according to the content of this disclosure, a product retrieval device based on permission configuration is provided, comprising: The receiving module is used to receive data query requests from users for preset product content; The acquisition module is used to respond to the data query request of the querying user for the preset product content and acquire the identity and permission fields corresponding to the querying user; The parsing module is used to parse the specific permission parameters included in the identity permission field corresponding to the queried user to obtain the user permission parameters; The mapping module is used to perform relational mapping on the user permission parameters through a preset permission-filter mapping relationship, so as to obtain the data filtering conditions of the query user corresponding to the product content in the product database; The determining module is used to determine, from the product database, the target product content to be displayed to the querying user based on the data filtering conditions corresponding to the querying user; the target product content includes: the preset product content, or the preset product content and other product content, or the other product content.

[0008] Thirdly, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the product retrieval method based on permission configuration as described in any of the above embodiments.

[0009] Fourthly, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the product retrieval steps based on permission configuration as described in any of the above embodiments.

[0010] The product retrieval method based on permission configuration provided in this application receives a data query request from a user for preset product content; responds to the user's request by obtaining the user's identity permission field; parses the specific permission parameters included in the user's identity permission field to obtain user permission parameters; maps the user permission parameters through a preset permission-filter mapping relationship to obtain data filtering conditions for the product content in the product database corresponding to the user; and determines the target product content to be displayed to the user from the product database based on the user's data filtering conditions. The target product content includes: preset product content, or preset product content and other product content, or other product content. Thus, by generating data filtering rules tailored to the user through a pre-established mapping relationship, precise filtering of product content is achieved during the product retrieval process, ensuring that the user can only obtain target product content matching their permissions, effectively improving data retrieval efficiency.

[0011] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more obvious and understandable, specific implementation methods of this application are described below. Attached Figure Description

[0012] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments will be briefly described below. It should be understood that the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure, wherein: Figure 1 This is a flowchart illustrating a product retrieval method based on permission configuration provided in this disclosure.

[0013] Figure 2 This is a schematic diagram of a product retrieval device based on permission configuration provided in this disclosure.

[0014] Figure 3 This is a schematic diagram of the structure of a computer device provided in this disclosure.

[0015] It should be noted that the elements in the attached diagram are schematic and not drawn to scale. Detailed Implementation

[0016] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are also within the scope of protection of this disclosure.

[0017] Unless otherwise defined, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this subject matter pertains. It will be further understood that terms such as those defined in commonly used dictionaries shall be interpreted as having the meaning consistent with their meaning in the context of the specification and in the relevant art, and shall not be interpreted in an idealized or overly formal form unless otherwise explicitly defined herein. As used herein, the statement of “connecting” or “coupling” two or more parts together shall mean that these parts are directly joined together or joined through one or more intermediate components.

[0018] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of the phrase "embodiment" in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0019] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists, A and B exist simultaneously, or B exists. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Terms such as "first" and "second" are only used to distinguish one component (or part of a component) from another component (or another part of a component).

[0020] In the description of this application, unless otherwise stated, "multiple" means two or more (including two), and similarly, "multiple groups" means two or more (including two groups).

[0021] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0022] Figure 1 This is a flowchart illustrating a product retrieval method based on permission configuration provided in an embodiment of this disclosure, such as... Figure 1 As shown, the specific process of the product retrieval method based on permission configuration includes: S110: Receive data query requests from users for preset product content.

[0023] The data query request includes, but is not limited to, the query user's identity information and keywords for the product content to be retrieved. Identity information is used to uniquely identify the query user, such as a unique identifier generated through a user account, employee ID, or mobile phone number. Product content keywords are the specific search criteria provided by the query user for the desired product content, such as product name, product model, functional features, and category.

[0024] S120. In response to the query user's data query request for preset product content, obtain the identity and permission fields corresponding to the query user.

[0025] The user's identity and permission fields can include: the user's role type, department information, data access level, and operation permissions for specific product categories. User role types include administrator, regular employee, external visitor, etc.; department information includes technical department, marketing department, finance department, etc.; data access levels include public, internal, confidential, etc.; and operation permissions for specific product categories include view-only, editable, downloadable, etc.

[0026] In some embodiments, obtaining the identity permission field corresponding to the query user includes: using the query user's identity identifier as the search keyword, traversing all identity identifier entries stored in the permission association table; if an identity identifier entry matching the query user's identity identifier is found, then the permission field corresponding to the identity identifier entry is extracted as the identity permission field corresponding to the query user; if no identity identifier entry matching the query user's identity identifier is found, then it is determined whether there is a group identity identifier that is associated with the query user's identity identifier; if so, then the permission field corresponding to the group identity identifier is extracted as the identity permission field corresponding to the query user; if not, then a preset permission field is used as the identity permission field corresponding to the query user.

[0027] The permission association table stores the mapping relationship between identity identifiers and permission fields. This mapping relationship can be pre-configured and dynamically updated by the system administrator according to the enterprise's organizational structure, business needs, and security policies.

[0028] Identity entries can be either a single, independent identity for a querying user, or a group identity for multiple users. The permission fields corresponding to a group identity can be basic permissions shared by all users within that group. For example, the identity of a department group could be associated with "internal data access level" and the operation permission "view only department product categories." When a querying user belongs to multiple related groups, the permission fields corresponding to the identity identifiers of each group can be merged according to a preset permission priority rule to obtain the identity permission fields corresponding to the querying user.

[0029] The preset permission fields are the basic permissions assigned by default, which may include the operation permissions of "public data access level" and "view only public product categories", so that query users who are not registered in the permission association table and have no associated groups can still obtain the minimum permission range that complies with security specifications.

[0030] In some embodiments, the method further includes: constructing a permission association table.

[0031] The permission association tables include: enterprise permission table, department permission table, internal dimension permission table, internal member permission table, external dimension permission table, and external member permission table.

[0032] Specifically, the enterprise permissions table is used to store enterprise-level permission configuration information and can be constructed in the following way.

[0033] --------------------------------------------------------------------- SQL CREATE TABLE `nebula_content_auth_corporation` ( `id` bigint PRIMARY KEY, `content_id` bigint NOT NULL, `corporation_id` bigint NOT NULL, KEY `idx_content_id` (`content_id`) ); --------------------------------------------------------------------- The department permission table is used to store the permission configuration information of each department under the enterprise, and can be constructed in the following way.

[0034] --------------------------------------------------------------------- SQL CREATE TABLE `nebula_content_auth_dept` ( `id` bigint PRIMARY KEY, `content_id` bigint NOT NULL, `dept_id` bigint NOT NULL, KEY `idx_content_id` (`content_id`) ); --------------------------------------------------------------------- The internal dimension permission table is used to store permission configuration information for different business dimensions within an enterprise, and can be constructed in the following way.

[0035] -------------------------------------------------------------------- SQL CREATE TABLE `nebula_content_auth_inner_dimension` ( `id` bigint PRIMARY KEY, `content_id` bigint NOT NULL, `dimension_id` bigint NOT NULL, KEY `idx_content_id` (`content_id`) ); --------------------------------------------------------------------- The internal member permission table is used to store the permission configuration information of individual employees within the enterprise, and can be constructed in the following way.

[0036] -------------------------------------------------------------------- SQL CREATE TABLE `nebula_content_auth_inner_member` ( `id` bigint PRIMARY KEY, `content_id` bigint NOT NULL, `member_id` bigint NOT NULL, KEY `idx_content_id` (`content_id`) ); --------------------------------------------------------------------- The external dimension permission table is used to store permission configuration information for different business dimensions outside the enterprise, and can be constructed in the following way.

[0037] -------------------------------------------------------------------- SQL CREATE TABLE `nebula_content_auth_outer_dimension` ( `id` bigint PRIMARY KEY, `content_id` bigint NOT NULL, `dimension_id` bigint NOT NULL, KEY `idx_content_id` (`content_id`) ); --------------------------------------------------------------------- The external member permission table is used to store the permission configuration information of individual external employees of the enterprise, and can be constructed in the following way.

[0038] -------------------------------------------------------------------- SQL CREATE TABLE `nebula_content_auth_outer_member` ( `id` bigint PRIMARY KEY, `content_id` bigint NOT NULL, `member_id` bigint NOT NULL, KEY `idx_content_id` (`content_id`) ); --------------------------------------------------------------------- S130. Parse the specific permission parameters included in the identity permission field corresponding to the query user to obtain the user permission parameters.

[0039] The user permission parameters may include: numeric level identifier, data area identifier, category identifier, and operation code set.

[0040] Numerical level identifiers quantify the overall permission level of a querying user within the product retrieval system. Different numbers correspond to different permission ranges and depths; higher numbers indicate a wider range of product data the querying user can access and manipulate, and a higher permission level. Data region identifiers describe the geographical or business area to which the querying user is authorized to retrieve product data. For example, it can specify that a querying user can only access product data within the coverage area of ​​a specific province, business line, or data center. Category identifiers define the specific category or classification of products that a querying user can retrieve. This identifier allows for vertical permission division of products, ensuring that the querying user can only retrieve specific product categories within their permission range. The operation code set is a series of codes representing specific operation permissions. Each operation code corresponds to a specific product retrieval-related operation, such as query, filter, sort, export, view details, add to favorites, etc. The querying user's operation permissions are strictly determined based on the operation codes contained in this code set; the querying user is only allowed to perform the corresponding operation when the corresponding operation code exists in the set.

[0041] In some embodiments, parsing the specific permission parameters included in the identity permission field corresponding to the query user to obtain the user permission parameters includes: performing structured parsing on the identity permission field to extract the permission level parameter, data access scope parameter, product category permission parameter, and operation permission parameter contained in the identity permission field; converting the permission level parameter into a corresponding numeric level identifier; converting the data access scope parameter into a corresponding data area identifier; mapping the product category permission parameter to a category identifier in the product category table of the product database; mapping the operation permission parameter to a corresponding set of operation codes, whereby the operation codes describe the permissions for query operations, view details operations, edit operations, and export operations; and determining the user permission parameters based on the corresponding numeric level identifier, data area identifier, category identifier, and set of operation codes.

[0042] The permission level parameter can be used to define the overall permission hierarchy of query users in the product retrieval system. Data access scope parameters may include geographic region codes, business line numbers, or data center identifiers. Product category permission parameters correspond to the hierarchical structure of the product category table in the product database; by mapping them to category identifiers, vertical domain segmentation of product data can be achieved. Operation permission parameters can be converted into a set of operation codes through preset mapping relationships. Each operation code corresponds to a specific product retrieval-related operation, such as "X001" for query operation, "X002" for viewing details operation, "X003" for editing operation, and "X004" for export operation, etc.

[0043] Therefore, by structurally decomposing identity and permission fields and accurately mapping multi-dimensional parameters, the previously ambiguous and unstructured permission descriptions can be transformed into digital permission parameters that can be directly identified and executed, ensuring the accuracy and efficiency of the permission parsing process.

[0044] In addition, to improve data query performance, the identity and permission fields of the querying user can be redundantly added to Elasticsearch (redundant permission fields) in the following way.

[0045] -------------------------------------------------------------------- JSON {"id": 123,"libraryType": "product_cloud","name": "iPhone 15 Pro", / / Permission fields (redundant)"importance": 6,"visibleRange": 2,"outVisibleRange": 4,"createUser": 1001,"deptId": 10, / / List of permission IDs (redundant, array format for easy term lookup)"adminUserIdList": [1001, 1002, 1003],"belongMemberIdList": [2001, 2002],"belongOutMemberIdList": [3001, 3002],"deptAuthIdList": [10, 11],"dimensionAuthIdList": [20, 21],"outDimensionAuthIdList": [30, 31], / / Other fields...} --------------------------------------------------------------------- S140. By performing relational mapping on user permission parameters through preset permission-filter mapping relationship, data filtering conditions are obtained for querying user corresponding to product content in the product database.

[0046] The preset permission-filter mapping relationship can be a mapping relationship between numerical level identifiers, data area identifiers, category identifiers and operation code sets.

[0047] In some embodiments, a preset permission-filtering mapping relationship is used to map user permission parameters to obtain data filtering conditions for the query user corresponding to product content in the product database. This includes: mapping numeric level identifiers to filtering rules for the query user's sensitivity to product data; matching data region identifiers with region attribute fields stored in the product database to obtain filtering rules for the query user's product data affiliation; associating category identifiers with the product classification table to obtain the range of product categories that the query user can retrieve; converting each operation code in the operation code set into filtering rules for the query user's data operation permissions; and integrating the filtering rules for the query user's sensitivity to product data, the filtering rules for product data affiliation, the range of retrieval product categories, and the filtering rules for data operation permissions to obtain data filtering conditions for the query user corresponding to product content in the product database.

[0048] Specifically, if the numeric level identifier is level 1, it corresponds to a filtering rule that allows the retrieval of all non-sensitive and low-sensitivity product data; if the numeric level identifier is level 2, it corresponds to a filtering rule that only allows the retrieval of non-sensitive product data.

[0049] You can use either exact match or fuzzy match to match a data region identifier with a region attribute field stored in the product database. In exact match, the data region identifier and the region attribute field must be completely identical for a match to be considered successful. In fuzzy match, a match is considered successful if the data region identifier is contained within the region attribute field content, or if the region attribute field content contains the data region identifier.

[0050] The operation codes in the operation code set correspond one-to-one with the filtering rules for data operation permissions. For example, the operation code "VIEW" corresponds to the filtering rule that allows viewing product data; the operation code "EDIT" corresponds to the filtering rule that allows editing product data; and the operation code "DELETE" corresponds to the filtering rule that allows deleting product data. When the operation code set contains multiple operation codes, the resulting filtering rules are the union of multiple operation permissions.

[0051] When integrating the filtering rules for product data sensitivity, product data attribution, searchable product category range, and data operation permissions for query users, the various filtering rules can be logically combined, such as by using a logical "AND" method. That is, the final data filtering conditions for query users must simultaneously meet the filtering rules for product data sensitivity, product data attribution, searchable product category range, and data operation permissions.

[0052] This ensures that users can only perform operations on product data within their authorized scope, effectively avoiding the risk of unauthorized data access or operations due to improper permission configuration.

[0053] S150. Based on the data filtering conditions corresponding to the querying user, determine the target product content to be displayed to the querying user from the product database; the target product content includes: preset product content, or preset product content and other product content, or other product content.

[0054] The data filtering conditions for querying users can be as follows: (Filtering rules for product data sensitivity) ∩ (Filtering rules for product data affiliation) ∩ (Filtering rules for searchable product category range) ∩ (Filtering rules for data operation permissions). That is, only when a piece of product data simultaneously meets the filtering rules of all four dimensions will it be included in the target product content filtering scope.

[0055] This embodiment designs seven levels of permission scopes for the product content stored in the product database: universal for all employees, personal control, departmental privacy, personal management, visible to all employees within / outside the enterprise, custom permissions, and departmental control. The permission scope description table is shown in Table 1.

[0056] Table 1. Description of Permission Scope

[0057] In some embodiments, the target product content to be displayed to the querying user is determined from the product database based on the data filtering conditions corresponding to the querying user. This includes: determining highly sensitive product data that the querying user cannot access based on filtering rules corresponding to the sensitivity of product data; determining product data that matches the querying user based on filtering rules corresponding to the product data affiliation of the querying user; determining product entries belonging to the corresponding category range based on the searchable product category range corresponding to the querying user; determining the specific operation functions that the querying user can perform based on filtering rules corresponding to the data operation permissions of the querying user; and filtering the target product content to be displayed to the querying user from the product database based on the highly sensitive product data that the querying user cannot access, the product data that matches the querying user, the product entries within the corresponding category range, and the specific operation functions that the querying user can perform.

[0058] The highly sensitive product data that the querying user cannot access includes highly confidential content in the product database, such as core technical parameters, trade secrets, undisclosed R&D information, and customer privacy data. Product data matching the querying user refers to product information directly related to the user's department, business area, responsible projects, or customer group. Product entries within the corresponding category are product sets limited by product categories, model series, or application scenarios that the querying user is pre-authorized to search in the system. The specific operations that the querying user can perform are determined by the data operation permission level assigned to the user in the system, specifying the types of operations that can be performed on the filtered target product content, such as viewing basic product information, downloading product specification documents, editing non-core product parameters, exporting product statistical reports, and submitting product inquiry requests.

[0059] Therefore, through a multi-dimensional and refined permission filtering mechanism, it is possible to accurately locate target content that meets the query user's permissions from the massive data in the product database; at the same time, by clarifying the executable operation functions, the principle of "least privilege" for data access can be effectively implemented, thereby improving the security and controllability of product data management.

[0060] In some embodiments, the method further includes: real-time monitoring of the user's access and operation behavior on the target product content; if abnormal access or operation behavior of the user is detected, an access warning is generated.

[0061] Specifically, if abnormal behavior is detected, such as the frequency of accesses exceeding a preset threshold within a unit of time, an abnormal number of consecutive operations on the same product content, or the execution of operation commands outside the scope of permissions, the access or operation behavior of the querying user can be determined to be abnormal. When abnormal access or operation behavior of the querying user is detected, the permission warning mechanism can be triggered immediately. Permission warning prompts can be sent to the administrator through system pop-ups, email notifications, SMS alerts, etc., so that the administrator can intervene in time to verify and prevent data risks caused by data leakage or improper operation.

[0062] In this embodiment, a data query request for preset product content is received from a user; in response to the user's request, the user's identity and permission fields are obtained; the specific permission parameters included in the user's identity and permission fields are parsed to obtain user permission parameters; the user permission parameters are mapped using a preset permission-filtering mapping relationship to obtain data filtering conditions for the product content in the product database corresponding to the user; based on the data filtering conditions for the user, the target product content to be displayed to the user is determined from the product database; the target product content includes: preset product content, or preset product content and other product content, or other product content. Thus, by generating data filtering rules tailored to the user through a pre-established mapping relationship, precise filtering of product content is achieved during product retrieval, ensuring that the user can only obtain target product content matching their permissions, effectively improving data retrieval efficiency.

[0063] In addition, this embodiment also provides a product retrieval system based on permission configuration, including: a permission scope module, an internal / external separation module, a permission storage module, a permission redundancy module, and a permission filtering module. The permission scope module defines seven levels of permission scope, including enterprise-wide, individual control, department-private, individual management, internal / external all-employees, custom, and department control. The internal / external separation module defines internal and external visibility scopes respectively. The permission storage module includes six permission association tables to store multi-dimensional permission relationships such as enterprise, department, dimension, and member. The permission redundancy module redundantly adds permission-related fields to the ES index to improve query performance. The permission filtering module dynamically constructs permission filtering conditions during ES queries to achieve efficient permission control. This embodiment supports seven permission scopes, internal / external permission separation, and multi-level authorization at the enterprise, department, dimension, and member levels, offering high flexibility. Permission judgment is completed at the ES query layer, avoiding secondary filtering at the application layer, with a query response time of <100ms and high system performance. It supports adding new permission dimensions (such as roles and tags), and permission configuration supports library-level customization, offering strong scalability.

[0064] Figure 2This embodiment provides a schematic diagram of a product retrieval device based on permission configuration. The product retrieval device based on permission configuration may include: The receiving module 210 is used to receive data query requests from users for preset product content.

[0065] The acquisition module 220 is used to respond to the data query request of the query user for the preset product content and obtain the identity and permission fields corresponding to the query user.

[0066] The parsing module 230 is used to parse the specific permission parameters included in the identity permission field corresponding to the query user to obtain the user permission parameters.

[0067] The mapping module 240 is used to perform relational mapping on user permission parameters through a preset permission-filter mapping relationship, so as to obtain the data filtering conditions for querying user corresponding to product content in the product database.

[0068] The determination module 250 is used to determine the target product content to be displayed to the querying user from the product database based on the data filtering conditions corresponding to the querying user; the target product content includes: preset product content, or preset product content and other product content, or other product content.

[0069] In this embodiment, optionally, the parsing module 230 is specifically used for: The identity and permission fields are parsed in a structured manner to extract the permission level parameters, data access scope parameters, product category permission parameters, and operation permission parameters contained therein. The permission level parameters are converted into corresponding numeric level identifiers; the data access scope parameters are converted into corresponding data area identifiers; the product category permission parameters are mapped to category identifiers in the product category table of the product database; and the operation permission parameters are mapped to corresponding sets of operation codes, which describe the permissions for query operations, view details operations, edit operations, and export operations. Based on the corresponding numeric level identifiers, data area identifiers, category identifiers, and operation code sets, the user permission parameters are determined.

[0070] In this embodiment, optionally, the mapping module 240 is specifically used for: The process involves mapping numerical level identifiers to filtering rules corresponding to the sensitivity of product data for query users; matching data region identifiers with region attribute fields stored in the product database to obtain filtering rules corresponding to the product data affiliation of query users; associating category identifiers with the product classification table to obtain the range of product categories that query users can retrieve; converting each operation code in the operation code set into filtering rules corresponding to the data operation permissions of query users; and integrating the filtering rules corresponding to the sensitivity of product data, the filtering rules for product data affiliation, the range of searchable product categories, and the filtering rules for data operation permissions to obtain the data filtering conditions for the product content in the product database corresponding to the query users.

[0071] In this embodiment, optionally, the determining module 250 is specifically used for: Based on the filtering rules corresponding to the sensitivity of product data for the querying user, highly sensitive product data that the querying user cannot access is identified; based on the filtering rules corresponding to the product data affiliation for the querying user, product data matching the querying user is identified; based on the querying user's corresponding searchable product category range, product entries belonging to the corresponding category range are identified; based on the filtering rules corresponding to the querying user's data operation permissions, the specific operation functions that the querying user can perform are identified; based on the highly sensitive product data that the querying user cannot access, the product data matching the querying user, the product entries within the corresponding category range, and the specific operation functions that the querying user can perform, the target product content to be displayed to the querying user is filtered from the product database.

[0072] In this embodiment, optionally, the acquisition module 220 is specifically used for: Using the user's identity identifier as the search keyword, the system iterates through all identity identifier entries stored in the permission association table. If an identity identifier entry matching the user's identity identifier is found, the permission field corresponding to that entry is extracted as the user's corresponding permission field. If no matching entry is found, the system checks if a group identity identifier is associated with the user's identity identifier. If so, the permission field corresponding to that group identity identifier is extracted as the user's corresponding permission field. If not, a preset permission field is used as the user's corresponding permission field.

[0073] In this embodiment, optionally, a building module is also included.

[0074] The module is used to build permission association tables. These tables include: an enterprise permission table, a department permission table, an internal dimension permission table, an internal member permission table, an external dimension permission table, and an external member permission table. The enterprise permission table stores enterprise-level permission configuration information; the department permission table stores permission configuration information for each department within the enterprise; the internal dimension permission table stores permission configuration information for different business dimensions within the enterprise; the internal member permission table stores permission configuration information for individual employees within the enterprise; the external dimension permission table stores permission configuration information for different business dimensions outside the enterprise; and the external member permission table stores permission configuration information for individual employees outside the enterprise.

[0075] In this embodiment, optionally, a monitoring module may also be included.

[0076] The monitoring module is used to monitor the access and operation behavior of query users on the target product content in real time; if abnormal access or operation behavior of query users is detected, an access warning will be generated.

[0077] The product retrieval device based on permission configuration provided in this disclosure can execute the above method embodiments. Its specific implementation principle and technical effects can be found in the above method embodiments, and will not be repeated here.

[0078] This application also provides a computer device. Please refer to the following for details. Figure 3 , Figure 3 This is a basic structural block diagram of the computer device in this embodiment.

[0079] The computer device includes a memory 310 and a processor 320 that are interconnected via a system bus. It should be noted that only a computer device with memory 310 and processor 320 is shown in the figure; however, it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented alternatively. Those skilled in the art will understand that the computer device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0080] Computer devices can include desktop computers, laptops, handheld computers, and cloud servers. These devices allow for human-computer interaction with users through methods such as keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0081] The memory 310 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. RAM may include static RAM or dynamic RAM. In some embodiments, the memory 310 may be an internal storage unit of a computer device, such as the hard disk or memory of the computer device. In other embodiments, the memory 310 may also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, or flash card equipped on the computer device. Of course, the memory 310 may include both internal storage units and external storage devices of the computer device. In this embodiment, the memory 310 is typically used to store the operating system and various application software installed on the computer device, such as the program code of the method described above. In addition, the memory 310 can also be used to temporarily store various types of data that have been output or will be output.

[0082] Processor 320 is typically used to perform overall operations of a computer device. In this embodiment, memory 310 is used to store program code or instructions, including computer operation instructions, and processor 320 is used to execute the program code or instructions stored in memory 310 or process data, such as program code that runs the methods described above.

[0083] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus system can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0084] Another embodiment of this application also provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads computer-readable program code stored in the computer-readable medium, enabling the processor to execute the functional actions specified in each step or combination of steps in the above method; and to generate means for implementing the functional actions specified in each block or combination of blocks in the block diagram.

[0085] Computer-readable media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any suitable combination thereof, wherein the memory is used to store program code or instructions, the program code including computer operation instructions, and the processor is used to execute the program code or instructions of the above-described methods stored in the memory.

[0086] The definitions of memory and processor can be found in the description of the foregoing computer device embodiments, and will not be repeated here.

[0087] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0088] In the various embodiments of this application, the functional units or modules can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0089] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0090] In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" as described in this application does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. This application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims listing several means, several units of these means may be embodied by the same item of hardware. The use of "first," "second," and "third," etc., does not indicate any order and these words should be interpreted as names. Unless otherwise specified, the steps in the above embodiments should not be construed as limiting the order of execution.

[0091] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A product retrieval method based on permission configuration, characterized in that, include: Receive data query requests from users for preset product content; In response to the query user's data query request for the preset product content, obtain the identity and permission fields corresponding to the query user; Parse the specific permission parameters included in the identity permission field corresponding to the queried user to obtain the user permission parameters; By performing a relational mapping on the user permission parameters through a preset permission-filter mapping relationship, the data filtering conditions corresponding to the product content in the product database for the querying user are obtained. Based on the data filtering conditions corresponding to the querying user, determine the target product content to be displayed to the querying user from the product database; The target product content includes: the preset product content, or the preset product content and other product content, or the other product content.

2. The method according to claim 1, characterized in that, The user permission parameters are obtained by parsing the identity permission fields corresponding to the queried user, including: The identity and permission fields are parsed in a structured manner to extract the permission level parameters, data access scope parameters, product category permission parameters, and operation permission parameters contained in the identity and permission fields. The permission level parameter is converted into a corresponding numeric level identifier; the data access range parameter is converted into a corresponding data area identifier; the product category permission parameter is mapped to the category identifier of the product classification table in the product database; The operation permission parameters are mapped to a corresponding set of operation codes, which are used to describe the permissions of query operation, view details operation, edit operation, and export operation. User permission parameters are determined based on the corresponding numerical level identifier, data area identifier, category identifier, and operation code set.

3. The method according to claim 2, characterized in that, By mapping the user permission parameters according to a preset permission-filtering mapping relationship, the data filtering conditions corresponding to the product content in the product database for the querying user are obtained, including: Map the numerical level identifier to the filtering rules corresponding to the product data sensitivity of the querying user; Match the data region identifier with the region attribute field stored in the product database to obtain the filtering rules for the product data belonging to the query user; The category identifier is associated and matched with the product classification table to obtain the range of product categories that the querying user can retrieve; Each operation code in the operation code set is converted into a filtering rule corresponding to the data operation permissions of the querying user; By integrating the filtering rules for the sensitivity of the query user to the product data, the filtering rules for the product data attribution, the filtering rules for the searchable product category range, and the filtering rules for the data operation permissions, the data filtering conditions for the query user to the product content in the product database are obtained.

4. The method according to claim 3, characterized in that, Based on the data filtering conditions corresponding to the querying user, the target product content to be displayed to the querying user is determined from the product database, including: Based on the filtering rules corresponding to the sensitivity of the product data for the querying user, determine the highly sensitive product data that the querying user cannot access; Based on the filtering rules that correspond to the product data belonging to the querying user, determine the product data that matches the querying user; Based on the query user's corresponding searchable product category range, determine the product entries belonging to the corresponding category range; Based on the filtering rules corresponding to the data operation permissions of the querying user, determine the specific operation functions that the querying user can perform; Based on the highly sensitive product data that the querying user cannot access, the product data that matches the querying user, the product entries within the corresponding category range, and the specific operation functions that the querying user can perform, the target product content to be displayed to the querying user is filtered from the product database.

5. The method according to claim 1, characterized in that, Retrieving the identity and permission fields corresponding to the queried user includes: Using the identity identifier of the querying user as the search keyword, traverse all identity identifier entries stored in the permission association table; If an identity identifier entry matching the identity identifier of the querying user is found, the permission field corresponding to the identity identifier entry is extracted as the identity permission field corresponding to the querying user; If no identity identifier entry matching the identity identifier of the querying user is found, it is determined whether there is a group identity identifier that is associated with the identity identifier of the querying user; if there is, the permission field corresponding to the group identity identifier is extracted as the identity permission field corresponding to the querying user; if there is no such field, a preset permission field is used as the identity permission field corresponding to the querying user.

6. The method according to claim 5, characterized in that, Also includes: Build a permission association table; The permission association tables include: an enterprise permission table, a department permission table, an internal dimension permission table, an internal member permission table, an external dimension permission table, and an external member permission table. The enterprise permission table stores enterprise-level permission configuration information. The department permission table stores permission configuration information for each department within the enterprise. The internal dimension permission table stores permission configuration information for different business dimensions within the enterprise. The internal member permission table stores permission configuration information for individual employees within the enterprise. The external dimension permission table stores permission configuration information for different business dimensions outside the enterprise. The external member permission table stores permission configuration information for individual employees outside the enterprise.

7. The method according to claim 1, characterized in that, Also includes: Real-time monitoring of the user's access and operation behavior regarding the target product content; If abnormal access or operation behavior of the querying user is detected, an access warning will be generated.

8. A product retrieval device based on permission configuration, characterized in that, include: The receiving module is used to receive data query requests from users for preset product content; The acquisition module is used to respond to the data query request of the querying user for the preset product content and acquire the identity and permission fields corresponding to the querying user; The parsing module is used to parse the specific permission parameters included in the identity permission field corresponding to the queried user to obtain the user permission parameters; The mapping module is used to perform relational mapping on the user permission parameters through a preset permission-filter mapping relationship, so as to obtain the data filtering conditions of the query user corresponding to the product content in the product database; The determining module is used to determine, from the product database, the target product content to be displayed to the querying user based on the data filtering conditions corresponding to the querying user; The target product content includes: the preset product content, or the preset product content and other product content, or the other product content.

9. A computer device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the product retrieval method based on permission configuration as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When a computer program is executed by a processor, it implements the product retrieval method based on permission configuration as described in any one of claims 1 to 7.