2011-09-21 37 views

回答

40

Oracle數據庫中的用戶只擁有您授予的權限。所以你可以通過不授予任何其他特權來創建一個只讀用戶。

當你創建一個用戶

CREATE USER ro_user 
IDENTIFIED BY ro_user 
DEFAULT TABLESPACE users 
TEMPORARY TABLESPACE temp; 

用戶甚至不必登錄到數據庫的權限。你可以授予,

GRANT CREATE SESSION to ro_user 

然後你可以去授予你想要的任何閱讀權限。例如,如果你想RO_USER能夠查詢SCHEMA_NAME.TABLE_NAME,你會做這樣的事情

GRANT SELECT ON schema_name.table_name TO ro_user 

一般情況下,最好創建一個角色,然而,授予對象權限的作用,使你然後可以將角色授予不同的用戶。像

東西創建角色

CREATE ROLE ro_role; 

授予對每個表選擇角色的訪問在特定模式

BEGIN 
    FOR x IN (SELECT * FROM dba_tables WHERE owner='SCHEMA_NAME') 
    LOOP 
    EXECUTE IMMEDIATE 'GRANT SELECT ON schema_name.' || x.table_name || 
            ' TO ro_role'; 
    END LOOP; 
END; 

然後授予角色給用戶

GRANT ro_role TO ro_user; 
8
create user ro_role identified by ro_role; 
grant create session, select any table, select any dictionary to ro_role; 
-1

它是n由於每個用戶通過公開自動獲得的許多公共執行,所以在默認數據庫中絕對是可能的。

1

以用戶系統爲例,執行以下步驟。

將p_owner設置爲架構所有者,將p_readonly設置爲只讀用戶的名稱。

create or replace 
procedure createReadOnlyUser(p_owner in varchar2, p_readonly in varchar2) 
AUTHID CURRENT_USER is 
BEGIN 
    execute immediate 'create user '||p_readonly||' identified by '||p_readonly; 
    execute immediate 'grant create session to '||p_readonly; 
    execute immediate 'grant select any dictionary to '||p_readonly; 
    execute immediate 'grant create synonym to '||p_readonly; 

    FOR R IN (SELECT owner, object_name from all_objects where object_type in('TABLE', 'VIEW') and owner=p_owner) LOOP 
     execute immediate 'grant select on '||p_owner||'.'||R.object_name||' to '||p_readonly; 
    END LOOP; 
    FOR R IN (SELECT owner, object_name from all_objects where object_type in('FUNCTION', 'PROCEDURE') and owner=p_owner) LOOP 
     execute immediate 'grant execute on '||p_owner||'.'||R.object_name||' to '||p_readonly; 
    END LOOP; 
    FOR R IN (SELECT owner, object_name FROM all_objects WHERE object_type in('TABLE', 'VIEW') and owner=p_owner) LOOP 
     EXECUTE IMMEDIATE 'create synonym '||p_readonly||'.'||R.object_name||' for '||R.owner||'."'||R.object_name||'"'; 
    END LOOP; 
    FOR R IN (SELECT owner, object_name from all_objects where object_type in('FUNCTION', 'PROCEDURE') and owner=p_owner) LOOP 
     execute immediate 'create synonym '||p_readonly||'.'||R.object_name||' for '||R.owner||'."'||R.object_name||'"'; 
    END LOOP; 
END; 
0

您可以創建用戶並授予特權

創建用戶通過READ_ONLY READ_ONLY鑑定; 授予創建會話,選擇任何表來read_only;