Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Oracle read only user

Posted on 2016-10-17
7
Medium Priority
?
63 Views
Last Modified: 2016-11-05
I need to create database user that should be able to view all the database objects - tables, procedures, packages, functions and triggers.

I can say - grant select any table to user. How do I go about doing this for the other objects.
0
Comment
Question by:happylife1234
  • 4
6 Comments
 
LVL 74

Accepted Solution

by:
sdstuber earned 1000 total points (awarded by participants)
ID: 41847210
select any table  -  this will apply to non-sys owned  tables and views

select any dictionary - this will apply to sys owned tables and views.  

For 12c it does NOT include SYS.USER$ (and others), you will need to grant select on that directly, but there is usually no need to do that and is not recommended.


for procedures, pacakges, functions and triggers I assume you mean you want to view the source.
with select any dictionary you can read dba_source for all of those


if you are trying to read the code by behind wrapped objects, you can't.  There is no privilege that allows that, not even SYS has that authority.
0
 

Author Comment

by:happylife1234
ID: 41847212
Thanks LVL73. If you grant select any dictionary, can I go and view the package body from Packagaes in sql developer or can I only view them from the dba_source table .
0
 
LVL 74

Assisted Solution

by:sdstuber
sdstuber earned 1000 total points (awarded by participants)
ID: 41847218
lvl73 isn't a name, it's a counter (sort of)   indicating the amount of time spent on EE answering questions.

but, I assume you meant me,  sdstuber

sql developer uses the ALL_* views,  but if you have select any dictionary, that should make ALL_* act pretty much like DBA_* (except a little heavier because the ALL_* views are doing extra work to confirm permissions)
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 78

Assisted Solution

by:slightwv (䄆 Netminder)
slightwv (䄆 Netminder) earned 1000 total points (awarded by participants)
ID: 41847227
Yes, "select ANY" will get you what you need but it will probably also get you a whole lot more.

You should really follow good security practices:
https://en.wikipedia.org/wiki/Principle_of_least_privilege

Select any dictionary and table can be a security issue.  It doesn't limit what the user can see.

If you want them to see absolutely everything in the database in every schema, even the sys and system schemas, then grant them.
0
 
LVL 74

Assisted Solution

by:sdstuber
sdstuber earned 1000 total points (awarded by participants)
ID: 41847232
what is your db version?

if it's 12.1.0.2 or higher you should probably use "read any table"  instead of "select any table"

the select privilege implicitly allows you to lock objects even if you can't update/insert/delete on them.

It's as simple as "select * from some_table for update"

even if you don't have update privilege, the select grant allows you to do that and that query would lock every row in the table.

if you have "read any table" privilege, you can't do that
1
 
LVL 74

Expert Comment

by:sdstuber
ID: 41847234
you can also explicitly issue LOCK TABLE statements with the select privilege, the READ privilege does not allow that.

again, the READ privilge for tables and views only applies to 12.1.0.2 and higher.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Working with Network Access Control Lists in Oracle 11g (part 1) Part 2: http://www.e-e.com/A_9074.html So, you upgraded to a shiny new 11g database and all of a sudden every program that used UTL_MAIL, UTL_SMTP, UTL_TCP, UTL_HTTP or any oth…
Note: this article covers simple compression. Oracle introduced in version 11g release 2 a new feature called Advanced Compression which is not covered here. General principle of Oracle compression Oracle compression is a way of reducing the d…
This video shows information on the Oracle Data Dictionary, starting with the Oracle documentation, explaining the different types of Data Dictionary views available by group and permissions as well as giving examples on how to retrieve data from th…
This video shows how to copy an entire tablespace from one database to another database using Transportable Tablespace functionality.

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question