Solved

Oracle read only user

Posted on 2016-10-17
7
46 Views
Last Modified: 2016-11-05
I need to create database user that should be able to view all the database objects - tables, procedures, packages, functions and triggers.

I can say - grant select any table to user. How do I go about doing this for the other objects.
0
Comment
Question by:happylife1234
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
7 Comments
 
LVL 74

Accepted Solution

by:
sdstuber earned 250 total points (awarded by participants)
ID: 41847210
select any table  -  this will apply to non-sys owned  tables and views

select any dictionary - this will apply to sys owned tables and views.  

For 12c it does NOT include SYS.USER$ (and others), you will need to grant select on that directly, but there is usually no need to do that and is not recommended.


for procedures, pacakges, functions and triggers I assume you mean you want to view the source.
with select any dictionary you can read dba_source for all of those


if you are trying to read the code by behind wrapped objects, you can't.  There is no privilege that allows that, not even SYS has that authority.
0
 

Author Comment

by:happylife1234
ID: 41847212
Thanks LVL73. If you grant select any dictionary, can I go and view the package body from Packagaes in sql developer or can I only view them from the dba_source table .
0
 
LVL 74

Assisted Solution

by:sdstuber
sdstuber earned 250 total points (awarded by participants)
ID: 41847218
lvl73 isn't a name, it's a counter (sort of)   indicating the amount of time spent on EE answering questions.

but, I assume you meant me,  sdstuber

sql developer uses the ALL_* views,  but if you have select any dictionary, that should make ALL_* act pretty much like DBA_* (except a little heavier because the ALL_* views are doing extra work to confirm permissions)
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 77

Assisted Solution

by:slightwv (䄆 Netminder)
slightwv (䄆 Netminder) earned 250 total points (awarded by participants)
ID: 41847227
Yes, "select ANY" will get you what you need but it will probably also get you a whole lot more.

You should really follow good security practices:
https://en.wikipedia.org/wiki/Principle_of_least_privilege

Select any dictionary and table can be a security issue.  It doesn't limit what the user can see.

If you want them to see absolutely everything in the database in every schema, even the sys and system schemas, then grant them.
0
 
LVL 74

Assisted Solution

by:sdstuber
sdstuber earned 250 total points (awarded by participants)
ID: 41847232
what is your db version?

if it's 12.1.0.2 or higher you should probably use "read any table"  instead of "select any table"

the select privilege implicitly allows you to lock objects even if you can't update/insert/delete on them.

It's as simple as "select * from some_table for update"

even if you don't have update privilege, the select grant allows you to do that and that query would lock every row in the table.

if you have "read any table" privilege, you can't do that
1
 
LVL 74

Expert Comment

by:sdstuber
ID: 41847234
you can also explicitly issue LOCK TABLE statements with the select privilege, the READ privilege does not allow that.

again, the READ privilge for tables and views only applies to 12.1.0.2 and higher.
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Working with Network Access Control Lists in Oracle 11g (part 1) Part 2: http://www.e-e.com/A_9074.html So, you upgraded to a shiny new 11g database and all of a sudden every program that used UTL_MAIL, UTL_SMTP, UTL_TCP, UTL_HTTP or any oth…
Background In several of the companies I have worked for, I noticed that corporate reporting is off loaded from the production database and done mainly on a clone database which needs to be kept up to date daily by various means, be it a logical…
This video shows how to recover a database from a user managed backup
This video shows how to configure and send email from and Oracle database using both UTL_SMTP and UTL_MAIL, as well as comparing UTL_SMTP to a manual SMTP conversation with a mail server.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question