Oracle数据库存储过程与权限
来源:易贤网 阅读:2912 次 日期:2014-09-17 10:17:34
温馨提示:易贤网小编为您整理了“Oracle数据库存储过程与权限”,方便广大网友查阅!

在执行存储过程时,我们可能会遇到权限问题

● 定义者权限存储过程

● 调用者权限存储过程

在数据库中创建存储过程时,定义者权限是缺省模式

当指定AUTHID CURRENT_USER关键字后,便是调用者权限存储过程

他俩之间最根本的差异在于role能否在存储过程中生效

㈠ 定义者权限存储过程问题

定义者权限存储过程role无效,必须要有显式授权

即便是拥有dba role,还是不能访问不同用户的表

> grant connect,resource to u1 identified by u1;

Grant succeeded.

> grant dba to u2 identified by u2;

Grant succeeded.

> conn u1/u1

Connected.

> create table t as select * from user_objects;

Table created.

> conn u2/u2

Connected.

> create or replace procedure p_test

2 as

3 begin

4 delete from u1.t;

5 commit;

6 end;

7 /

Warning: Procedure created with compilation errors.

> show error;

Errors for PROCEDURE P_TEST:

LINE/COL ERROR

-------- -----------------------------------------------------------------

4/3 PL/SQL: SQL Statement ignored

4/18 PL/SQL: ORA-00942: table or view does not exist

> conn u1/u1

Connected.

> grant all on t to u2;

Grant succeeded.

> conn u2/u2

Connected.

> create or replace procedure p_test

2 as

3 begin

4 delete from u1.t;

5 commit;

6 end;

7 /

Procedure created.

㈡ 调用者权限存储过程问题

调用者权限存储过程role编译不可见,但运行时可见

用动态SQL避免直接授权,而将权限的检查延后至运行时

> conn u1/u1

Connected.

> revoke all on t from u2;

Revoke succeeded.

> conn u2/u2

Connected.

> create or replace procedure p_test

2 authid current_user

3 as

4 begin

5 delete from u1.t;

6 commit;

7 end;

8 /

Warning: Procedure created with compilation errors.

> show error;

Errors for PROCEDURE P_TEST:

LINE/COL ERROR

-------- -----------------------------------------------------------------

5/3 PL/SQL: SQL Statement ignored

5/18 PL/SQL: ORA-00942: table or view does not exist

> create or replace procedure p_test

2 authid current_user

3 as

4 begin

5 execute immediate

6 'delete from u1.t';

7 commit;

8 end;

9 /

Procedure created.

> exec p_test;

PL/SQL procedure successfully completed.

> select count(*) from u1.t;

COUNT(*)

----------

0

更多信息请查看IT技术专栏

更多信息请查看数据库
易贤网手机网站地址:Oracle数据库存储过程与权限
由于各方面情况的不断调整与变化,易贤网提供的所有考试信息和咨询回复仅供参考,敬请考生以权威部门公布的正式信息和咨询为准!
关于我们 | 联系我们 | 人才招聘 | 网站声明 | 网站帮助 | 非正式的简要咨询 | 简要咨询须知 | 加入群交流 | 手机站点 | 投诉建议
工业和信息化部备案号:滇ICP备2023014141号-1 云南省教育厅备案号:云教ICP备0901021 滇公网安备53010202001879号 人力资源服务许可证:(云)人服证字(2023)第0102001523号
云南网警备案专用图标
联系电话:0871-65317125(9:00—18:00) 获取招聘考试信息及咨询关注公众号:hfpxwx
咨询QQ:526150442(9:00—18:00)版权所有:易贤网
云南网警报警专用图标