oracle创建最小查询权限用户
方法一: SQL> create user user1 identified by oracle; User created. SQL> grant connect to user1; Grant succeeded. SQL> grant select any table to user1; Grant succeeded. SQL> grant select any dictionary to user1; Grant succeeded. SQL> conn user1/oracle Connected. SQL> select * from emp; select * from emp * ERROR at line 1: ORA-00942: table or view does not exist SQL> SQL> select * from scott.emp; EMPNO ENAME JOB MGR HIREDATE SAL COMM DEPTNO ---------- ---------- --------- ---------- --------- ---------- ---------- ---------- 7369 SMITH CLERK 7902 17-DEC-80 800 20 7499 ALLEN SALESMAN 7698 20-FEB-81 1600 300 30 7521 WARD SALESMAN 7698 22-FEB-81 1250 500 30 7566 JONES MANAGER 7839 02-APR-81 2975 20 7654 MARTIN SALESMAN 7698 28-SEP-81 1250 1400 30 7698 BLAKE MANAGER 7839 01-MAY-81 2850 30 7782 CLARK MANAGER 7839 09-JUN-81 2450 10 7788 SCOTT ANALYST 7566 19-APR-87 3000 20 7839 KING PRESIDENT 17-NOV-81 5000 10 7844 TURNER SALESMAN 7698 08-SEP-81 1500 0 30 7876 ADAMS CLERK 7788 23-MAY-87 1100 20 7900 JAMES CLERK 7698 03-DEC-81 950 30 7902 FORD ANALYST 7566 03-DEC-81 3000 20 7934 MILLER CLERK 7782 23-JAN-82 1300 10 14 rows selected. 方法二: SQL> conn / as sysdba Connected. SQL> SQL> create user user2 identified by oracle; User created. SQL> grant connect to user2; Grant succeeded. SQL> grant create synonym to user2; Grant succeeded. SQL> grant select on scott.emp to user2; Grant succeeded. SQL> create or replace synonym user2.emp for scott.emp; Synonym created. SQL> conn user2/oracle Connected. SQL> select * from emp; EMPNO ENAME JOB MGR HIREDATE SAL COMM DEPTNO ---------- ---------- --------- ---------- --------- ---------- ---------- ---------- 7369 SMITH CLERK 7902 17-DEC-80 800 20 7499 ALLEN SALESMAN 7698 20-FEB-81 1600 300 30 7521 WARD SALESMAN 7698 22-FEB-81 1250 500 30 7566 JONES MANAGER 7839 02-APR-81 2975 20 7654 MARTIN SALESMAN 7698 28-SEP-81 1250 1400 30 7698 BLAKE MANAGER 7839 01-MAY-81 2850 30 7782 CLARK MANAGER 7839 09-JUN-81 2450 10 7788 SCOTT ANALYST 7566 19-APR-87 3000 20 7839 KING PRESIDENT 17-NOV-81 5000 10 7844 TURNER SALESMAN 7698 08-SEP-81 1500 0 30 7876 ADAMS CLERK 7788 23-MAY-87 1100 20 7900 JAMES CLERK 7698 03-DEC-81 950 30 7902 FORD ANALYST 7566 03-DEC-81 3000 20 7934 MILLER CLERK 7782 23-JAN-82 1300 10 14 rows selected. 备注: 1.批量授权查询多个表的权限 select 'grant select on '||owner||'.'||object_name||' to user2;' from dba_objects where owner in ('SCOTT') and object_type='TABLE'; 2.批量创建同义词 SELECT 'create or replace SYNONYM user2.'||object_name||' FOR '||owner||'.'||object_name||';' from dba_objects where owner='SCOTT' and object_type='TABLE'; 总结,方法一用户查询数据的时候仍然要在表名前添加schema才可以查询,方法二使用创建同义词的方法,在查询的时候不需要添加schema,生产上一般使用方法二创建最小查询权限用户。