文稿教學(xué)講稿les_第1頁
文稿教學(xué)講稿les_第2頁
文稿教學(xué)講稿les_第3頁
文稿教學(xué)講稿les_第4頁
文稿教學(xué)講稿les_第5頁
已閱讀5頁,還剩23頁未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡介

1、Controlling User AccessObjectivesAfter completing this lesson, you should be able to do the following:Differentiate system privileges from object privilegesGrant privileges on tablesGrant rolesDistinguish between privileges and rolesLesson AgendaSystem privilegesCreating a roleObject privilegesRevok

2、ing object privilegesControlling User AccessDatabaseadministratorUsersUsername and passwordPrivilegesPrivilegesDatabase security:System securityData securitySystem privileges: Performing a particular action within the databaseObject privileges: Manipulating the content of the database objectsSchemas

3、: Collection of objects such as tables, views, and sequencesSystem PrivilegesMore than 100 privileges are available.The database administrator has high-level system privileges for tasks such as:Creating new usersRemoving usersRemoving tablesBacking up tablesCreating UsersThe database administrator (

4、DBA) creates users with the CREATE USER statement.CREATE USER demoIDENTIFIED BY demo;CREATE USER user IDENTIFIED BY password;User System PrivilegesAfter a user is created, the DBA can grant specific system privileges to that user.An application developer, for example, may have the following system p

5、rivileges:CREATE SESSIONCREATE TABLECREATE SEQUENCECREATE VIEWCREATE PROCEDUREGRANT privilege , privilege.TO user , user| role, PUBLIC.;Granting System PrivilegesThe DBA can grant specific system privileges to a user.GRANT create session, create table, create sequence, create viewTO demo;Lesson Agen

6、daSystem privilegesCreating a roleObject privilegesRevoking object privilegesWhat Is a Role?Allocating privilegeswithout a roleAllocating privilegeswith a rolePrivilegesUsersManagerCreating and Granting Privileges to a RoleCreate a role:Grant privileges to a role:Grant a role to users:CREATE ROLE ma

7、nager; GRANT create table, create view TO manager; GRANT manager TO BELL, KOCHHAR; Changing Your PasswordThe DBA creates your user account and initializes your password.You can change your password by using the ALTER USER statement.ALTER USER demo IDENTIFIED BY employ;Lesson AgendaSystem privilegesC

8、reating a roleObject privilegesRevoking object privilegesObject privilege Table View SequenceObject PrivilegesALTERDELETEINDEXINSERTREFERENCESSELECT UPDATEObject PrivilegesObject privileges vary from object to object.An owner has all the privileges on the object.An owner can give specific privileges

9、 on that owners object. GRANTobject_priv (columns) ONobject TOuser|role|PUBLIC WITH GRANT OPTION;Granting Object PrivilegesGrant query privileges on the EMPLOYEES table:Grant privileges to update specific columns to users and roles:GRANT selectON employeesTO demo;GRANT update (department_name, locat

10、ion_id)ON departmentsTO demo, manager;Passing On Your PrivilegesGive a user authority to pass along privileges:Allow all users on the system to query data from Alices DEPARTMENTS table:GRANT select, insertON departmentsTO demoWITH GRANT OPTION;GRANT selectON alice.departmentsTO PUBLIC;Confirming Gra

11、nted PrivilegesData Dictionary ViewDescriptionROLE_SYS_PRIVSSystem privileges granted to rolesROLE_TAB_PRIVSTable privileges granted to rolesUSER_ROLE_PRIVSRoles accessible by the userUSER_SYS_PRIVSSystem privileges granted to the userUSER_TAB_PRIVS_MADEObject privileges granted on the users objects

12、USER_TAB_PRIVS_RECDObject privileges granted to the userUSER_COL_PRIVS_MADEObject privileges granted on the columns of the users objectsUSER_COL_PRIVS_RECDObject privileges granted to the user on specific columnsLesson AgendaSystem privilegesCreating a roleObject privilegesRevoking object privileges

13、Revoking Object PrivilegesYou use the REVOKE statement to revoke privileges granted to other users.Privileges granted to others through the WITH GRANT OPTION clause are also revoked.REVOKE privilege , privilege.|ALLON objectFROM user, user.|role|PUBLICCASCADE CONSTRAINTS;Revoking Object PrivilegesRe

14、voke the SELECT and INSERT privileges given to the demo user on the DEPARTMENTS table.REVOKE select, insertON departmentsFROM demo;SummaryIn this lesson, you should have learned about statements that control access to the database and database objects.StatementActionCREATE USERCreates a user (usually performed by a DBA)GRANTGives other users privileges to access the objectsCREATE ROLECreates a collection of privileges (usually performed by a DBA)ALTER USERChanges a users passwordREVOKERem

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論