我希望将CREATE ANY DIRECTORY权限授予用户,但有以下限制:该用户创建的所有目录都必须在/foo/bar中,任何在该权限之外创建目录的尝试都会失败,出现权限错误。我如何在Oracle11G或12C上做到这一点?
发布于 2017-05-24 09:04:42
您可以在触发器中包含此限制。系统事件和属性列表( 处理系统事件 )
CREATE OR REPLACE TRIGGER trg_before_ddl 
BEFORE DDL ON DATABASE
declare 
    v_sql ORA_NAME_LIST_T;
   v_ddl varchar2(4000);
   v_cnt BINARY_INTEGER;
   is_valid number;
begin
   if  ora_sysevent in ('CREATE') and ora_dict_obj_type = 'DIRECTORY' then 
       v_cnt := ora_sql_txt (v_sql);
       FOR i IN 1..v_cnt LOOP     
          v_ddl := v_ddl || RTRIM (v_sql (i), CHR (0));
       END LOOP;
       v_ddl :=  regexp_substr(v_ddl,'AS ''(.*)''', 1, 1, 'i', 1 ); -- get path from ddl_statement             
       -- check valid directory here, path is in v_ddl ;
       is_valid := REGEXP_instr(v_ddl,'^/valid_dir/.*$');
       if (is_valid = 0) then 
         raise_application_error(-20000,'Directory is not valid' || v_ddl);
       end if; 
   end if;   
END;
/
CREATE DIRECTORY valid_dir AS '/valid_dir/xyz';
CREATE DIRECTORY invalid_dir AS '/invalid_dir/xyz';https://stackoverflow.com/questions/44142383
复制相似问题