Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> RE: Privileges needed for truncate /thanks all

RE: Privileges needed for truncate /thanks all

From: Jack van Zanen <nlzanen1_at_EY.NL>
Date: Wed, 25 Sep 2002 00:33:29 -0800
Message-ID: <F001.004D889F.20020925003329@fatcity.com>

Hi

Thx all those that replied.

I've decided to create a procedure to truncate the table and grant execute to the user.

Jack

                                                                                                                                       
                      "Ron Rogers"                                                                                                     
                      <RROGERS_at_galotter        To:       Multiple recipients of list ORACLE-L <ORACLE-L_at_fatcity.com>                   
                      y.org>                   cc:       (bcc: Jack van Zanen/nlzanen1/External/MEY/NL)                                
                      Sent by:                 Subject:  RE: Privileges needed for truncate                                            
                      root_at_fatcity.com                                                                                                 
                                                                                                                                       
                                                                                                                                       
                      24-09-2002 21:08                                                                                                 
                      Please respond to                                                                                                
                      ORACLE-L                                                                                                         
                                                                                                                                       
                                                                                                                                       



Jack,
  I have found that if a user needs to truncate a table then make the user the owner of the table that way the user will have all privileges on the table. The user then will grant the DBA all privileges with the grant option so the DBA can have some resemblence of control over the table. If you only allow a user to delete then as the DBA you have to export the table, truncate the table, and import the data to "clean" it up and defrag it.
Ron
ROR m™Ņ™m

>>> Stephen_Karniotis_at_compuware.com 09/24/02 02:43PM >>>
I agree that this is a security hole. It scares me that someone would need
this. I would have expected Oracle to correct this situation, but as of
now, they have not.

Thank You

Stephen P. Karniotis
Product Architect
Compuware Corporation

Direct:            (248) 865-4350
Mobile:            (248) 408-2918
Email:             Stephen.Karniotis_at_Compuware.com
Web:         www.compuware.com

 -----Original Message-----
Sent:        Tuesday, September 24, 2002 1:59 PM
To:          Multiple recipients of list ORACLE-L

delete wasn't enough for me. had to grant 'drop any table'.

>From the Oracle8i SQL Reference

Release 3 (8.1.7) manal:

"To truncate a table or cluster, the table or cluster must be in your schema
or you must have DROP ANY TABLE system privilege. "

> -----Original Message-----
> From: Ruth Gramolini [mailto:rgramolini_at_tax.state.vt.us]
> Sent: Thursday, September 19, 2002 2:18 PM
> To: Multiple recipients of list ORACLE-L
> Subject: Re: Privileges needed for truncate
>
>
> To truncate you need delete privileges. Ruth
> ----- Original Message -----
> To: "Multiple recipients of list ORACLE-L" <ORACLE-L_at_fatcity.com>
> Sent: Thursday, September 19, 2002 10:23 AM
>
>
> Hi
>
>
> I need to create a user/role that among other stuff must be able to
> truncate a table. I can't figure out which privileges are
> needed (DBA is a
> bit OTT :-))
> Try them one by one does not sound appealing at all
>
> TIA
>
>
> Jack
>
> ===================================================================
> De informatie verzonden in dit e-mailbericht is vertrouwelijk en is
> uitsluitend bestemd voor de geadresseerde. Openbaarmaking,
> vermenigvuldiging, verspreiding en/of verstrekking van deze
> informatie aan
> derden is, behoudens voorafgaande schriftelijke toestemming
> van Ernst &
> Young, niet toegestaan. Ernst & Young staat niet in voor de juiste
en
> volledige overbrenging van de inhoud van een verzonden
> e-mailbericht, noch
> voor tijdige ontvangst daarvan. Ernst & Young kan niet
> garanderen dat een
> verzonden e-mailbericht vrij is van virussen, noch dat
e-mailberichten
> worden overgebracht zonder inbreuk of tussenkomst van
> onbevoegde derden.
>
> Indien bovenstaand e-mailbericht niet aan u is gericht,
> verzoeken wij u
> vriendelijk doch dringend het e-mailbericht te retourneren
> aan de verzender
> en het origineel en eventuele kopieŽn te verwijderen en te
> vernietigen.
>
> Ernst & Young hanteert bij de uitoefening van haar
> werkzaamheden algemene
> voorwaarden, waarin een beperking van aansprakelijkheid is
> opgenomen. De
> algemene voorwaarden worden u op verzoek kosteloos toegezonden.
>



> The information contained in this communication is confidential and
is
> intended solely for the use of the individual or entity to whom it
is
> addressed. You should not copy, disclose or distribute this
> communication
> without the authority of Ernst & Young. Ernst & Young is
> neither liable for
> the proper and complete transmission of the information
> contained in this
> communication nor for any delay in its receipt. Ernst & Young does
not
> guarantee that the integrity of this communication has been
> maintained nor
> that the communication is free of viruses, interceptions or
> interference.
>
> If you are not the intended recipient of this communica
tion
> please return
> the communication to the sender and delete and destroy all copies.
>
> In carrying out its engagements, Ernst & Young applies
> general terms and
> conditions, which contain a clause that limits its liability.
> A copy of
> these terms and conditions is available on request free of charge.
> ===================================================================
>
>
>
>
>
> --
> Please see the official ORACLE-L FAQ: http://www.orafaq.com
> --
> Author: Jack van Zanen
> INET: nlzanen1_at_EY.NL
>
> Fat City Network Services -- 858-538-5051 http://www.fatcity.com
> San Diego, California -- Mailing list and web hosting
services
>


> To REMOVE yourself from this mailing list, send an E-Mail message
> to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
> the message BODY, include a line containing: UNSUB ORACLE-L
> (or the name of mailing list you want to be removed from). You may
> also send the HELP command for other information (like subscribing).
>
> --
> Please see the official ORACLE-L FAQ: http://www.orafaq.com
> --
> Author: Ruth Gramolini
> INET: rgramolini_at_tax.state.vt.us
>
> Fat City Network Services -- 858-538-5051 http://www.fatcity.com
> San Diego, California -- Mailing list and web hosting
services
>


> To REMOVE yourself from this mailing list, send an E-Mail message
> to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
> the message BODY, include a line containing: UNSUB ORACLE-L
> (or the name of mailing list you want to be removed from). You may
> also send the HELP command for other information (like subscribing).
>
--
Please see the official ORACLE-L FAQ: http://www.orafaq.com
--
Author: Glenn Travis
  INET: Glenn.Travis_at_sas.com

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).



The contents of this e-mail are intended for the named addressee only.
It
contains information that may be confidential. Unless you are the
named
addressee or an authorized designee, you may not copy or use it, or
disclose
it to anyone else. If you received it in error please notify us
immediately
and then destroy it.

--
Please see the official ORACLE-L FAQ: http://www.orafaq.com
--
Author: Karniotis, Stephen
  INET: Stephen_Karniotis_at_compuware.com

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).
--
Please see the official ORACLE-L FAQ: http://www.orafaq.com
--
Author: Ron Rogers
  INET: RROGERS_at_galottery.org

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).



===================================================================
De informatie verzonden in dit e-mailbericht is vertrouwelijk en is
uitsluitend bestemd voor de geadresseerde. Openbaarmaking,
vermenigvuldiging, verspreiding en/of verstrekking van deze informatie aan
derden is, behoudens voorafgaande schriftelijke toestemming van Ernst &
Young, niet toegestaan. Ernst & Young staat niet in voor de juiste en
volledige overbrenging van de inhoud van een verzonden e-mailbericht, noch
voor tijdige ontvangst daarvan. Ernst & Young kan niet garanderen dat een
verzonden e-mailbericht vrij is van virussen, noch dat e-mailberichten
worden overgebracht zonder inbreuk of tussenkomst van onbevoegde derden.

Indien bovenstaand e-mailbericht niet aan u is gericht, verzoeken wij u
vriendelijk doch dringend het e-mailbericht te retourneren aan de verzender
en het origineel en eventuele kopieŽn te verwijderen en te vernietigen.

Ernst & Young hanteert bij de uitoefening van haar werkzaamheden algemene
voorwaarden, waarin een beperking van aansprakelijkheid is opgenomen. De
algemene voorwaarden worden u op verzoek kosteloos toegezonden.
=====================================================================
The information contained in this communication is confidential and is
intended solely for the use of the individual or entity to whom it is
addressed. You should not copy, disclose or distribute this communication
without the authority of Ernst & Young. Ernst & Young is neither liable for
the proper and complete transmission of the information contained in this
communication nor for any delay in its receipt. Ernst & Young does not
guarantee that the integrity of this communication has been maintained nor
that the communication is free of viruses, interceptions or interference.

If you are not the intended recipient of this communication please return
the communication to the sender and delete and destroy all copies.

In carrying out its engagements, Ernst & Young applies general terms and
conditions, which contain a clause that limits its liability. A copy of
these terms and conditions is available on request free of charge.
===================================================================






-- 
Please see the official ORACLE-L FAQ: http://www.orafaq.com
-- 
Author: Jack van Zanen
  INET: nlzanen1_at_EY.NL

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).
Received on Wed Sep 25 2002 - 03:33:29 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US