-
Notifications
You must be signed in to change notification settings - Fork 10
/
Copy pathbase_crea_db_role_privs_diff.sql
143 lines (143 loc) · 2.84 KB
/
base_crea_db_role_privs_diff.sql
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
with
grantees_to as
( select
distinct
connect_by_root(usr.name) username,
r_usr.name name
from
sys.sysauth$@DWHPRD_X3DM_LNK sau,
sys.user$@DWHPRD_X3DM_LNK r_usr,
sys.user$@DWHPRD_X3DM_LNK usr
where
sau.privilege# = r_usr.user#
and sau.grantee# = usr.user#
connect by
prior privilege# = grantee#
start with grantee# in
( select
user#
from
sys.user$@DWHPRD_X3DM_LNK
where
name in
( select
owner
from
dba_objects@DWHPRD_X3DM_LNK
where
object_type = 'DATABASE LINK'
)
)
union all
select
distinct
owner,
owner
from
dba_objects@DWHPRD_X3DM_LNK
where
object_type = 'DATABASE LINK'
),
users_to as
( select
distinct
owner
from
dba_objects@DWHPRD_X3DM_LNK a
where
object_type = 'DATABASE LINK'
and not exists
( select
null
from
uptdba.exclude_oracle_users b
where
b.user_name = a.owner
)
minus
select
grt.username
from
grantees_to grt,
dba_sys_privs@DWHPRD_X3DM_LNK sp
where
grt.name = sp.grantee
and privilege = 'CREATE DATABASE LINK'
),
grantees_from as
( select
distinct
connect_by_root(usr.name) username,
r_usr.name name
from
sys.sysauth$@DWHPRD_LNK sau,
sys.user$@DWHPRD_LNK r_usr,
sys.user$@DWHPRD_LNK usr
where
sau.privilege# = r_usr.user#
and sau.grantee# = usr.user#
connect by
prior privilege# = grantee#
start with grantee# in
( select
user#
from
sys.user$@DWHPRD_LNK
where
name in
( select
owner
from
dba_objects@DWHPRD_LNK
where
object_type = 'DATABASE LINK'
)
)
union all
select
distinct
owner,
owner
from
dba_objects@DWHPRD_LNK
where
object_type = 'DATABASE LINK'
),
users_from as
( select
distinct
owner
from
dba_objects@DWHPRD_LNK a
where
object_type = 'DATABASE LINK'
and not exists
( select
null
from
uptdba.exclude_oracle_users b
where
b.user_name = a.owner
)
minus
select
grt.username
from
grantees_from grt,
dba_sys_privs@DWHPRD_LNK sp
where
grt.name = sp.grantee
and privilege = 'CREATE DATABASE LINK'
)
select
owner
from
users_to
union
select
owner
from
users_from
order by
owner
;