data:image/s3,"s3://crabby-images/e8110/e81100a17b8dcedc040ddd58d344223b26cbde67" alt="Digikam applying recursive tag"
data:image/s3,"s3://crabby-images/6d4ea/6d4ea622090ed99d4fe581ebe7356a11483b101b" alt="digikam applying recursive tag digikam applying recursive tag"
Let's see an example and then we guess what privilege we need. Please note that, CREATE INDEX is not a valid privilege, but CREATE ANY INDEX is. In the above section, we have granted CREATE TABLE to THOMAS, which enables Thomas the ability to CREATE INDEX in his schema. SQL> alter table test1 add constraint fk_eid foreign key (e_id) references hr.employees (employee_id) SQL> grant references on hr.employees to thomas We should grant the privilege to him either by HR or privileged users. The right privilege to reference other's data is not SELECT, it's REFERENCES. SQL> alter table test1 add constraint fk_eid foreign key (e_id) references hr.employees (employee_id) Īlter table test1 add constraint fk_eid foreign key (e_id) references hr.employees (employee_id)
data:image/s3,"s3://crabby-images/dc41a/dc41a85e0afce0127d351873344dc87a0867a3d6" alt="digikam applying recursive tag digikam applying recursive tag"
SQL> grant select on hr.employees to thomas User Thomas wants to add a constraint so as to make a reference to another user's data, so we grant SELECT on that table to THOMAS by instinct. That's why there's no such GRANT ALTER TABLE TO user.
data:image/s3,"s3://crabby-images/957c6/957c64cc88075bf640c29fceffcf0bd1aa8f21d7" alt="digikam applying recursive tag digikam applying recursive tag"
Please note that, ALTER TABLE is not a privilege, but ALTER ANY TABLE is. So the cause of ORA-01031 in ALTER TABLE is not obvious like we thought. Implicitly, he also has the right to ALTER TABLE on schema-level. In the above section, we have granted CREATE TABLE to THOMAS.
DIGIKAM APPLYING RECURSIVE TAG UPDATE
That is to say, not only SELECT, but also INSERT, UPDATE or DELETE privilege you should have to manipulate tables owned by other users. SQL> grant insert,update,delete on hr.t1 to sh Īs we can see, the grantor grants 3 object privileges INSERT, UPDATE and DELETE on the table to the grantee at a time.Ĭommit complete. You may ask for DBA or the object owner to grant the privilege to you. Solution to ORA-01031Ĭlearly, the right privilege is INSERT, UPDATE or DELETE at object-level.
data:image/s3,"s3://crabby-images/fd0af/fd0af9638fd3bbf292efbc4e7e1420d8209ba96f" alt="digikam applying recursive tag digikam applying recursive tag"
This is because you lack INSERT, UPDATE or DELETE privilege to modify on that table which is usually owned by others. For example, INSERT INTO some data like this: SQL> insert into hr.t1 values (4) SQL> conn sh/shīut you may not have the right to modify the table. You may have the right to select other's table. If you use EXECUTE IMMEDIATE to run CREATE TABLE in a stored procedure, you may check ORA-01031 in EXECUTE IMMEDIATE section in this post. SQL> create table test1 (id number, e_id number) The solution is simple, just grant him CREATE TABLE, a schema-based privilege or CREATE ANY TABLE, a system-wide privilege. Immediately, ORA-01031: insufficient privileges shows up, which tells THOMAS he doesn't have the right privilege to do that. C:\Users\edchen>sqlplus create table test1 (id number, e_id number) Ĭreate table test1 (id number, e_id number) Let's see what will happen if the new user wants to create a table. SQL> create user thomas identified by thomas Īs you can see, a new user THOMAS is created, but we only grant CREATE SESSION to him, which allows him to connect to the database. ORA-01031 is very common when a new user wants to create a table. You may click whichever situation you encountered. There're several error patterns of ORA-01031 in this post. So I can only do my best to collect cases for you. Since this error can be seen almost in every kind of SQL statement, sometimes you would never know what privilege you lack. ORA-01031: Insufficient Privileges means that the current user did not use the right privilege to process the SQL statement.
data:image/s3,"s3://crabby-images/e8110/e81100a17b8dcedc040ddd58d344223b26cbde67" alt="Digikam applying recursive tag"