-
Type: Bug
-
Resolution: Done
-
Priority: Major - P3
-
None
-
Affects Version/s: 3.0.0-rc11
-
Component/s: Security
-
None
-
Fully Compatible
-
ALL
-
The HTTP Interface code (db/dbwebserver.cpp) was never updated to work with SCRAM-style user documents, and thus is not compatible with the new user document format. However, the interface still works with 2.6-style user documents in a 3.0 database that have not yet been updated.
Alternatively, we could deprecate support for the HTTP interface with auth enabled (or entirely) as it is a potential security risk.
- is duplicated by
-
SERVER-17512 Unable to authenticate with web console with SCRAM-SHA-1
- Closed
- is related to
-
SERVER-17527 Add startupWarning if server started with --rest or --httpinterface and access control is enabled
- Closed