Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-25804

The listCollections command does not take the user's permissions into account

    • Type: Icon: Improvement Improvement
    • Resolution: Duplicate
    • Priority: Icon: Minor - P4 Minor - P4
    • None
    • Affects Version/s: None
    • Component/s: Security
    • Labels:
      None

      Some use cases have a need for "views" per user, and need to be able to grant access only to certain collections in a single database. This can be achieved easily using user-defined roles, with the correct permissions.

      However, when configuring roles this way, users can still use the listCollections command, and list collections that they cannot read from.

            Assignee:
            sara.golemon@mongodb.com Sara Golemon
            Reporter:
            charles.sarrazin@mongodb.com Charles Sarrazin (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            16 Start watching this issue

              Created:
              Updated:
              Resolved: