Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-75656

Remove configureQueryAnalyzer action from permitted actions in Serverless

    • Type: Icon: Task Task
    • Resolution: Fixed
    • Priority: Icon: Major - P3 Major - P3
    • 7.1.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • Minor Change
    • Security 2023-08-07
    • None
    • 3
    • None
    • None
    • None
    • None
    • None
    • None

      The action type configureQueryAnalyzer was added to the dbAdmin role according to the design for shard key metrics.]. However, the configureQueryAnalyzer command should not be permitted to run by users authenticated by Server Token (i.e. in multi-tenant situations). 

      The action type was added to serverlessActionType lists in SERVER-69653 in order to pass tests in native_tenant_data_isolation_with_security_token_jscore_passthrough test suite, but should ultimately be removed and excluded from permissions for multi-tenant users.

       

            Assignee:
            sara.golemon@mongodb.com Sara Golemon (Inactive)
            Reporter:
            israel.hsu@mongodb.com Israel Hsu (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: