Uploaded image for project: 'Documentation'
  1. Documentation
  2. DOCS-1250

Document that system.users access is blocked for readOnly users

    XMLWordPrintableJSON

Details

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major - P3 Major - P3
    • None
    • None
    • None
    • None

    Description

      On the security practices page we dont mention that read only users cannot access the system.users collection for a given DB. We mention explicitly that readOnly users have read access to all collections in a db.
      http://docs.mongodb.org/manual/administration/security/#security-authentication

      We document it here. http://docs.mongodb.org/manual/tutorial/control-access-to-mongodb-with-authentication/#password-hashing-insecurity

      Attachments

        Activity

          People

            sam.kleinman Sam Kleinman (Inactive)
            david.hows David Hows
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:
              10 years, 48 weeks ago