[DOCS-181] Mention more commands require auth in 2.0 release notes Created: 09/Apr/12  Updated: 30/Oct/23  Resolved: 11/Sep/12

Status: Closed
Project: Documentation
Component/s: Server
Affects Version/s: None
Fix Version/s: Server_Docs_20231030

Type: Task Priority: Trivial - P5
Reporter: Mathias Stearn Assignee: Bob Grabar
Resolution: Done Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Related
is related to SERVER-3418 Make sure commands check auth before ... Closed
is related to SERVER-3773 It's possible to invoke certain admin... Closed
is related to SERVER-5555 Sharded GLE doesn't require auth Closed
Participants:
Days since reply: 11 years, 23 weeks, 1 day ago

 Description   

We are much more strict about checking auth for commands in 2.0.



 Comments   
Comment by auto [ 11/Sep/12 ]

Author:

{u'date': u'2012-09-11T07:59:29-07:00', u'email': u'samk@10gen.com', u'name': u'Sam Kleinman'}

Message: merge: DOCS-181
Branch: master
https://github.com/mongodb/docs/commit/27efeae291b742412f0833ef7b48e4a9ec703576

Comment by auto [ 11/Sep/12 ]

Author:

{u'date': u'2012-09-11T07:44:04-07:00', u'email': u'bob.grabar@10gen.com', u'name': u'Bob Grabar'}

Message: DOCS-181 edit to commands that don't require auth
Branch: master
https://github.com/mongodb/docs/commit/03f1caffba04992bbb2fe125d5e5b3bba44b6ae1

Comment by auto [ 11/Sep/12 ]

Author:

{u'date': u'2012-09-11T07:16:30-07:00', u'email': u'bob.grabar@10gen.com', u'name': u'Bob Grabar'}

Message: DOCS-181 commands that do not require auth
Branch: master
https://github.com/mongodb/docs/commit/96805275ef59e624dd9528d2235a273a6dd009eb

Comment by Mathias Stearn [ 09/Apr/12 ]

Yes, we changed the rules for 2.0 but didn't mention it in release notes. The user in the linked free support suggested that we should mention it there.

Actually all commands now require auth with the following few exceptions:

  • isMaster
  • authenticate
  • getnonce
  • buildInfo
  • ping
  • isdbgrid
  • sharded getlasterror

The last one is probably an error since auth is required when not sharded. I'll open a ticket about it. We probably shouldn't doc that one.

Comment by Sam Kleinman (Inactive) [ 09/Apr/12 ]

Just to confirm that you want to edit the existing release notes for version 2.0, and not the upcoming release notes for 2.2?

I think it would also be good to amend the API references accordingly as well. Is the list of auth-required commands, as follows:

https://github.com/mongodb/mongo/commit/991bfa6eae1d63ccc4a78901bca5ebea7645c251#L3R21

(plus getLastError) or am I missing some?

Generated at Thu Feb 08 07:38:06 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.