[SERVER-10791] Write commands privilege check is incomplete Created: 16/Sep/13  Updated: 02/Aug/18  Resolved: 13/Nov/13

Status: Closed
Project: Core Server
Component/s: Security
Affects Version/s: 2.5.2
Fix Version/s: 2.5.4

Type: Task Priority: Major - P3
Reporter: J Rassi Assignee: Gregory McKeon (Inactive)
Resolution: Done Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Participants:

 Description   
  • insert command privilege check incorrect for system.indexes; should be using checkAuthForInsert.
  • update command ignoring upsert privilege check; should be using checkAuthForUpdate.
  • write commands privilege check should be using checkAuthForCommand instead of deprecated addRequiredPrivileges.


 Comments   
Comment by Greg Studer [ 13/Nov/13 ]

fixed in:

commit 268f85261996bf51781bfce3c5ca6efb07587c22
Author: Greg Studer <greg@10gen.com>
Date: Thu Nov 7 19:44:31 2013 -0500

SERVER-10818 properly check auth for index write batches

Generated at Thu Feb 08 03:24:04 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.