[SERVER-61508] Require privileges for "$_backupFile" aggregate Created: 16/Nov/21 Updated: 27/Oct/23 Resolved: 16/Nov/21 |
|
| Status: | Closed |
| Project: | Core Server |
| Component/s: | None |
| Affects Version/s: | None |
| Fix Version/s: | None |
| Type: | Bug | Priority: | Major - P3 |
| Reporter: | Matthew Russotto | Assignee: | Unassigned |
| Resolution: | Works as Designed | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Operating System: | ALL |
| Sprint: | Replication 2021-11-29 |
| Participants: |
| Description |
|
The "$_backupFile" aggregate can be used to download all the data from a mongodb instance, if a backup is in progress. While it does require the user know the backup id, it would be best if it also required privileges. The "exportCollection" privilege for all collections should be appropriate. |
| Comments |
| Comment by Matthew Russotto [ 16/Nov/21 ] |
|
No, this command is already set to be for internal users only. "Never mind". |