官术网_书友最值得收藏!

Time for action — anonymously accessing the _users database

Let's go through a quick exercise of calling a curl statement to the _users database to see why it's important to secure our data.

  1. Open Terminal.
  2. Run the following command, replacing your_username with the username of the server admin that you just created.
    curl localhost:5984/_users/org.couchdb.user:your_username | python -mjson.tool 
    
  3. Terminal will respond with something similar to:
    { "_id": "org.couchdb.user:your_username", "_rev": "1-b9af54a7cdc392c2c298591f0dcd81f3", "name": "your_username", "password_sha": "3bc7d6d86da6lfed6d4d82e1e4d1c3ca587aecc8", "roles": [], "salt": "9812acc4866acdec35c903f0cc072c1d", "type": "user" } 
    

What just happened?

You used Terminal to create a curl request to read the document containing your server admin's data. The passwords in the database are encrypted, but it's possible that someone could still unencrypt the password or use the usernames of the users against them. With that in mind, let's secure the database so that only administrators can access this database.

主站蜘蛛池模板: 莱西市| 张家界市| 关岭| 黄梅县| 望城县| 延吉市| 进贤县| 白城市| 廊坊市| 达日县| 昆明市| 栾川县| 区。| 临沂市| 绥德县| 全椒县| 景宁| 大埔县| 苗栗县| 常熟市| 津市市| 杭锦后旗| 阿尔山市| 恩施市| 新营市| 乌审旗| 潢川县| 丰都县| 紫云| 大庆市| 弋阳县| 潮安县| 阳朔县| 田东县| 崇州市| 织金县| 涡阳县| 怀远县| 兖州市| 诸暨市| 宁城县|