官术网_书友最值得收藏!

Time for action — anonymously accessing the _users database

Let's go through a quick exercise of calling a curl statement to the _users database to see why it's important to secure our data.

  1. Open Terminal.
  2. Run the following command, replacing your_username with the username of the server admin that you just created.
    curl localhost:5984/_users/org.couchdb.user:your_username | python -mjson.tool 
    
  3. Terminal will respond with something similar to:
    { "_id": "org.couchdb.user:your_username", "_rev": "1-b9af54a7cdc392c2c298591f0dcd81f3", "name": "your_username", "password_sha": "3bc7d6d86da6lfed6d4d82e1e4d1c3ca587aecc8", "roles": [], "salt": "9812acc4866acdec35c903f0cc072c1d", "type": "user" } 
    

What just happened?

You used Terminal to create a curl request to read the document containing your server admin's data. The passwords in the database are encrypted, but it's possible that someone could still unencrypt the password or use the usernames of the users against them. With that in mind, let's secure the database so that only administrators can access this database.

主站蜘蛛池模板: 沙坪坝区| 青铜峡市| 乌拉特后旗| 昭觉县| 隆尧县| 论坛| 松桃| 贞丰县| 营山县| 赣榆县| 鸡东县| 玛沁县| 布尔津县| 和静县| 烟台市| 乐亭县| 平塘县| 报价| 桃源县| 肃南| 福州市| 肇庆市| 额敏县| 庆元县| 银川市| 临洮县| 方城县| 曲麻莱县| 健康| 昆山市| 鄂托克旗| 讷河市| 象州县| 奎屯市| 贺兰县| 剑川县| 富平县| 盐边县| 屏山县| 仙居县| 万荣县|