官术网_书友最值得收藏!

Time for action — anonymously accessing the _users database

Let's go through a quick exercise of calling a curl statement to the _users database to see why it's important to secure our data.

  1. Open Terminal.
  2. Run the following command, replacing your_username with the username of the server admin that you just created.
    curl localhost:5984/_users/org.couchdb.user:your_username | python -mjson.tool 
    
  3. Terminal will respond with something similar to:
    { "_id": "org.couchdb.user:your_username", "_rev": "1-b9af54a7cdc392c2c298591f0dcd81f3", "name": "your_username", "password_sha": "3bc7d6d86da6lfed6d4d82e1e4d1c3ca587aecc8", "roles": [], "salt": "9812acc4866acdec35c903f0cc072c1d", "type": "user" } 
    

What just happened?

You used Terminal to create a curl request to read the document containing your server admin's data. The passwords in the database are encrypted, but it's possible that someone could still unencrypt the password or use the usernames of the users against them. With that in mind, let's secure the database so that only administrators can access this database.

主站蜘蛛池模板: 汾西县| 湟源县| 永寿县| 黄石市| 登封市| 藁城市| 镇宁| 平凉市| 彝良县| 双流县| 天峨县| 利津县| 项城市| 鄂州市| 焦作市| 济阳县| 曲沃县| 东方市| 宁波市| 托克逊县| 西丰县| 萨嘎县| 上杭县| 武川县| 德江县| 大洼县| 舞钢市| 任丘市| 新安县| 九龙县| 民和| 浦江县| 长垣县| 柳州市| 南和县| 方城县| 漳州市| 武陟县| 上蔡县| 双流县| 靖边县|