官术网_书友最值得收藏!

Time for action — checking to make sure the database is secure

Your _users database should be secure, so that only admins can read or alter the structure of the database. Let's quickly test this:

  1. Open Terminal.
  2. Try to read the user document again by running the following command. Again, replace your_username with the username of the service admin that you just created:
    curl localhost:5984/_users/org.couchdb.user:your_username 
    
  3. Terminal will respond with the following:
    {"error":"unauthorized","reason":"You are not authorized to access this db."} 
    

What just happened?

With the CouchDB instance out of Admin Party mode, the authentication module stepped in to make sure that anonymous users couldn't read the database.

Note

We'll add more security to the databases down the road, but this is one of the simplest ways to add security to a database.

If you were to play around with the command line again, you would be restricted by doing anything with the _users database, but you would also notice that the test-db database is operating just as it was before, perfect! That's exactly what we wanted. You might be asking how do I access the _users database through the command line, now that security is enabled? You have to show that you are an admin by passing your credentials to the RESTful JSON API.

主站蜘蛛池模板: 彰武县| 张北县| 建昌县| 望城县| 康保县| 洮南市| 凤凰县| 南华县| 同德县| 镶黄旗| 牡丹江市| 浙江省| 高淳县| 沭阳县| 辉南县| 奈曼旗| 鄂托克前旗| 隆子县| 精河县| 陕西省| 鲁山县| 武宁县| 深泽县| 湘潭县| 麻阳| 万州区| 六安市| 密云县| 石泉县| 闽侯县| 白水县| 宜章县| 尼玛县| 杭锦旗| 象山县| 桑植县| 全州县| 无极县| 河津市| 万盛区| 湘潭县|