官术网_书友最值得收藏!

Time for action — checking to make sure the database is secure

Your _users database should be secure, so that only admins can read or alter the structure of the database. Let's quickly test this:

  1. Open Terminal.
  2. Try to read the user document again by running the following command. Again, replace your_username with the username of the service admin that you just created:
    curl localhost:5984/_users/org.couchdb.user:your_username 
    
  3. Terminal will respond with the following:
    {"error":"unauthorized","reason":"You are not authorized to access this db."} 
    

What just happened?

With the CouchDB instance out of Admin Party mode, the authentication module stepped in to make sure that anonymous users couldn't read the database.

Note

We'll add more security to the databases down the road, but this is one of the simplest ways to add security to a database.

If you were to play around with the command line again, you would be restricted by doing anything with the _users database, but you would also notice that the test-db database is operating just as it was before, perfect! That's exactly what we wanted. You might be asking how do I access the _users database through the command line, now that security is enabled? You have to show that you are an admin by passing your credentials to the RESTful JSON API.

主站蜘蛛池模板: 竹溪县| 蒙山县| 香港| 南木林县| 满城县| 庐江县| 肥西县| 石台县| 双鸭山市| 滨州市| 枞阳县| 徐州市| 海城市| 甘德县| 榆林市| 冷水江市| 张掖市| 剑阁县| 金乡县| 庄河市| 安远县| 甘肃省| 遂溪县| 花垣县| 温泉县| 郎溪县| 社旗县| 昭苏县| 车致| 潮安县| 大兴区| 孝义市| 新野县| 射洪县| 富川| 孟州市| 永平县| 青铜峡市| 且末县| 鹤岗市| 昌邑市|