官术网_书友最值得收藏!

Time for action — anonymously accessing the _users database

Let's go through a quick exercise of calling a curl statement to the _users database to see why it's important to secure our data.

  1. Open Terminal.
  2. Run the following command, replacing your_username with the username of the server admin that you just created.
    curl localhost:5984/_users/org.couchdb.user:your_username | python -mjson.tool 
    
  3. Terminal will respond with something similar to:
    { "_id": "org.couchdb.user:your_username", "_rev": "1-b9af54a7cdc392c2c298591f0dcd81f3", "name": "your_username", "password_sha": "3bc7d6d86da6lfed6d4d82e1e4d1c3ca587aecc8", "roles": [], "salt": "9812acc4866acdec35c903f0cc072c1d", "type": "user" } 
    

What just happened?

You used Terminal to create a curl request to read the document containing your server admin's data. The passwords in the database are encrypted, but it's possible that someone could still unencrypt the password or use the usernames of the users against them. With that in mind, let's secure the database so that only administrators can access this database.

主站蜘蛛池模板: 治多县| 恭城| 锦屏县| 林甸县| 乌拉特前旗| 宁津县| 夏邑县| 彩票| 甘德县| 云南省| 中卫市| 三明市| 宁国市| 维西| 蓬溪县| 砀山县| 阳高县| 兴城市| 木里| 桐庐县| 措勤县| 辽宁省| 河曲县| 伽师县| 大同县| 临沂市| 富平县| 西城区| 邵武市| 天门市| 新田县| 宁强县| 黑山县| 利辛县| 延吉市| 宜章县| 文登市| 航空| 耿马| 信宜市| 明光市|