We are working on developing a Role-Based Access Control in MongoDB for a web project. We have been working on roles from the shell so far, to make sure the database is working well locally. However, we have been facing some issues.
I will present here one of the role created.
db.getRole("proposer", {showPrivileges: true})
{
"role" : "proposer",
"db" : "mydb",
"isBuiltin" : false,
"roles" : [ ],
"inheritedRoles" : [ ],
"privileges" : [
{
"resource" : {
"db" : "mydb",
"collection" : "users"
},
"actions" : [
"find",
"update"
]
},
{
"resource" : {
"db" : "mydb",
"collection" : "votes&signatures"
},
"actions" : [
"find"
]
},
{
"resource" : {
"db" : "mydb",
"collection" : "group&categories&propositions&comments"
},
"actions" : [
"find",
"insert",
"remove",
"update"
]
}
],
"inheritedPrivileges" : [
{
"resource" : {
"db" : "mydb",
"collection" : "users"
},
"actions" : [
"find",
"update"
]
},
{
"resource" : {
"db" : "mydb",
"collection" : "votes&signatures"
},
"actions" : [
"find"
]
},
{
"resource" : {
"db" : "mydb",
"collection" : "group&categories&propositions&comments"
},
"actions" : [
"find",
"insert",
"remove",
"update"
]
}
]
}
As you can see here, this role shouldn't allow a user to insert any data in the "users" collection of mydb. At least from my understanding. Thus, we have created a user with this role to test this function.
> db.getUser("user1")
{
"_id" : "mydb.user1",
"user" : "user1",
"db" : "mydb",
"customData" : {
},
"roles" : [
{
"role" : "proposer",
"db" : "mydb"
}
]
}
However, when I connect to the shell with such user, I am able to insert data with no issue in the user collections, ruining the purpose of this control access we're trying to implement.
mongo --port 27017 -u "user1" -p "password" --authenticationDatabase "mydb"
> db.users.insert({x: 1})
WriteResult({ "nInserted" : 1 })
Also, I tried to follow the documentation of MongoDB concerning Enabling Auth, but there is no way to login a userAdminAnyDatabase or clusterAdmin to myDB, which is weird because from my understanding, any userAdminAnyDatabase in the admin DB had access to the rest of the databases.
So, do you have any ideas where is the problem with this implementation of Roled Based AC in mongo? Thank you for reading, and thanks in advance for the help!