For a given user foo with password bar, I can successfully authenticate against the admin database and get the desired result from one of our shard nodes with the following command:
mongo PRIMARY --host exampleShard1.com \
--port 27018 \
--username foo \
-p bar \
--authenticationDatabase 'admin' \
--eval 'db.serverStatus().connections'
However, when attempting to do the exact same command via a third party library such as the Java's MongoDB Driver or Python's pymongo, the authentication passes successfully but I'm unable to execute any commands successfully due to "not authorized" errors.
For example, here's a pymongo version of the working command above:
#!/usr/bin/python3
from pymongo import MongoClient
mongoClient = MongoClient("exampleShard1.com", 27018)
mongoClient.admin.authenticate("foo", "bar")
primaryDb = mongoClient["PRIMARY"]
print(primaryDb.eval("db.serverStatus().connections"))
Despite this appearing to be equivalent to the origin working command, this version fails with a version of the following error:
not authorized on local to execute command
{
$eval: db.serverStatus().connections,
args: [],
lsid: {
id: UUID("f5a936ee-71ad-4568-8bf2-a45c69424200")
},
$clusterTime: {
signature: {
keyId: 111,
hash: BinData(0, 6F)
},
clusterTime: Timestamp(1536848021, 159)
},
$db: "local",
$readPreference: {
mode: "primaryPreferred"
}
}
This is despite the authenticate() method returning "True", proving a successful authentication.
My guess would be there's a required value being set automatically from the command line that isn't being set from the script version, or that the command line version is somehow bypassing an extra level of authentication that the script version is caught in.
At this point, I'm unfortunately out of things to try, and I've exhausted Google for help. Any guidance would be greatly appreciated!