rnewson commented on a change in pull request #1440: Optionally prevent
non-admins from accessing /_all_dbs
URL: https://github.com/apache/couchdb/pull/1440#discussion_r202527098
##########
File path: src/chttpd/src/chttpd_auth_request.erl
##########
@@ -34,7 +34,11 @@ authorize_request_int(#httpd{path_parts=[]}=Req) ->
authorize_request_int(#httpd{path_parts=[<<"favicon.ico">>|_]}=Req) ->
Req;
authorize_request_int(#httpd{path_parts=[<<"_all_dbs">>|_]}=Req) ->
- Req;
+ case config:get("chttpd", "admin_only_all_dbs", "false") of
+ "false" -> Req;
+ "true" -> require_admin(Req);
+ Else -> couch_log:error("Invalid setting for admin_only_all_dbs: ~p.
Must be true or false.", [Else])
Review comment:
this will cause a badmatch or something in the response itself, no? In
general I'm not in favour of error messages that only the couchdb administrator
can see and not the person/agent making the request.
Either don't have the clause, so we get a case_clause (and a 500 server
error) or flip it around like;
"true" -> require_admin(Req);
_ -> Req
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
With regards,
Apache Git Services