couchdb-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Brian Candler <>
Subject Re: DB ACLs (was Re: 0.11 Release / Feature Freeze for 1.0)
Date Tue, 09 Feb 2010 19:30:37 GMT
On Tue, Feb 09, 2010 at 09:04:49AM -0800, Chris Anderson wrote:
> If you do a get against /_session does it show you as an admin?

Yes (see below)

> couch_db:check_is_admin() should allow access in this case.
> If you can reliably reproduce this, I'd like to fix it.

Yes, I can reliably reproduce. Here is a brand new installation of trunk,
still in admin party mode:

$ curl -X PUT
$ curl -X PUT -d '{"names":["foo"]}'
$ curl -X POST -d '{"map":"function(){}"}'
{"error":"unauthorized","reason":"You are not authorized to access this db."}
$ curl
$ curl



View raw message