Return-Path: Delivered-To: apmail-couchdb-user-archive@www.apache.org Received: (qmail 8342 invoked from network); 3 Jun 2010 12:25:52 -0000 Received: from unknown (HELO mail.apache.org) (140.211.11.3) by 140.211.11.9 with SMTP; 3 Jun 2010 12:25:52 -0000 Received: (qmail 73736 invoked by uid 500); 3 Jun 2010 12:25:51 -0000 Delivered-To: apmail-couchdb-user-archive@couchdb.apache.org Received: (qmail 73681 invoked by uid 500); 3 Jun 2010 12:25:50 -0000 Mailing-List: contact user-help@couchdb.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: user@couchdb.apache.org Delivered-To: mailing list user@couchdb.apache.org Received: (qmail 73671 invoked by uid 99); 3 Jun 2010 12:25:50 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 03 Jun 2010 12:25:50 +0000 X-ASF-Spam-Status: No, hits=2.9 required=10.0 tests=HTML_MESSAGE,SPF_NEUTRAL X-Spam-Check-By: apache.org Received-SPF: neutral (nike.apache.org: local policy) Received: from [209.85.161.52] (HELO mail-fx0-f52.google.com) (209.85.161.52) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 03 Jun 2010 12:25:41 +0000 Received: by fxm10 with SMTP id 10so66019fxm.11 for ; Thu, 03 Jun 2010 05:25:21 -0700 (PDT) Received: by 10.102.254.26 with SMTP id b26mr3406148mui.118.1275567921113; Thu, 03 Jun 2010 05:25:21 -0700 (PDT) MIME-Version: 1.0 Received: by 10.103.108.6 with HTTP; Thu, 3 Jun 2010 05:25:01 -0700 (PDT) In-Reply-To: References: From: =?UTF-8?Q?Siegmund_F=C3=BChringer?= Date: Thu, 3 Jun 2010 14:25:01 +0200 Message-ID: Subject: Re: Authorizing Anonymous Users To: user@couchdb.apache.org Content-Type: multipart/alternative; boundary=001636426575d328db04881f4c69 X-Virus-Checked: Checked by ClamAV on apache.org --001636426575d328db04881f4c69 Content-Type: text/plain; charset=UTF-8 hi! On Wed, Jun 2, 2010 at 1:20 PM, afshin afzali wrote: > Hi List, > > As stated in "Security Features Overview", there are three kind of > users : database readers, database admins, server admins. Also if > there are one or more server admins configured and the > require_valid_user is set to false: the request will be validated as > "anonymous". Does the anonymous user authorize to readers ? I mean it > can edit docs? > you can specify readers and admins per database. if you don't specify reader roles or users, than anyone (even anonymous) can read the database, but anonyous users can't change it, if there are admin roles/users set on the database. i hope that answers your question. cheers, sifu > > Best Regards, > -- afshin > --001636426575d328db04881f4c69--