diff options
Diffstat (limited to 'jstests/auth/authz_cache_on_system_modification.js')
| -rw-r--r-- | jstests/auth/authz_cache_on_system_modification.js | 30 |
1 files changed, 19 insertions, 11 deletions
diff --git a/jstests/auth/authz_cache_on_system_modification.js b/jstests/auth/authz_cache_on_system_modification.js index 23473cd0d01..65c49951853 100644 --- a/jstests/auth/authz_cache_on_system_modification.js +++ b/jstests/auth/authz_cache_on_system_modification.js @@ -7,7 +7,6 @@ const conn = MongoRunner.runMongod({auth: ''}); let db = conn.getDB('admin'); -const authzErrorCode = 13; // creates a root user assert.commandWorked(db.runCommand({createUser: 'root', pwd: 'pwd', roles: ['__system']}), @@ -46,23 +45,32 @@ db.logout(); assert(db.auth('custom', 'pwd')); assert.commandFailedWithCode( db.runCommand({insert: "admin.test", documents: [{woo: "mar"}]}), - authzErrorCode, + ErrorCodes.Unauthorized, "Privileges retained after modification to system.roles collections"); db.logout(); })(); -// tests that a user does not retain their privileges after the system.users colleciton is modified +// tests that a user cannot rename the system.users collection. (function testModifySystemUsersCollection() { - jsTestLog("Testing authz cache invalidation on system.users collection modification"); + jsTestLog("Testing that a user cannot rename the system.users collection"); assert(db.auth('root', 'pwd')); - assert.commandWorked(db.createCollection("scratch", {}), - "Collection not created with root user"); - assert.commandWorked(db.runCommand({renameCollection: 'admin.system.users', to: 'admin.foo'}), - "System collection could not be renamed with root user"); + + assert.commandFailedWithCode( + db.runCommand({renameCollection: 'admin.system.users', to: 'foo.system.users'}), + ErrorCodes.IllegalOperation, + "Renaming the system.users collection should not be allowed"); + assert.commandFailedWithCode( + db.runCommand({renameCollection: 'foo.system.users', to: 'admin.system.users'}), + ErrorCodes.IllegalOperation, + "Renaming the system.users collection should not be allowed"); + assert.commandFailedWithCode( + db.runCommand({renameCollection: 'admin.system.users', to: 'admin.system.foo'}), + ErrorCodes.IllegalOperation, + "Renaming the system.users collection should not be allowed"); assert.commandFailedWithCode( - db.runCommand({renameCollection: 'admin.scratch', to: 'admin.system.users'}), - authzErrorCode, - "User cache not invalidated after modification to system collection"); + db.runCommand({renameCollection: 'admin.system.foo', to: 'admin.system.users'}), + ErrorCodes.IllegalOperation, + "Renaming the system.users collection should not be allowed"); db.logout(); })(); |
