Alex Rivera | Logout

How to Secure CouchDB

Asked 2009-12-17T17:35:49.643
35

CouchDB access as a rest service seems insecure. Anyone can hit the database and delete/add documents once it is exposed.

What strategies are there to secure the CouchDB?

Edit
Report

1 Answer

6

This may be a little different from your original question. If your couchdb is only a back-end store for a full server app, you can make a special account for the server app to use and require those credentials for access to couchdb.

On the other hand, a pure couch app that people hit directly through a javascript client needs a lot of care to be secure.

Using rewrites is not optional. You need a vhosts config that forces requests to your domain through your rewrites.

Rewrite routes */_all_docs and /*/_design/* to a 404 page. Otherwise users can list every document or get your whole app.

Rewrite generic object access, ie /dbname/:id to a show that can deny access if the user is not allowed to see the document. Unfortunately there is no equivalent workaround for doc-based access control of attachments.

We used haproxy to filter GET requests on _users. There is no legit reason for someone from outside to get a user record or list all your users. We want users to be able to register so we need write access. Currently couch cannot block read access to a db and simultaneously allow writes. It's a bug. Filtering with something like haproxy is our best workaround for now.

Use your own database to keep contact information that is in addition to what is provided by _users. This allows more control over access.

validate_doc_update should carefully reject any writes that should not be allowed.

In every case you need to imagine what someone who understood the system could do to subvert it and lock down those avenues of attack.

answered 2011-12-05T17:52:49.780

Your Answer