Summary
In MongoConnection.listDatabases():
final adminDb = await openDatabase('admin');
final result = await adminDb.runCommand({'listDatabases': 1});
On managed MongoDB hosting providers (such as MongoDB Atlas shared tiers M0/M2/M5, DigitalOcean, or standard database-scoped user accounts), users are only granted readWrite privileges on their designated target database (e.g. my_app_prod). They lack the cluster-level listDatabases privilege on the admin database.
When openDatabase('admin') or runCommand({'listDatabases': 1}) is executed, MongoDB returns an unauthorized error (code: 13). In MongoDatabasesView, this error is caught and sets _error = 'Failed to list databases: ', permanently blocking the user from seeing or browsing any collections, even though a valid database was configured in ConnectionRow.database.
Repro
- Connect with credentials that have read/write access to
testdb only, without cluster privileges on admin.
- Open the MongoDB database explorer.
- Observe that
listDatabases fails with an authorization error, displaying a full-screen error with no way to access testdb.
Scope
- Catch authorization errors in
listDatabases() or in MongoDatabasesView._loadDatabases().
- If listing all cluster databases fails and
connectionRow.database is provided, fall back to returning [connectionRow.database].
- Allow the user to proceed to browse collections within their accessible database without obstruction.
Out of scope
- Dynamic permission probing.
Summary
In
MongoConnection.listDatabases():On managed MongoDB hosting providers (such as MongoDB Atlas shared tiers M0/M2/M5, DigitalOcean, or standard database-scoped user accounts), users are only granted
readWriteprivileges on their designated target database (e.g.my_app_prod). They lack the cluster-levellistDatabasesprivilege on theadmindatabase.When
openDatabase('admin')orrunCommand({'listDatabases': 1})is executed, MongoDB returns an unauthorized error (code: 13). InMongoDatabasesView, this error is caught and sets_error = 'Failed to list databases: ', permanently blocking the user from seeing or browsing any collections, even though a valid database was configured inConnectionRow.database.Repro
testdbonly, without cluster privileges onadmin.listDatabasesfails with an authorization error, displaying a full-screen error with no way to accesstestdb.Scope
listDatabases()or inMongoDatabasesView._loadDatabases().connectionRow.databaseis provided, fall back to returning[connectionRow.database].Out of scope