Skip to content

fix(mongodb): handle unauthorized listDatabases on admin by falling back to connection database #924

Description

@ZhuchkaTriplesix

Summary

In MongoConnection.listDatabases():

final adminDb = await openDatabase('admin');
final result = await adminDb.runCommand({'listDatabases': 1});

On managed MongoDB hosting providers (such as MongoDB Atlas shared tiers M0/M2/M5, DigitalOcean, or standard database-scoped user accounts), users are only granted readWrite privileges on their designated target database (e.g. my_app_prod). They lack the cluster-level listDatabases privilege on the admin database.

When openDatabase('admin') or runCommand({'listDatabases': 1}) is executed, MongoDB returns an unauthorized error (code: 13). In MongoDatabasesView, this error is caught and sets _error = 'Failed to list databases: ', permanently blocking the user from seeing or browsing any collections, even though a valid database was configured in ConnectionRow.database.

Repro

  1. Connect with credentials that have read/write access to testdb only, without cluster privileges on admin.
  2. Open the MongoDB database explorer.
  3. Observe that listDatabases fails with an authorization error, displaying a full-screen error with no way to access testdb.

Scope

  • Catch authorization errors in listDatabases() or in MongoDatabasesView._loadDatabases().
  • If listing all cluster databases fails and connectionRow.database is provided, fall back to returning [connectionRow.database].
  • Allow the user to proceed to browse collections within their accessible database without obstruction.

Out of scope

  • Dynamic permission probing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions