Authentication & Authorization
Authentication & Authorization
Section titled “Authentication & Authorization”MongoDB has two separate security concepts:
- Authentication — Who are you? (verifying identity)
- Authorization — What can you do? (permissions based on roles)
Real-World Analogy
Section titled “Real-World Analogy”Think of an office building:
- Authentication = Showing your ID card at the entrance
- Authorization = Your access level determines which floors you can enter:
- Employee can enter floors 1–3
- Manager can enter floors 1–5
- Admin can enter all floors including the server room
Auth Flow
Section titled “Auth Flow”sequenceDiagram participant User as Application / User participant MongoDB as MongoDB
User->>MongoDB: Connect with credentials (username + password) MongoDB-->>User: Authenticated ✅
User->>MongoDB: db.users.find() MongoDB-->>User: ⛔ Error: not authorized for query
Note over User,MongoDB: Even after login, permissions depend on roles
User->>MongoDB: db.orders.find() MongoDB-->>User: ✅ Returns data (has read permission on orders)Creating Users
Section titled “Creating Users”// Connect to admin database to create usersuse admin
// Create a user with readWrite role on myapp databasedb.createUser({ user: "appuser", pwd: passwordPrompt(), // or plain string (not recommended) roles: [ { role: "readWrite", db: "myapp" } ]})
// Create an admin user (full access)db.createUser({ user: "admin", pwd: passwordPrompt(), roles: [ { role: "root", db: "admin" } ]})
// Create a read-only user for reportingdb.createUser({ user: "reporter", pwd: passwordPrompt(), roles: [ { role: "read", db: "myapp" } ]})
// Create user with multiple roles across databasesdb.createUser({ user: "developer", pwd: passwordPrompt(), roles: [ { role: "readWrite", db: "myapp" }, { role: "read", db: "analytics" }, { role: "dbAdmin", db: "myapp" } ]})Built-in Roles
Section titled “Built-in Roles”flowchart TB subgraph Roles[Built-in Roles — Hierarchy] R1[databaseUser<br/>🗄️ Read/Write on one DB] R2[databaseAdmin<br/>🔧 Manage indexes & schema] R3[userAdmin<br/>👥 Manage users] R4[dbOwner<br/>👑 All DB operations] R5[root<br/>⚡ Superuser — everything] R6[read<br/>📖 Read-only] R7[readWrite<br/>✏️ Read & write] R8[clusterAdmin<br/>🌐 Cluster management] end
R6 --> R7 R7 --> R1 R1 --> R4 R2 --> R4 R3 --> R4 R4 --> R5 R8 --> R5
style R5 fill:#7c3aed,color:#fff style R4 fill:#3b82f6,color:#fff style R1 fill:#059669,color:#fff style R8 fill:#f59e0b,color:#fff| Role | Scope | Permissions |
|---|---|---|
read | Database | Read any collection |
readWrite | Database | Read + write any collection |
dbAdmin | Database | Manage indexes, schema, stats |
userAdmin | Database | Create/manage users on this database |
dbOwner | Database | All database operations (readWrite + dbAdmin + userAdmin) |
root | Global | Superuser — everything |
clusterAdmin | Cluster | Sharding, replication, cluster management |
backup | Global | Backup data |
restore | Global | Restore from backup |
Custom Roles
Section titled “Custom Roles”use myapp
// Create a custom role that can only read orders and manage usersdb.createRole({ role: "orderManager", privileges: [ { resource: { db: "myapp", collection: "orders" }, actions: ["find", "insert", "update"] }, { resource: { db: "myapp", collection: "users" }, actions: ["find", "update"] } ], roles: [] // can inherit from other roles})
// Create user with custom roledb.createUser({ user: "orderManager", pwd: passwordPrompt(), roles: [ { role: "orderManager", db: "myapp" } ]})Managing Users and Roles
Section titled “Managing Users and Roles”// List all usersdb.getUsers()
// Show current user's privilegesdb.runCommand({ usersInfo: "appuser", showPrivileges: true })
// Update user's rolesdb.updateUser("appuser", { roles: [ { role: "readWrite", db: "myapp" }, { role: "read", db: "analytics" } ]})
// Remove a userdb.dropUser("olduser")
// List all rolesdb.getRoles({ showBuiltinRoles: true })In Simple Words
Section titled “In Simple Words”- Authentication checks who you are; Authorization controls what you can do
- Built-in roles range from
read(basic) toroot(superuser) - Always create application users with least privilege — only grant what’s needed
- Use custom roles when built-in roles don’t give the exact permissions you need
- Store passwords securely, never hardcode them in your app
Next: Schema Validation →