gpt4 book ai didi

javascript - 尽管存在不安全,但 meteor 更新访问被拒绝

转载 作者:可可西里 更新时间:2023-11-01 09:11:23 26 4
gpt4 key购买 nike

我安装了不安全的软件包,但在客户端控制台中得到以下信息:

Meteor.user()
Object {_id: "4Dyaa5wRmxmq7j7XF", profile: Object, services: Object}_id: "4Dyaa5wRmxmq7j7XF"profile: Objectname: "Mel Oug"__proto__: Objectservices: Objectfacebook: Object__proto__: Object__proto__: Object__defineGetter__: function __defineGetter__() { [native code] }__defineSetter__: function __defineSetter__() { [native code] }__lookupGetter__: function __lookupGetter__() { [native code] }__lookupSetter__: function __lookupSetter__() { [native code] }constructor: function Object() { [native code] }hasOwnProperty: function hasOwnProperty() { [native code] }isPrototypeOf: function isPrototypeOf() { [native code] }propertyIsEnumerable: function propertyIsEnumerable() { [native code] }toLocaleString: function toLocaleString() { [native code] }toString: function toString() { [native code] }valueOf: function valueOf() { [native code] }get __proto__: function __proto__() { [native code] }set __proto__: function __proto__() { [native code] }
va = Meteor.user()._id
"4Dyaa5wRmxmq7j7XF"
Meteor.users.update(va, {$set: {email: 'the@aarts.com'}})
1
debug.js:41 update failed: Access denied

我不确定要包含哪些其他相关代码。我没有设置拒绝(或允许)规则。这是一个非常直接的用户设置,我只是看不出有什么可能会阻止它。

这是我得到的包:

ccounts-facebook          1.0.4  Login service for Facebook accounts
accounts-google 1.0.4 Login service for Google accounts
accounts-twitter 1.0.4 Login service for Twitter accounts
aldeed:autoform 5.1.2 Easily create forms with automatic insert a...
aldeed:collection2 2.3.3 Automatic validation of insert and update o...
autopublish 1.0.3 Publish the entire database to all clients
blaze 2.1.2 Meteor Reactive Templating library
cmather:handlebars-server 2.0.0 Allows handlebars templates to be defined o...
email 1.0.6 Send email messages
insecure 1.0.3 Allow all database writes by default
iron:router 1.0.7 Routing specifically designed for Meteor
meteor-platform 1.2.2 Include a standard set of Meteor packages i...
mquandalle:jade 0.4.1* Jade template language
msavin:mongol 1.0.30* The insanely handy development package for...
service-configuration 1.0.4 Manage the configuration for third-party se...
twbs:bootstrap 3.3.4 The most popular front-end framework for de...
useraccounts:bootstrap 1.8.1* Accounts Templates styled for Twitter Boots

最佳答案

Meteor.users 集合是一个特例,具有既定的结构和权限。即使安装了不安全的软件包,您也只能从客户端更新 user.profile 字段。

这会起作用,例如:

Meteor.users.update(va, {$set: {'profile.email': 'the@aarts.com'}})

电子邮件通常从服务器代码中保存并推送到用户记录中提供的“电子邮件”数组。

“电子邮件”:[ { “地址”:“the@aarts.com”, “已验证”:假 } ],

来自 meteor 文档:

Users are by default allowed to specify their own profile field with Accounts.createUser and modify it with Meteor.users.update. To allow users to edit additional fields, use Meteor.users.allow.

关于javascript - 尽管存在不安全,但 meteor 更新访问被拒绝,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/30246837/

26 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com