Head's Up! These forums are read-only. All users and content have migrated. Please join us at community.neo4j.com.
08-05-2020 02:33 PM
Hi community,
we're trying to move our application from a graph-based user management over to the integrated role based one from the 4.1 enterprise. At the moment we have all users stored in one instance per tenant and therefore the management is secure for each of them as they only can see their own users.
But we couldn't setup a system with one neo4j instance and multiple databases as granting user management allows to see all other users because of the access to the dbms. We can of course filter them down within the application using a filter to the corresponding roles, but there's still the evil database access what chalks up our system as a vulnerable.
Has anybody else had to do with such a setup already and if so what was the final outcome? Would be great to hear from you.
Kindly,
Marc
08-06-2020 05:21 AM
08-06-2020 05:53 AM
Hi @sameerG,
thanks for sharing this video. I've already been walking through nearly all features of 4.1 concerning its' access control features. Inside the video I've seen nothing concerning any kind of "tenant-user-admin-roles", or maybe I've skipped the crucial few seconds.
Kindly,
Marc
All the sessions of the conference are now available online