Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Why is it not recommended to use server-side stored functions in MongoDB?

According to the MongoDB documentation, it isn't recommended to use server-side stored functions. What is the reason behind this warning?

like image 953
Carlos Melo Avatar asked Mar 27 '13 13:03

Carlos Melo


People also ask

Can we store function in MongoDB?

These functions, saved as BSON type JavaScript, are available for use from any JavaScript context, such as mapReduce and $where . Functions saved as the deprecated BSON type JavaScript (with scope), however, cannot be used by mapReduce and $where starting in MongoDB 4.4.

Does MongoDB uses JavaScript?

MongoDB supports JavaScript through the official Node. js driver. You can connect your Node. js applications to MongoDB and work with your data.

How to remove server-side JavaScript?

Disable Server-Side Execution of JavaScript You can disable all server-side execution of JavaScript: For a mongod instance by passing the --noscripting option on the command line or setting security. javascriptEnabled to false in the configuration file.

Can we store source code in MongoDB?

MongoDB is a popular open-source NoSQL database written in C++. MongoDB is a Dynamic Schema Document-Oriented Database that stores data in JSON-like documents. It means that when storing your records, you don't have to worry about the Data Structure, the number of fields or the types of fields used to store values.


1 Answers

I am sure I have stated the list a couple of times despite the Google search result being filled only with people telling you how to do it:

  • It is eval
  • eval has natural abilities to be easily injected, it is like a non-PDO equilivant to SQL, if you don't buld a full scale escaping library around it it will mess you up. By using these functions you are effectively replacing the safer native language of MongoDB for something that is just as insecure as any old SQL out there.
  • It takes a global lock and can take write lock and will not release until the operation is completely done, unlike other operations which will release in certain cases.
  • eval only works on Primaries and never any other member of the replica set
  • It is basically running, unchecked, a tonne of JS in a bundled V8/spidermonkey envo that comes with MongoDB with full ability to touch any part of your database and admin commands, does that sound safe?
  • It is NOT MongoDB and nor is it "MongoDBs SQL", it runs within a built in JS environment, not MongoDBs C++ code itself (unlike the aggregation framework).
  • Due to the previous point it is EXTREMELY slow in comparison to many other options, this goes for $where usage as well.

That should be enough to get you started on this front.

like image 100
Sammaye Avatar answered Sep 28 '22 06:09

Sammaye