0Pricing
Neo4j Graph Database Fundamentals · Lektion

Authentifizierung und Autorisierung

Implementieren Sie Authentifizierungsmethoden und konfigurieren Sie Autorisierungsregeln, um zu steuern, wer auf Ihre Graphdaten zugreifen und sie ändern darf.

Authentifizierung und Autorisierung ist eine kostenlose Neo4j Graph Database Fundamentals-Lektion auf CoddyKit. Dies ist Lektion 2 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Neo4j Graph Database Fundamentals-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Neo4j Graph Database Fundamentals-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

AuthN vs. AuthZ: The Basics

When we talk about database security, two key concepts are Authentication and Authorization. While they sound similar, they serve distinct purposes.

Authentication (AuthN) is about verifying who you are. It confirms your identity, typically using a username and password.

Authorization (AuthZ) is about determining what you can do. Once authenticated, the system decides what actions you're permitted to perform.

Neo4j Authentication Methods

Neo4j primarily uses native authentication, where user credentials (username and password) are stored and managed directly within the database.

For enterprise setups, Neo4j also supports integration with external authentication systems like LDAP or Kerberos, but for most applications, native authentication is sufficient and simpler to manage.

The Initial 'neo4j' User

Upon your first installation and startup of Neo4j, a default administrative user named neo4j is automatically created.

This user has full administrative privileges. It is crucial for security reasons to change the initial password for the neo4j user immediately after setup.

Changing User Passwords

You can change the password for the currently authenticated user using a built-in Cypher procedure. This is essential for managing security.

Try changing the password for the neo4j user. Remember to replace 'your_new_password' with a strong, unique password.

CALL dbms.security.changeUserPassword('your_new_password');

Understanding Authorization in Neo4j

Once a user is authenticated, Neo4j uses authorization to control their access. This is achieved through a system of roles and privileges.

  • Roles: Groups of users that share a common set of permissions.
  • Privileges: Specific permissions that define what actions can be performed (e.g., read, write, create nodes).

By assigning privileges to roles, and roles to users, you can manage access efficiently.

Common Privilege Types

Neo4j offers granular control over various operations. Here are some common privilege types:

  • ACCESS: Allows connection to a specific database.
  • READ: Permits reading data (nodes, relationships, properties).
  • WRITE: Allows creating, updating, or deleting data.
  • SCHEMA: Grants permission to manage schema elements like labels, relationship types, and indexes.
  • SHOW: Allows viewing database information and configurations.

Privileges can be scoped to specific graphs, labels, relationship types, or even properties.

Granting Privileges to Roles

The GRANT clause is used to assign privileges to a role. This allows users assigned to that role to perform specific actions.

For example, you might grant a viewer role the ability to read data on specific node labels within your graph.

GRANT READ {labels: ['Movie', 'Person']} ON GRAPH neo4j TO ROLE viewer;

Denying Privileges

The DENY clause explicitly forbids a privilege for a role. This is powerful because a DENY privilege always takes precedence over any GRANT privilege for the same action.

This means if a role is granted a privilege but also denied it, the deny will be enforced.

DENY WRITE ON GRAPH neo4j TO ROLE viewer;

Revoking Privileges

To remove a previously granted or denied privilege from a role, you use the REVOKE clause. This effectively removes the explicit permission or denial.

If a privilege was previously GRANTED and then REVOKED, the role will no longer have that specific permission.

REVOKE READ ON GRAPH neo4j TO ROLE viewer;

Quick Check: Security Actions

Consider the core concepts of Neo4j security. Which of the following statements are true?

Recap: Securing Your Graph

In this lesson, we established the difference between authentication (who you are) and authorization (what you can do) in Neo4j.

You learned about the default neo4j user and the importance of changing its password. We then explored how to manage privileges using GRANT, DENY, and REVOKE clauses to control access for various roles, ensuring your graph data remains secure and accessible only to authorized users.

Häufig gestellte Fragen

Ist die Lektion „Authentifizierung und Autorisierung“ kostenlos?

Ja — der vollständige Text von „Authentifizierung und Autorisierung“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Neo4j Graph Database Fundamentals-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Neo4j Graph Database Fundamentals-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Authentifizierung und Autorisierung“?

Implementieren Sie Authentifizierungsmethoden und konfigurieren Sie Autorisierungsregeln, um zu steuern, wer auf Ihre Graphdaten zugreifen und sie ändern darf. Du übst Neo4j Graph Database Fundamentals mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Neo4j Graph Database Fundamentals zu starten?

Keine Vorkenntnisse erforderlich. Neo4j Graph Database Fundamentals auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 2 von 4.

Wie lange dauert die Lektion „Authentifizierung und Autorisierung“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Neo4j Graph Database Fundamentals-Lektion Code schreiben und ausführen?

Ja. Jede Neo4j Graph Database Fundamentals-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Benutzerverwaltung und Rollen
  2. Authentifizierung und Autorisierung
  3. Ihre Neo4j-Bereitstellung absichern
  4. Feingranulare Zugriffskontrolle und Auditing
← Zurück zu Neo4j Graph Database Fundamentals