--- status: resolved opened: 2026-09-22 located-in: [mesh-catalog modules/redis (the provisioner's ACL)] fixed-by: mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused --- # 080 — A cache grant lets the consumer flush the server ## Symptom The cache provider's provisioner creates each consumer an ACL user confined to keys under its own login and allowed every command. A key pattern confines only commands that name keys. `FLUSHALL`, `FLUSHDB`, `CONFIG`, `SHUTDOWN` and the rest of the dangerous category name none, so a consumer granted "its own keys" could wipe every other consumer's, or stop the server. Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed: `FLUSHALL` as the consumer answered `OK`. ## Why it matters beyond the instance A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The promise was checked on the key pattern and never on the command set, and the one bed that had asked was retired before it was run against the catalogue's module. ## What would close it The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed asserts a write outside the consumer's keys and a `FLUSHALL` are both refused.