Files
hq/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/01-diagnosis.md

903 B

Diagnosis — 2026-09-22

  1. The provisioner's ACL SETUSER gave ~<login>:* and +@all. Redis applies a key pattern to commands that take keys; a command taking none is governed by the command categories alone, and @all includes @dangerous.
  2. Fixed with -@dangerous after +@all. KEYS goes with the category; SCAN stays, and is what a consumer scoped to a prefix should use.

Located in: the redis module's client. Not a decision. Proven by the grant end-to-end bed.

On review. INFO is in the dangerous category and several client libraries ask it at connect; it reads nothing a consumer keeps, so it is allowed back. Whether the catalogue's two cache consumers need anything else the category removes is unverified — and moot until they present the login they were granted (issue 081).