Files
hq/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/00-report.md
T

30 lines
1.4 KiB
Markdown

---
status: resolved
opened: 2026-09-22
located-in: [mesh-catalog modules/redis (the provisioner's ACL)]
fixed-by: mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused
---
# 080 — A cache grant lets the consumer flush the server
## Symptom
The cache provider's provisioner creates each consumer an ACL user confined to keys under its own
login and allowed every command. A key pattern confines only commands that name keys. `FLUSHALL`,
`FLUSHDB`, `CONFIG`, `SHUTDOWN` and the rest of the dangerous category name none, so a consumer
granted "its own keys" could wipe every other consumer's, or stop the server.
Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed:
`FLUSHALL` as the consumer answered `OK`.
## Why it matters beyond the instance
A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The
promise was checked on the key pattern and never on the command set, and the one bed that had
asked was retired before it was run against the catalogue's module.
## What would close it
The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed
asserts a write outside the consumer's keys and a `FLUSHALL` are both refused.