Files
hq/04-ISSUES/080-a-cache-grant-lets-the-consumer-flush-the-server/00-report.md
T

1.4 KiB

status, opened, located-in, fixed-by
status opened located-in fixed-by
resolved 2026-09-22
mesh-catalog modules/redis (the provisioner's ACL)
mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused

080 — A cache grant lets the consumer flush the server

Symptom

The cache provider's provisioner creates each consumer an ACL user confined to keys under its own login and allowed every command. A key pattern confines only commands that name keys. FLUSHALL, FLUSHDB, CONFIG, SHUTDOWN and the rest of the dangerous category name none, so a consumer granted "its own keys" could wipe every other consumer's, or stop the server.

Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed: FLUSHALL as the consumer answered OK.

Why it matters beyond the instance

A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The promise was checked on the key pattern and never on the command set, and the one bed that had asked was retired before it was run against the catalogue's module.

What would close it

The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed asserts a write outside the consumer's keys and a FLUSHALL are both refused.