15 lines
903 B
Markdown
15 lines
903 B
Markdown
# Diagnosis — 2026-09-22
|
|
|
|
1. The provisioner's `ACL SETUSER` gave `~<login>:*` and `+@all`. Redis applies a key pattern to
|
|
commands that take keys; a command taking none is governed by the command categories alone,
|
|
and `@all` includes `@dangerous`.
|
|
2. Fixed with `-@dangerous` after `+@all`. `KEYS` goes with the category; `SCAN` stays, and is
|
|
what a consumer scoped to a prefix should use.
|
|
|
|
**Located in:** the redis module's client. Not a decision. Proven by the grant end-to-end bed.
|
|
|
|
*On review.* `INFO` is in the dangerous category and several client libraries ask it at connect;
|
|
it reads nothing a consumer keeps, so it is allowed back. Whether the catalogue's two cache
|
|
consumers need anything else the category removes is unverified — and moot until they present the
|
|
login they were granted ([issue 081](../081-a-cache-consumer-does-not-use-the-login-it-was-granted/00-report.md)).
|