diff --git a/modules/redis/client.ts b/modules/redis/client.ts index d4eb35d..7ca6744 100644 --- a/modules/redis/client.ts +++ b/modules/redis/client.ts @@ -98,9 +98,14 @@ export class RedisClient { * clears any prior rules so the call is idempotent, then the user is enabled with the given * password, confined to keys matching `:*`, and allowed the ordinary command set. The * consumer connects as this user and can touch nothing outside its prefix. + * + * Minus the dangerous category: a key pattern confines commands that name keys, and FLUSHALL, + * FLUSHDB, CONFIG, SHUTDOWN and the rest of `@dangerous` name none — with `+@all` alone a + * consumer scoped to its own keys could still wipe the server (novox/hq issue 080). KEYS goes + * with them; SCAN stays, and is what a consumer should use anyway. */ async createAclUser(username: string, password: string, keyspacePrefix: string): Promise { - await this.command("ACL", "SETUSER", username, "reset", "on", `>${password}`, `~${keyspacePrefix}:*`, "+@all"); + await this.command("ACL", "SETUSER", username, "reset", "on", `>${password}`, `~${keyspacePrefix}:*`, "+@all", "-@dangerous"); } async deleteAclUser(username: string): Promise {