redis: a consumer's ACL loses the dangerous category — a key pattern does not confine FLUSHALL (novox/hq issue 080)

This commit is contained in:
2026-09-22 01:39:29 +02:00
parent 54af5e8536
commit 421f4d8577
+6 -1
View File
@@ -98,9 +98,14 @@ export class RedisClient {
* clears any prior rules so the call is idempotent, then the user is enabled with the given * clears any prior rules so the call is idempotent, then the user is enabled with the given
* password, confined to keys matching `<prefix>:*`, and allowed the ordinary command set. The * password, confined to keys matching `<prefix>:*`, and allowed the ordinary command set. The
* consumer connects as this user and can touch nothing outside its prefix. * consumer connects as this user and can touch nothing outside its prefix.
*
* Minus the dangerous category: a key pattern confines commands that name keys, and FLUSHALL,
* FLUSHDB, CONFIG, SHUTDOWN and the rest of `@dangerous` name none — with `+@all` alone a
* consumer scoped to its own keys could still wipe the server (novox/hq issue 080). KEYS goes
* with them; SCAN stays, and is what a consumer should use anyway.
*/ */
async createAclUser(username: string, password: string, keyspacePrefix: string): Promise<void> { async createAclUser(username: string, password: string, keyspacePrefix: string): Promise<void> {
await this.command("ACL", "SETUSER", username, "reset", "on", `>${password}`, `~${keyspacePrefix}:*`, "+@all"); await this.command("ACL", "SETUSER", username, "reset", "on", `>${password}`, `~${keyspacePrefix}:*`, "+@all", "-@dangerous");
} }
async deleteAclUser(username: string): Promise<void> { async deleteAclUser(username: string): Promise<void> {