redis: a consumer's ACL loses the dangerous category (issue 080) #36

Merged
jschoubben merged 2 commits from multiple-fixes into main 2026-09-22 00:19:15 +00:00
Owner
  • A consumer's ACL user was scoped to ~<login>:* with +@all. A key pattern confines only commands that name keys, so FLUSHALL, FLUSHDB, CONFIG, SHUTDOWN were all allowed: a consumer granted its own keys could wipe every other consumer's. Now +@all -@dangerous. KEYS goes with the category; SCAN stays.

Found by the grant end-to-end bed's new tenancy assertions (carried from the large bed's retired cache-grant test). Proof: mesh-grant-end-to-end 1/1 with the redis runtime rebuilt from 421f4d8 — a write outside the login's keys and FLUSHALL are refused, a write under it succeeds. Companion MRs on multiple-fixes: mesh-controller, mesh-lab, hq.

- A consumer's ACL user was scoped to `~<login>:*` with `+@all`. A key pattern confines only commands that name keys, so `FLUSHALL`, `FLUSHDB`, `CONFIG`, `SHUTDOWN` were all allowed: a consumer granted its own keys could wipe every other consumer's. Now `+@all -@dangerous`. `KEYS` goes with the category; `SCAN` stays. Found by the grant end-to-end bed's new tenancy assertions (carried from the large bed's retired cache-grant test). Proof: mesh-grant-end-to-end 1/1 with the redis runtime rebuilt from 421f4d8 — a write outside the login's keys and FLUSHALL are refused, a write under it succeeds. Companion MRs on `multiple-fixes`: mesh-controller, mesh-lab, hq.
jschoubben added 1 commit 2026-09-21 23:55:40 +00:00
jschoubben added 1 commit 2026-09-22 00:03:25 +00:00
jschoubben merged commit b2a48558ea into main 2026-09-22 00:19:15 +00:00
jschoubben deleted branch multiple-fixes 2026-09-22 00:19:15 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#36