redis: a consumer's ACL loses the dangerous category (issue 080) #36

Merged
jschoubben merged 2 commits from multiple-fixes into main 2026-09-22 00:19:15 +00:00
Showing only changes of commit c71bbd497f - Show all commits
+3 -2
View File
@@ -102,10 +102,11 @@ export class RedisClient {
* Minus the dangerous category: a key pattern confines commands that name keys, and FLUSHALL,
* FLUSHDB, CONFIG, SHUTDOWN and the rest of `@dangerous` name none — with `+@all` alone a
* consumer scoped to its own keys could still wipe the server (novox/hq issue 080). KEYS goes
* with them; SCAN stays, and is what a consumer should use anyway.
* with them; SCAN stays, and is what a consumer should use anyway. INFO comes back: it is in the
* category, reads nothing a consumer keeps, and several client libraries ask it at connect.
*/
async createAclUser(username: string, password: string, keyspacePrefix: string): Promise<void> {
await this.command("ACL", "SETUSER", username, "reset", "on", `>${password}`, `~${keyspacePrefix}:*`, "+@all", "-@dangerous");
await this.command("ACL", "SETUSER", username, "reset", "on", `>${password}`, `~${keyspacePrefix}:*`, "+@all", "-@dangerous", "+info");
}
async deleteAclUser(username: string): Promise<void> {