nopass
Any password authenticates, including an empty one
user metrics on nopass ~metrics:* +@read
Paste ACL rules to find the ones that do not do what they look like. The reference list of categories is below the findings, since choosing the right category is most of writing a good rule set.
Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.
The answer appears here
Paste on the left and press Audit. Nothing leaves this tab.
Nothing else to flag.
No formatting problems, and nothing the rules object to. Worth remembering what that covers: this reads the file you pasted, not the account or cluster it will be applied to.
No finding matches that filter.
Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.
Any password authenticates, including an empty one
user metrics on nopass ~metrics:* +@read
Every command and no key access, which fails with an error naming the key
user worker on >pw +@all
These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.
That takes clear text, which then lives in the config file, in shell history, and in any log that captured the command. Redis stores it hashed; everything upstream of Redis saw it.
Instead:Use `#<sha256hex>`. ACL GETUSER shows existing hashes so you can convert without the original.
@slow means every command not in @fast, which includes a great many ordinary ones. It is far more restrictive than it sounds and breaks applications in ways that look unrelated.
Instead:Name the categories you want: +@read +@write +@keyspace.
acl-pubsub-default changed from allchannels to resetchannels, so users that worked on 6.x lose channel access on upgrade.
Instead:Grant `&pattern` explicitly rather than relying on the default.
Granting individual commands does not survive Redis adding new ones. Categories do, which makes them the maintainable choice, with two caveats worth knowing before you rely on them.
For an administrative user, +@all -@dangerous is clear and self-maintaining. For an application user the opposite is better: start from nothing and add +@read +@write +@keyspace, so a new Redis version cannot silently widen what the user can do.
It means every command not in @fast, which includes a great many ordinary commands. -@slow is far more restrictive than people expect and breaks applications in ways that look unrelated to the ACL.
It covers FLUSHALL, KEYS, CONFIG, SHUTDOWN, DEBUG and similar. It is a curated list maintained by Redis, so it is a good default and not a security boundary you can reason about from first principles. Check what it contains on your version with ACL CAT dangerous.
ACL SETUSER either applies every rule or none of them. A single unknown category rejects the whole command and the user is left exactly as it was, which is safe but means a typo produces no change rather than a partial one.
It cannot evaluate a selector's contents, which is a Redis 7.0 feature for granting independent permission sets. It also cannot tell you whether the permissions are appropriate: only that they are probably not what the rules appear to say. ACL LOG on a running server shows what a user was actually denied, which is the best evidence for widening a rule set.