Modelled on src/acl.c, Redis 7.2.14. Command categories and key specs are generated from that release's src/commands/*.json.
ACL rules are applied in the order you write them and the last rule that touches a
command wins. +@all and -@all are not ordinary rules: each one
rewrites the whole permission bitmap and discards every rule stated before it
(acl.c:1030, acl.c:1037). Type a rule set on the left, then dry-run a command to see the
replay that produced the answer.
Supported: SETUSER · GETUSER · DELUSER · LIST · USERS · CAT · DRYRUN
Run a check to see how each rule, in order, moved the verdict for that one command.
+@all / -@all is always emitted first: placed later it would
erase every category rule before it (acl.c:1030).
| Order of checks | command bit, then keys, then channels — acl.c:1662 ACLSelectorCheckCmd. |
| Selectors | Each (…) becomes a selector. Selectors are tried in order, the root selector first, and the first one that passes wins — acl.c:1839. The reported error is the command if no selector could run it, otherwise the last key or channel no selector matched — acl.c:1828. |
+@all / -@all | Fills or clears the whole bitmap and drops accumulated command rules and first-args — acl.c:1030, acl.c:1037. |
| Container commands | Allowing or blocking a container also applies to its subcommands — acl.c:608. A category rule additionally walks subcommands on their own categories — acl.c:629. |
| Commands exempt from the bitmap | Commands flagged NO_AUTH skip the command check entirely — acl.c:1665. In 7.2.14 those are AUTH, HELLO, RESET and QUIT. |
off | Blocks authentication only. DRYRUN and already-authenticated connections are unaffected — acl.c:1191, and the DRYRUN path never reads the enabled flag. |
| PSUBSCRIBE | Its argument is compared to ACL channel patterns as a literal string, not glob-matched — acl.c:1630. |
| SETUSER is atomic | If any rule is invalid nothing is applied and no user is created — acl.c:2057. |
| Not modelled: SORT, SORT_RO, MIGRATE | Their later key specs are marked incomplete in the command table; real Redis resolves them with a command-specific function. Only the keys their complete specs describe are checked here. |
| Not modelled: BITFIELD | Its key spec carries VARIABLE_FLAGS and the read/write decision is made by a C helper this page has not reproduced, so its key is not checked. SET's variable flags are modelled, from db.c:2501. |
| Not modelled | ACL LOG, ACL SAVE/LOAD, modules, and cluster or sentinel specifics. |