Premier League Predictor: FastAPI & Redis — Chapter 11, Exercise 2 ================================================================== TASK Create an ACL user limited to keys matching season:* and gameweek:*. Try SADD on a gameweek key, ZADD on a season key, HSET on a fixture key, INCR on fixture:next_id, and a Lua script that writes one permitted and one forbidden key. Report each result, and whether the permitted write inside the script took effect. SOLUTION ACL SETUSER narrow on >pw ~season:* ~gameweek:* &* +@all -@dangerous Connected as that user: SADD gameweek:1:1:used_teams 1 -> 1 ZADD season:1:table -> 1 HSET fixture:1 (outside patterns) -> DENIED: No permissions to access a key INCR fixture:next_id -> DENIED: No permissions to access a key Script: HSET KEYS[1] (season:1:foo, permitted), then HSET fixture:9 (forbidden), return 1. -> DENIED: ACL failure in script: No permissions to access a key EXISTS season:1:foo -> 1 (the permitted write DID take effect) EXISTS fixture:9 -> 0 The script was stopped at the forbidden command, but the write before it was not undone. Redis does not roll back a failed script, in the same way Chapter 3 found that it does not roll back a failed MULTI/EXEC transaction. ACL rules protect keys from being touched; they do not make a script all-or-nothing. Consequence: a script that can fail partway needs its checks before its writes, or must be written so a partial run is harmless. WHY THIS WORKS AS AN ANSWER ---------------------------- It runs all five cases, and it checks the state afterwards instead of assuming a denied script left nothing behind - which it did not.